Post,Author,Content "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",stavrosk,"Submitted by Stavros Koutsangelas, Co-Founder and COO, Karisma. I am an EU founder relocating to Cyprus in 2027. I run a curated community of six and seven figure founders, I build operational AI systems for facility services companies, and I run an events business in tourism and hospitality. Comments on Entrepreneurship and Innovation, Government, and Talent. 1. Annex C, Entrepreneurship and Innovation, and Section 5.2. The Strategy wants repeat founders and offers them only money. The Strategy sets out to attract ""experienced engineers, researchers, and repeat founders with real presence and knowledge transfer"", and to produce three unicorns. Both ambitions are right. The mechanism proposed for both is growth capital. That will not do it on its own. Experienced founders do not choose a country for its funding instruments. Access to capital is close to borderless now, and a matching fund that requires an institutional lead is not a reason to move anywhere. Founders relocate for other founders: for the density of people at the same altitude, for the deals and hires that come out of those relationships, and for a reason to stay once the novelty of the tax position wears off. The Strategy has no answer to that. Across 101 pages, ""founder network"" and ""community of founders"" do not appear. ""Mentor"", ""peer"" and ""convening"" appear once each. Testbeds, sandboxes and funds are all supply side. None of them creates the thing that actually holds senior people in a small country. Recommendation: name founder density as an explicit objective under the Entrepreneurship pillar, and treat convening as infrastructure rather than as an event budget. Concretely, that means a standing programme that brings experienced operators into the country and keeps them connected to local founders, measured on retention and on companies started or relocated, not on attendance. 2. Sections 2.2.1, 3.4.1 and 5.4. The adoption target depends on work the Strategy never describes. The Strategy puts enterprise AI adoption at 9.27% against an EU average of 19.95%, and targets 75%. Getting there means ordinary mid-sized companies changing how they work day to day. Procurement appears throughout the document, but almost always as a governance question: how the public sector should approve and buy AI. Section 3.4.1 gives one sentence to ""the transition towards AI-first procurement models by 2032"" and leaves it there, with no definition, no use case and nobody accountable. Public procurement is one of the largest document heavy processes government runs. Tendering, specification, calculation, bid evaluation, contract administration, compliance reporting: most of it still runs on email and spreadsheets. Facility services procurement across ministries, schools and hospitals is a concrete example, and it is absent. The words ""tender"" and ""facility management"" do not appear anywhere in the document. Separately, the AI Sovereign Investment Matching Fund puts 75% of its capital into Series A and B rounds and invests only after an institutional investor commits. The companies producing the 9.27% figure are not raising Series A. For a 40 person facility services operator the problem is not funding. It is that there is nobody they can hire or buy from who will rebuild how their operation works. Recommendation: name operational procurement as a use case family under 3.4.1, with a defined pilot, an owner and measurable outcomes. Add an implementation instrument for existing SMEs alongside the Matching Fund, redeemable against certified providers and measured separately from startup funding. Government both buys facility services and runs them, so one pilot can be tested from both sides. 3. Section 3.6.5. The talent chapter leaves out what Cyprus already has. Section 3.6.5 says only that ""specific incentives will be developed"" to attract AI experts and startups. No instrument, no timeline, no measure. Cyprus already has them. Non-dom status, the 50% income tax exemption on employment above EUR 55,000, and the IP Box regime covering copyrighted software. These exist today and for anyone weighing a move they are decisive. I am making that calculation this year, and none of the three appears in the talent section. Recommendation: reference them directly in 3.6.5, so the offer is clear now rather than waiting on incentives still to be designed. Offer of contribution. I move to Cyprus in 2027 and I am building in two of the priority sectors. Happy to contribute free of charge on any of the above: on what actually makes experienced founders relocate and stay, on tender and calculation workflows in facility services, and on what mid-sized operators need before they can adopt anything at all." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",igor_akimov,"Hi everyone and happy last day of summer. It was a pleasure to read the strategy and 120 pages of comments so far. Looks like this topic is truly important to organizations and residents of Cyprus. I'll try to gather some practical review without relying solely on AI tools. In general, I support this strategy. Cyprus shouldn't compete on GPU capacity (especially with such electricity prices) or try to create another global ChatGPT (every country except US and China failed). Its advantages are a compact market, a strong service sector, EU membership, and the ability to quickly test. The ""trusted AI hub for regulated industries"" is a reasonable bet, and the education component is one of the strongest I've seen in a national strategy. What the document still lacks is a plan for achieving the goal: funding, responsible parties, and a sequence of actions. I write this as a practitioner. I run more than a dozen of AI implementation projects in Cyprus, have implemented projects based on publicly available Cypriot data, and worked on speech recognition in Cypriot Greek. I also discussed the project with several colleagues from the local AI industry, so these points are based on practical experience. So, what will be great to add: 1. A three-year implementation plan with costing. A short working document of 15-20 actions for 2027-2029. Each action should be carried out by a single responsible person and include launch and operating costs, funding source, baseline plan, target date, and scaling or termination conditions. Costs should cover the entire lifecycle: licenses, integration, security, training, and support. A pilot project that lacks future funding will remain a pilot. 2. One set of numbers.The adoption target is presented in three versions (50% by 2032, 75% by 2032, 75% by 2030). Ministry AI strategies are updated both ""annually"" and ""every three years."" ""3,000 AI specialists"" are three different concepts in three different places. A unified KPI dictionary with baseline metrics and data sources solves this problem. Essentially, 75% by 2030, instead of the current 9.27%, is unrealistic; 50% by 2032, considering only systems in actual productive use, would be a plausible and still ambitious target. But it was mentioned a lot of times. 3. Easier control. A dozen new councils, committees, and centers is a lot for a country of this size. One small central team with a budget and authority to unblock ministries, one person responsible for each initiative, one AI coordinator per ministry. Expert committees as temporary working groups. The team driving implementation should not conduct self-audits; oversight should be left to existing regulatory bodies. Publish a quarterly report (what has already been implemented, how much it cost, what has been stopped) and report to parliament once a year. Fighting bureaucracy with AI can be a good goal too. 4. Three missions for the first wave, not sixteen flagships. It's OK. I also like setting 10 different highest priority KPIs for the quarter, so need someone to reduce this to at most three (my wife is the best of this). First, a unified platform for public services: identification, payments, document searches, manual data transfer, with municipalities using the same components. Second, artificial intelligence in the maritime sector, where Cyprus holds a real position: the third-largest fleet in the EU and the largest ship management center in Europe in Limassol. Third, robust AI for regulated services (finance, legal, healthcare), where the rapid and transparent application of EU regulations could become an export product. Other sectors remain in the portfolio and will move to the next stage once the data, owner, and budget are ready. 5. Pay for working software, not just for consultations. I've attended several dozens of AI conferences. Most of them are just nice presentations, or talks about ChatGPT wrappers... For a small company, the barrier is licensing, setup, and CRM integration, not a lack of research. A voucher of up to €15,000–€20,000 is offered, covering the first year of subscription, setup, and training. This voucher includes an application for micro-enterprises and payment to the vendor upon system launch. It's possible to measure how many companies continue to pay for the system themselves after a year. And it will be great to measure real usage and transformation of AI, not just amount of presentations generated. 6. Real access to public procurement for Cypriot SMEs. One large tender for the creation of a national platform will go to an international integrator, and the know-how will go with the contract. Divide the initial procurement into lots that can be completed by a company of 2-30 people, add an expedited process for smaller projects, and track the share of AI contract value won by local SMEs. Terms should be equal for everyone, and conflicts of interest should be disclosed; simply avoid formulating terms that deliberately exclude the entire local market. And guys, you need to do something with tenders. It's not possible to do something meaningful if after 30.000 euro contract you need years of struggles and court fights. 7. Correct the data before purchasing the equipment. Based on my own experience working with publicly available data in Cyprus, the problem isn't a lack of well-designed models, but fragmented datasets, inconsistent registries, and undocumented interfaces. There are ZERO good-quality datasets for Cypriot speech! The one you find on HuggingFace was created by us. It's not possible to create speech services for cypriots without data. It's not possible! Even with all money of the world. Let's start with just finding what is available and at the data level: named owners for each dataset, machine-readable formats, documented APIs, and quality guidelines. We'll integrate ministries in stages, based on their actual maturity. Healthcare requires an EHDS-compatible environment, not just a repository. 8. Test knowledge of the Greek language instead of relying on the statement “we support the Greek language.” Before funding a sovereign programming language training program, open datasets for assessing Greek and Cypriot Greek through Pharos-CY must be published: accuracy, imitation, human transfer, as well as terminology for public administration, tourism, law, healthcare, and maritime affairs. From my experience working with Cypriot language, I know that the phrase ""the model supports Greek"" alone means little. Without common benchmarks, the state will be purchasing machine translation at the price of a language system. This will cost several million dollars and will pay for itself with every conversational service planned for implementation under the strategy. 9. Open standards, not Cypriot ones. The strategy mentions interoperability and product-specific alignment, but doesn't name any standards. The rule should be: use open international standards and never create local variants where they already exist. Specific protocols should be described in a brief technical description, which the development team will review annually; the field is evolving too rapidly to commit protocol names to a 2032 document. The two planned AI registries should be merged, or at least a single schema with a public API should be created for them, so that the registry also serves as a catalog of verified systems. But this was mentioned several times already. 10. Ensure proportionality in compliance with the Artificial Intelligence Law. Most systems required by small and medium-sized businesses pose low risk. A short checklist is sufficient for a chat assistant or document search: disclose AI information, maintain a log, ensure human control is transferred, specify the data location, require confirmation of important actions, and specify the owner and complaints channel. Compliance with these requirements guarantees a presumption of compliance with all government agencies. Cyprus is becoming a reliable jurisdiction through rapid implementation of EU regulations, not through the addition of a national certificate. It will be great if government help here, not just flood startups with all new best-in-the-world AI regulation. 11. Specific rights of citizens. Two publicly available documents: a registry of government AI systems (purpose, owner, provider, cost, risk class, oversight, incidents) and brief, clear instructions on what to do if you've been notified of the presence of AI, how to obtain an explanation, request a human review, file a complaint, and how to quickly receive a response. In healthcare, social benefits, employment, education, lending, and justice, the final decision rests with humans. Government contracts must guarantee access to event logs, data portability, and a plan for terminating cooperation with the vendor. It will be great to have a sandbox for testing different systems by people before the public release. 12. Talent: Reasons to stay, not just courses completed. This component takes into account trained specialists; the more difficult task is retaining them. Add recruitment and retention rates, expedited visa processes for AI specialists and founders (the long-discussed visa reform for startups is relevant here), paid internships, and professional development obligations for recipients of tax incentives and large contracts. Schools should also teach how to detect deepfakes, voice cloning, and phishing, and not just through AI. It should be very easy for a talented guy to move, find job and/or create a company here. 13. Measure demand before you start ""sovereign"" calculations. Cyprus already has access to Pharos-CY and EuroHPC. Before investing significantly, it's necessary to determine which workloads truly cannot leave the country and how much they cost in terms of electricity and water. Reasonable distribution: processing important data on the island, large-scale training at European AI centers (European AI Factory). For a small country, sovereignty lies in control of critical data, rules, and logs, not in owning every server. Datacenters can be blessing, but not with this temperature, electricity cost and water scarcity, sorry. A few things I would reconsider. Replace the ""three unicorns"" with metrics the state can influence: export revenue, jobs, and intellectual property retained in Cyprus. Require AI strategies only from companies using high-risk or regulated systems; for everyone else, it will be just paperwork. Avoid registers and certifications that duplicate the EU database and the AI ​​Law's compliance assessment. And regarding the ""AI judge,"" even in small, uncontested cases: let the AI ​​prepare the materials, but the decision must be made and signed by a human. In short: maintain the foundation (robust AI, industry specialization, common components, data as infrastructure, human participation) and add an implementation mechanism: one responsible person, a three-year budget, three initial missions, a single set of metrics, and a public progress report. Cyprus doesn't need to promise to become the largest AI hub in the region. It's enough to be the place where AI is most quickly applied in real-world projects, and the rules are clearly defined. I'd be happy to participate in any working group where the input of practitioners would be beneficial. Thanks a lot for this opportunity. And good luck!" "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","AI Integrity Institute","Our full submission is available here: https://www.ai-3.org/blog/cyprus-national-ai-strategy-submission The AI Integrity Institute (AI³) is a non-profit organisation working on AI governance. We connect research, industry, the public sector and civil society so that AI is developed and used responsibly and in ways that work in practice. Cyprus is the starting point for our international work. We regard the draft Strategy as a serious and candid document. The comments below are intended to strengthen it rather than to redirect it. We set out twenty-six comments. Each names the sections of the Strategy it affects, states what the draft currently says, sets out the change we recommend, and explains the reasoning. Fourteen of the twenty-six require no new institution and no significant new expenditure. Comment 1 Affected sections: 1.1, 1.4.8, 2.5.7, 3.1.2, 3.4.3, 3.9.3 to 3.9.6, Annex A, Annex F The Strategy already contains most of the substance of citizen rights. Section 3.9.6 embeds rights to explainability, contestation and human review in health, credit, employment and social benefits, and states that no system whose decisions significantly affect individuals should operate without human oversight. Our observation concerns form rather than substance. Section 3.9.6 frames these as mandates on organisations. A mandate on an organisation and an entitlement of a person are not the same instrument. A mandate is discharged through compliance documentation and is visible to a regulator. An entitlement must be findable, intelligible and enforceable by the individual. There is no single statement of what a person may demand, no time limit attached to any commitment, and no named point of contact. We propose a Citizen AI Charter, published as a short document in Greek and English within three months of adoption. It should state the right to be told AI is in use, to a meaningful explanation, to human review by a named body, to challenge a decision and obtain correction, to an alternative service route, and to know where to complain. Each right should carry a maximum response time and a responsible contact point. The Charter should distinguish rights that already exist in law from commitments made by the Strategy, and should describe the explanation right as Article 86 of the AI Act does. Comment 2 Affected sections: 3.3.2, 3.4, 3.9.3, 3.9.6, Section 5 item 4, Annex B The Strategy proposes three registration instruments. Section 3.9.6 mandates registration in the European database. Section 5 proposes a national application and certification registry, and separately a registry cataloguing AI solutions on the market. All three are compliance or market instruments. None is a national list of the systems that Cypriot public bodies use on the people they serve. The European database does not meet this need. It covers high-risk systems only, it is populated by providers rather than by the deploying public bodies, and it is structured for conformity rather than public comprehension. A citizen asking whether AI shaped a decision about their benefits would not find the answer there. We propose a single public register of AI systems used by ministries, public law bodies and local authorities. Scope it by risk, covering systems that are operational or approved and that materially affect rights, health, safety, eligibility or access to public services, together with pilots involving live personal data or direct public interaction. For each system publish the purpose, responsible body and contact point, supplier, data categories, risk classification and legal basis, human oversight arrangements, lifecycle stage, impact assessment summary, routes to challenge, and any serious incidents or withdrawals. Justified exceptions should apply for national security, cybersecurity and legitimate commercial confidentiality. Registration should be a condition of passing the control gates in Annex B. Cyprus should adopt an existing international schema rather than design its own. The Netherlands, the United Kingdom, France, Norway and Scotland all operate national registers, and a group of European cities has developed a shared data schema. Comment 3 Affected sections: 2.5.4, 3.1.1, 3.4.1, 3.4.3, Annex A, Annex C The Strategy commits to human oversight of high-risk systems and refers to multilingual support and inclusive access tools. It does not commit that a citizen who cannot or does not wish to use an AI-mediated channel retains a route to the service. We propose a commitment structured by the significance of the service. For essential public services, and for any service where an AI system makes or materially informs a decision affecting a person's rights, eligibility, entitlements or effective access, the responsible body should guarantee timely access to human assistance, and where appropriate human review or an alternative route. The alternative should carry no additional charge and should not place the person at an unjustified disadvantage in timeliness or completeness. It may be delivered by digital, telephone or in-person channels, and need not require a wholly separate service infrastructure where AI performs only a back-office function. Accessibility requirements under the European Accessibility Act should apply to AI-enabled interfaces from design stage rather than as remediation. AI-enabled citizen services should be tested with older users, users with disabilities and users with low digital confidence before deployment, with results published in summary. Cyprus records 44.2 per cent generative AI use among people aged 16 to 74, but that figure conceals a wide spread by age and circumstance. A strategy that improves service for confident digital users while degrading it for everyone else will reduce trust even as it raises efficiency. Comment 4 Affected sections: 2.5.6, 3.2, 3.5, 3.7, 3.8.6, Annex C The Strategy refers to multilingual services in eighteen places. It does not name the Greek language anywhere in the document. It does not refer to Cypriot Greek, and it does not refer to Turkish, which is an official language of the Republic. We propose that the language position be stated explicitly, supported by a national language resources programme with four components. First, assembly and open publication of Greek-language corpora and terminology resources for public administration, health, law and tourism, with clear licensing and in compliance with data protection, copyright and confidentiality rules. Second, creation of Greek-language evaluation datasets and benchmarks, including Cypriot Greek usage, so that procurement can distinguish a system that genuinely performs in Greek from one that is machine translated. Third, participation in European multilingual model initiatives rather than an attempt to build a national foundation model. Fourth, a stated commitment on the official languages of the Republic and on the practical language needs of residents and visitors. This is where the citizen agenda and the sovereignty agenda meet. If public services run on models that perform poorly in Greek, the citizen experience degrades and the state depends on suppliers whose language performance it cannot verify. Evaluation infrastructure is a public good. Without it, the phrase ""supports Greek"" is a claim on a sales document that procurement has no means to test. Comment 5 Affected sections: 2.5.4, 3.3.1, 3.4, 3.4.4, Annex C The Strategy is written almost entirely for central government. Ministries carry the obligations, AI Officers sit inside ministries, and the Applied AI Strategy requirement is directed at ministries and public bodies. Local authorities appear only marginally. We propose that local authorities be included explicitly in Section 3.4 and in the governance structure, through a proportionate route. A municipality cannot reasonably produce an Applied AI Strategy on the same terms as a ministry. We suggest three elements. First, a shared services model in which local authorities consume national capabilities such as the citizen assistant, document intelligence and translation rather than procuring their own. Second, a simplified adoption template and a single point of support within the National AI Authority. Third, representation of local government in the governance structure. In most European countries local government is where public sector AI meets the citizen most often, in permits, waste, local planning, social support and local information. It is also where capacity is weakest. A strategy that assumes ministry-level capability throughout will produce a two-speed public sector, in which the services citizens use most often are the least well governed. Comment 6 Affected sections: 3.3.1, 3.3.1.3, 3.3.1.5, 3.3.1.6, 3.11.3, 4.1.6 The Strategy places considerable weight on public trust, human-centred AI and ethics. The governance architecture provides no institutional role for civil society. Every proposed body is drawn from government, academia, research and industry. We propose three measures. First, civil society representation on the National Ethics and Values Committee. Section 3.3.1.5 gives that Committee responsibility for ethical principles and public trust, which cannot be discharged credibly by a body composed entirely of state, academic and industry representatives. Second, representation on the National AI Taskforce. Section 3.3.1.5 provides that the Committee's recommendations are submitted to the Taskforce, so representation at Committee level has limited effect unless the body receiving those recommendations also includes a civil society voice. Third, a standing Civil Society and Stakeholder Engagement Mechanism, comprising transparent open calls for representatives, periodic structured consultation, and a permanent channel for submissions during implementation. Participation should attach to three fixed points: comment on the annual implementation report, consultation before deployment of high-impact citizen-facing systems, and an independent opinion before any substantial revision of the Strategy. Transparency and conflict of interest rules should apply, and participation should complement rather than displace accountable decision-making by the responsible public bodies. This introduces no new objective. It gives effect to objectives the Strategy has already adopted. Multi-stakeholder models at European Union, Council of Europe and UNESCO level have involved civil society alongside academia, industry and public authorities. Comment 7 Affected sections: 1.4.10, 2.3.3, 3.11.2, 3.12.1, Section 5, Annex A The Strategy cites the AI Act as Regulation 2024/1689. It gives one compliance date, in the Section 5 table, asking for risk management, auditability and governance maturity ahead of 2 August 2026. That date has passed and the obligations behind it have changed. The Strategy makes no mention of Regulation (EU) 2026/1744, which amended the AI Act on 27 July 2026, six days before that deadline. We propose three changes. Update the citation to read Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. Replace the 2 August 2026 milestone with the dates that now apply. Add a short compliance calendar to Annex A. Some obligations are already in force. The Article 5 prohibitions have applied since 2 February 2025, with new provisions added by the amending Regulation from 2 December 2026. General purpose AI model obligations have applied since 2 August 2025, with earlier models to comply by 2 August 2027. Article 50 transparency obligations have applied since 2 August 2026, with systems already on the market having until 2 December 2026 to mark synthetic content in machine readable form. The remaining dates fall ahead. At least one national AI regulatory sandbox must be operational by 2 August 2027. Stand-alone high-risk systems under Annex III come into scope on 2 December 2027, and high-risk AI inside regulated products on 2 August 2028. High-risk systems already used by public authorities have until 2 August 2030. The Strategy proposes a unified government knowledge assistant, a Citizen 2032 portal and multilingual ministry assistants. All are citizen-facing conversational systems already within Article 50. Comment 8 Affected sections: 3.3.1 and Figure 2, 3.3.1.1, 3.3.1.5, 3.9.6, Annex A The Strategy contains two institutional maps that do not reference each other. Section 3.3.1 and Figure 2 set out the governance structure. Annex A separately states that the Communications Commissioner and the Commissioner for Personal Data Protection are the competent authorities for the AI Act. Neither Commissioner appears in Figure 2 or in the Section 3.3.1 list. This leaves several questions open. Section 3.3.1.1 proposes a National AI Authority acting as policy coordination body, execution body and governance and control gatekeeper, without stating how that relates to authorities holding statutory enforcement powers. Figure 2 describes the National Ethics and Values Committee as overseeing compliance with the EU AI Act, which is a function of the designated authorities rather than of an advisory committee. Section 3.9.6 refers to an annual audit by a Cyprus AI Security and Certification Authority, a body that appears nowhere else and is not defined. We propose that the two maps be merged, with Annex A carrying a single institutional map and Figure 2 redrawn to show the designated authorities and their interface with the Strategy bodies. The Strategy should state clearly what the National AI Authority is and is not. The draft is currently inconsistent, since Section 3.3.1.1 says the Authority does not assume operational control while Section 5 assigns it standards, enablement, compliance oversight and platform operations. Enablement and platform functions should be separated from any compliance assessment role. Regulated entities should have a single point of contact, formal escalation arrangements and predictable decision timelines. The same principle should apply within ministries. The person or team delivering an AI use case should not be the person or team performing its risk, ethics and compliance review. Comment 9 Affected sections: 3.8.5, Section 5 item 2, Annex A The Strategy refers to sandboxes in many places, including industry sandboxes, sectoral sandboxes and a maritime sandbox. No date, responsible authority or funding is attached, and the Article 57 obligation is not mentioned. Article 57 of the AI Act requires each Member State to ensure that at least one AI regulatory sandbox is established at national level. The original deadline of 2 August 2026 was moved by Regulation (EU) 2026/1744, and the obligation now stands at 2 August 2027. The obligation may be met jointly with another Member State, or by participating in an existing sandbox providing equivalent national coverage. We propose that the Strategy name the responsible authority, state the operating model, commit to an operational date within the deadline, and state whether Cyprus intends to meet the obligation alone or jointly. It should confirm the priority access for small and medium enterprises and start-ups required under Articles 58 and 62. Participation should remain voluntary and support testing and compliance readiness. It should not become a precertification mechanism or a prerequisite for procurement, deployment or market access. Cyprus has a live legal deadline eleven months away with no named authority, no operating model and no date in its national strategy. A sandbox that is genuinely operational ahead of August 2027, well documented and open to foreign small and medium enterprises, would be a concrete demonstration of the trusted jurisdiction proposition. Comment 10 Affected sections: 3.9, 3.3.2, 3.4.2, Annex B, Annex F The Strategy requires mandatory legal, ethical and data protection assessments for high-impact systems and approval gates before procurement, deployment and scaling. It specifies no methodology, template, publication requirement or consultation requirement. We propose a single national methodology for an integrated impact assessment covering fundamental rights, ethics, data protection and, where material, environmental and workforce effects. It should be required for high-risk systems and for any system materially affecting rights or access to public services, whether or not classified as high risk under the AI Act. It should be completed before Control Gate 2 in Annex B, with a non-confidential summary published in the public register, and repeated after substantial modification, material drift, a serious incident or a significant change of context. Proportionate consultation with affected groups and frontline professionals should apply where impact is material. Three operational points matter. There should be one methodology rather than several, so a public body completes a single assessment. The assessment must attach to a gate in the delivery lifecycle, or it becomes documentation produced after decisions are already made. The template must be usable without specialist support, or small bodies and local authorities will not complete it. The assessment should be prepared by a person independent of the delivery team, or where the size of a body makes that impractical, reviewed independently before the gate. The methodology governs the public sector's own use of AI. It should not impose obligations on private organisations beyond Union and sectoral law. Comment 11 Affected sections: 3.3.2, 3.9.5, 3.11.3, 3.13, Annex B, Annex F The commitment to redress exists in four places. Section 1.1 refers to clear redress mechanisms. Section 3.9.6 commits to mechanisms for redress. Annex A describes an aspiration to establish a robust and accelerated legal mechanism. The control framework refers to procedures for incident reporting, escalation and remediation. None states to whom an incident is reported, how a citizen reports harm, what is published, or within what period. We propose that the incident pathway be defined in operational terms. Establish a single reporting channel for citizens, public servants and suppliers. Define what constitutes a serious incident, aligned with Article 73 of the AI Act, so that a single report discharges both national and Union obligations where the law permits. State the internal reporting timeline and the escalation route. Publish an annual account of serious incidents, systems suspended or withdrawn, corrective actions and time to remediation, in aggregated and anonymised form that protects personal data, trade secrets and security-sensitive information. Include reversal and override rates, and the number and resolution time of requests for human review, in the measurement framework. The Strategy should state explicitly that transparent incident reporting is treated as evidence of good governance rather than as failure. If reporting an incident is treated as an admission of fault, incidents will be resolved quietly and the national record will show a safety performance that does not exist. Comment 12 Affected sections: 3.4.1, 2.5.8, 3.1.2, 3.3.2, 3.6.3, Annex B, Annex F Section 3.4.1 states that the government will work towards AI-first procurement models by 2032. The control framework refers to approval gates and to approved and certified delivery partners. There are no standard contractual requirements. We propose two changes. First, replace the AI-first framing with a problem-first framing, committing that procurement will assess whether AI is the appropriate solution to a defined problem and that AI-enabled options are evaluated on outcomes rather than on technology category. Section 3.1.2 already states that AI initiatives will be selected on measurable outcomes and not on technological novelty. The AI-first formulation states the opposite, and it appears twice, in Section 3.4.1 and in the description of the Government Innovation Hub. Second, mandate a standard set of contractual requirements for AI procurement. These should cover technical documentation sufficient for oversight, rights of independent audit, ownership and deletion of data, portability of exportable data and digital assets in interoperable formats, substitutability of models and components where technically and legally feasible, avoidance of lock-in, open standards, documented accuracy and fitness for purpose, continuous monitoring of failure and bias, liability and remediation, tested exit, complete audit logs, publication of lifecycle cost, and environmental impact where material. Audit rights should be scoped to the oversight objective and should protect trade secrets, with recognised certifications accepted where they provide sufficient evidence. We would add one point on lot sizing. Large tenders normally require minimum turnover and evidence of comparable prior contracts. Applied to national AI programmes that test is circular, because a company can only qualify by having already delivered a programme of similar scale, and Cyprus has never run one. Every domestic supplier is excluded before its capabilities are examined. Dividing flagship programmes into lots that a small domestic supplier can bid for requires no additional funding, no new institution and no legislation, only a decision taken when the tender is drafted. Comment 13 Affected sections: 3.4.2, 3.5, Annex A, Annex C The Strategy states that private-sector AI adoption is voluntary. Other provisions qualify that significantly. Section 3.4.2 provides that every sizeable organisation must formalise an AI adoption plan. Annex C provides that in regulated sectors institutional AI strategies become part of supervisory reporting with the same legal weight as risk-management frameworks, and that private enterprises dealing with critical and high-risk systems must share their AI strategy and acceptable use policy in order to obtain or renew participation in state-subsidised programmes, access to national compute or datasets, and new or renewed operating licences in strategic sectors. The terms sizeable organisation, critical and high-risk systems, strategic sectors and basic compliance are not defined. We propose four changes. Preserve the voluntary character of private-sector adoption, and recast the requirement that every sizeable organisation formalise a plan as guidance. Remove the connection between disclosure of an enterprise AI strategy and the grant or renewal of operating licences. Do not give institutional AI strategies the same legal weight as risk-management frameworks by way of a strategy document, since supervisory reporting obligations should be established under Union and sectoral law within the mandate of the competent regulator. Where eligibility conditions attach to state-supported programmes, national compute or public datasets, they should be transparent, risk based, proportionate and non-discriminatory, requiring only the information necessary and accepting targeted attestations rather than a full institutional AI strategy. A corporate AI strategy contains forward-looking commercial plans, technical architecture, security controls and supplier relationships. Conditioning market access on its disclosure, through a strategy document rather than legislation and with undefined triggering terms, creates legal uncertainty for every company operating in or considering Cyprus. Comment 14 Affected sections: 3.5, Annex C Section 3.5 and Annex C propose an AI Judge Capability for very basic, factually uncontested cases valued under five thousand euro, subject to legal constraints and human oversight. They also propose AIREG, a blockchain-based registry providing immutable certification of AI assets. On the judicial provision, we propose replacing the term AI Judge Capability with AI-assisted judicial administration and decision support, and stating expressly that AI may support administration, research and analysis but does not determine case outcomes, issue judgments or exercise judicial authority. The competent judge should retain independent judgment, decisional authority, responsibility for the reasoning and accountability for the outcome. Any deployment should protect the right to a fair trial, procedural fairness, contestability and effective human oversight. Judicial and case-outcome uses fall within the high-risk categories of the AI Act. On AIREG, we propose that its scope, legal effect and disclosure requirements be defined. Registration should be voluntary and evidentiary, supporting proof that a record existed at a point in time and has not been altered. It should not create or determine ownership, alter copyright or intellectual property rules, or be presented as establishing Union-wide presumptions, and it should not require disclosure of model weights, training data, source code or trade secrets. Terminology carries commitments. A national strategy that announces an AI Judge, whatever the safeguards in the surrounding text, invites every reader to conclude that Cyprus intends machines to decide cases, and that impression will outlive the caveats. Comment 15 Affected sections: 1.1, 2.4, 2.5.6, 2.5.8, 3.7.3, Annex G Sovereignty is central to the Strategy and is used in at least three different senses across the document. Sometimes it means physical control of compute, sometimes legal and regulatory autonomy, sometimes the ability to decide independently while relying on partners for delivery. Sovereignty that is not defined cannot be planned, budgeted, procured or measured. We propose a single operational definition across five layers, each with its own test, owner and indicator. Infrastructure sovereignty concerns where computation runs, under whose jurisdiction, and whether critical services continue if a supplier relationship ends. Data sovereignty concerns who decides access to national datasets, on what legal basis, with what auditability. Model sovereignty concerns the ability to choose, inspect, adapt, evaluate and replace the models on which public services depend. Application and assurance sovereignty concerns the ability to verify independently that a system performs as claimed. Talent sovereignty concerns whether the knowledge to specify, commission, operate and supervise these systems sits inside Cypriot institutions. The definition should go into the glossary in Annex G, be used consistently, and be supported by a small number of indicators. The Strategy should state where Cyprus intends to be on each layer by 2032. Three points keep the framework practical. Each layer is measured through verifiable outcomes and controls, and each can be satisfied while working with international partners. Inspection means access to information and evidence proportionate to the use case, sufficient to evaluate performance, limitations, safety, security and compliance. Talent sovereignty means the capability to specify, commission, evaluate and govern, which is where the existing education and skills provisions already do most of the work. Comment 16 Affected sections: 3.7.1 to 3.7.5, 3.10.2, Annex F Section 3.7.3 states that infrastructure choices should be guided by interoperability, portability, vendor diversity, supply chain resilience, security and long-term sustainability. This is the right list, expressed as guidance rather than requirement, and none of it is measured. We propose that the guidance be converted into testable criteria applied at procurement and reviewed annually. First, legal and regulatory exposure, meaning the extent to which applicable legal regimes may compel access to data or affect service continuity, assessed for the relevant workload alongside the technical and contractual safeguards available. Second, key control, meaning who holds encryption keys and administrative access. Third, exit, meaning a documented and tested plan to move a workload to another provider within a stated period. Fourth, dependency, meaning a published register of critical dependencies across compute, models and platforms. Fifth, continuity, meaning what happens if a supplier relationship ends at short notice. Two indicators should be added. One measuring material dependency on any single provider across compute, model and platform layers, regardless of nationality or place of establishment, assessed through workload criticality, substitutability, interoperability, tested exit and continuity. One measuring the share of critical public workloads subject to legal regimes permitting compelled access from outside the Union without effective safeguards. The first measures resilience, the second measures the exposure that motivates the sovereignty objective, and neither substitutes for the other. We recommend that Cyprus adopt the European Commission's Cloud Sovereignty Framework rather than design national criteria. It assesses providers against eight sovereignty objectives, assigns assurance levels, and was applied by the Commission in April 2026 to a sovereign cloud award. Adopting it gives Cyprus a tested methodology at no development cost and aligns national procurement with Union practice. The risk in a hybrid model is not the partnership itself but the absence of an exit path. Sovereignty as reversibility is testable in a way that sovereignty as ownership is not. Comment 17 Affected sections: 3.2, 2.5.6, Annex C, Annex D The Strategy treats data modernisation and the National Data Policy as prerequisites for AI adoption, which is correct. It proposes a federated architecture, a national data layer and a national API fabric, and a National Health Data Repository. Annex C states that healthcare data and interoperability will follow HL7 FHIR, SNOMED CT and ICD, and will reflect European Health Data Space principles. We propose three additions. First, state the sequencing explicitly and accept that digital maturity differs across public bodies, so that AI adoption is staged according to the readiness of each organisation rather than applied uniformly. Second, establish a formal data access framework, including data access committees with published decision criteria and published decisions, so that access to high-value national datasets is governed by a visible process rather than by negotiation. Third, convert the reference to European Health Data Space principles into an operational commitment, identifying the national bodies responsible for primary and secondary use of health data, stating how Cyprus will connect to the cross-border infrastructures, and setting a date. The semantic and technical standards named in Annex C should be carried into the main body of the Strategy, since they apply well beyond healthcare. Data sovereignty is not achieved by holding data nationally. It is achieved by controlling, documenting and being able to justify decisions about access. A federated architecture without published access rules relocates discretion rather than governing it. Comment 18 Affected sections: 2.5.8, 3.7, 3.8, 3.8.6, Annex D The Strategy addresses compute, data, skills and governance. On models it says relatively little. The Government Innovation Hub is to guide developments for sovereign specialised learning models, and a legal language model trained on Cyprus law is proposed. There is no national position on which models the state will use, on what basis it will choose them, how it will evaluate them, or how it will change them. In the delivery lifecycle, model approach appears once, in Annex B Stage 2, with no criteria attached. We propose a short model layer subsection covering five points. First, a model selection policy enabling choice among commercial, open weight and nationally adapted models on the functional requirements and risk profile of each use case, with criteria covering performance and accuracy including Greek-language performance, security, privacy, safety, transparency, legal compliance and licensing, interoperability, operational support, total cost of ownership, and substitutability. Second, a scoped weighting for open weight models in defined use categories where inspection, independent evaluation or long-term availability is material to the public interest, applied through the criteria of a specific procurement rather than as a general preference or a mandatory condition. Third, national evaluation capability, meaning the ability to test a model against Cypriot requirements. Fourth, adaptation rather than creation, meaning that Cyprus fine-tunes existing models and participates in European initiatives rather than financing a national foundation model. Fifth, portability, so that the underlying model can be replaced without rebuilding the service. Model choice is where dependency is created and hardest to reverse. In agentic systems the lock-in accumulates in orchestration, tool integration and evaluation rather than in the model itself, so the Strategy should commit to open, vendor-neutral interoperability standards adopted from recognised international bodies. Portugal released a national model for European Portuguese in July 2026 for an initial public investment of approximately five and a half million euro, built by extending an existing open European model rather than training from scratch. That is the cost envelope and the method a country of Cyprus's size should plan against. Comment 19 Affected sections: 2.5.1, 3.8, 4.3, Section 5 item 4, Annex C The Strategy proposes a National AI Compliance Framework, a certification registry, an annual audit function and centres of excellence, and positions Cyprus as a compliance and testing hub. It does not describe the capability required to perform assurance, or identify who will be qualified to do it. We propose an assurance capability plan with three elements. First, technical evaluation capacity, meaning people and facilities able to test AI systems for accuracy, robustness, bias, security and compliance, hosted in the research ecosystem and available to the public sector and industry. Second, an explicit assessment of whether Cyprus should host one or more notified bodies under the AI Act, and if so what accreditation and staffing that requires and by when. Third, deliberate development of AI assurance, audit, evaluation and compliance services as an export industry building on the existing professional services base. Where the capability performs conformity assessment under the AI Act, it should operate within the applicable accreditation and notified body framework. It should not create additional national certification, registration or audit requirements, and it should not extend to the supervision of general purpose AI models as such, which is the role of the European AI Office. Voluntary evaluation and compliance support should complement the Union framework and should not become a prerequisite for procurement, deployment or market access. This is the commercial opportunity best matched to what Cyprus already has. Assurance is also the layer at which sovereignty becomes economically productive. A country that can independently verify AI systems does not need to own them in order to trust them. Comment 20 Affected sections: 1.5, 3.10.3, Section 5, Annex F The Strategy is not silent on money. Section 3.10.3 states that funding may combine public investment, European co-funding through EuroHPC and Digital Europe, and structured cost-sharing. Section 3.3.1 states that budget allocations will be aligned with strategic performance goals agreed between the Ministry of Finance and the Deputy Ministry. The Sovereign Investment Matching Fund carries a stated cap of one million euro per round per company. What is absent is scale and attribution. There is no total investment envelope, no figure attached to any of the four proposed funds, no capital or operating cost for the national compute infrastructure, and no budget or named delivery owner against any individual action. The funding sources are named in the conditional. We propose a costed delivery plan for the period to 2032, published as a companion document and updated annually. For each major action it should state the responsible organisation, the delivery lead, the timetable and interim milestones, the expected deliverables, the estimated budget and funding source, the staffing requirement and the principal dependencies. Cost should be assessed across the full lifecycle rather than at procurement, including operation, maintenance, security, audit, data management, model monitoring, licensing, support, upgrade and decommissioning. The total public investment envelope and its expected sources should be stated. Estonia, a country of comparable population with a stronger digital baseline, backed its AI and Data Action Plan for 2024 to 2026 with a stated package of approximately eighty-five million euro. A strategy that names no figure invites the assumption that no figure has been agreed. Comment 21 Affected sections: 3.3.1 and Figure 2 and all subsections, 4.2, Section 5 items 1 and 3 The Strategy proposes a National AI Authority including a Government AI Accelerator, an Interministerial AI Council, a National AI Taskforce, a National AI Infrastructure Committee, a National Ethics and Values Committee, a National AI Misinformation and Security Council, a National AI Skills Observatory, a Government Innovation Hub, an Industrial Centre of Excellence, a National AI Cybersecurity Centre of Excellence, AI Officers in every ministry and AI Champions in every ministry. Additional bodies appear elsewhere. Figure 2 is a useful diagram and it is not an accountability instrument. It shows which bodies exist and how they are grouped. It does not show, for any given decision, which body decides, which approves, which is consulted and which remains answerable for the outcome. We propose two changes. First, publish a governance and accountability matrix identifying, for every function, which body sets policy, which approves, which delivers, which supervises and which is accountable, together with escalation and dispute resolution procedures. Second, consolidate. The monitoring and advisory functions currently distributed across four separate bodies could be delivered by fewer standing committees reporting through the National AI Taskforce, and the three centres of excellence could share a single governance and administrative structure while maintaining distinct technical missions. Where an existing institution can perform a function, the Strategy should say so rather than create a new body. The objection is arithmetic. The proposed architecture requires a substantial number of senior, scarce and specialised people to staff committees, and the Strategy itself identifies limited execution capacity as one of the two structural weaknesses it must overcome. The risk is not that these bodies will conflict. It is that several will exist only on paper. Comment 22 Affected sections: 3.10.1, 3.7, 3.4.1, Annex D, Annex F Section 3.10.1 commits to green computing principles, renewable energy integration where feasible, efficient cooling and shared services. This is one short subsection with no measurement, no reporting obligation, no procurement weighting and no target. We propose four changes. First, state that data centres supporting national AI infrastructure will report energy and water key performance indicators in line with Article 12 of the recast Energy Efficiency Directive and Commission Delegated Regulation (EU) 2024/1364, which apply to facilities with installed information technology power demand of at least 500 kilowatts and cover energy consumption, capacity utilisation, waste heat, renewable energy and both total and drinking water consumption. Second, publish national aggregate figures annually, reusing information already reported under Union and national mechanisms rather than creating a duplicative national channel, with aggregation that protects trade secrets and security-sensitive information. Third, include energy and water performance as weighted criteria in the procurement of AI infrastructure and services. Fourth, add environmental indicators covering energy intensity, water consumption, share of renewable supply and waste heat recovery. This is a matter of national self-interest rather than general environmental preference. Cyprus operates an isolated electricity system with no interconnection to a continental grid, which makes additional large and inflexible loads more consequential than in most Member States. Cyprus also faces severe water stress, and the Strategy itself identifies water management as a research priority. Data centre cooling is water intensive. The European Commission is developing a Union rating scheme for data centres with labels expected from 2027. Facilities that already measure and report will be able to demonstrate performance from the outset. Comment 23 Affected sections: 1.5, 2.5.2, 3.4, 3.5, 3.11, Section 5 item 4, Annex C, Annex F The Strategy has targets but very few milestones. A target is an endpoint. A milestone is a dated checkpoint with an owner and published evidence. Quantified endpoints appear throughout Section 1.5 and Annex C, including a recommended productivity improvement of 15 per cent, a recommended GDP expansion of 12 per cent, more than three thousand AI professionals, a 40 per cent reduction in citizen waiting times, and sector figures for shipping and financial services. Almost all are dated 2030 or 2032 with nothing in between. Dated commitments appear in only one place, in Section 5. The measurement framework is not yet operational. Annex F is described as a sample and as indicative. It lists categories of indicator rather than indicators, with no baseline value, no numerical target, no data source, no measurement method, no reporting frequency and no organisation named as responsible. The implementation timeline in Section 1.5 uses relative bands of 0 to 8 months, 6 to 12 months and 12 to 24 months, with no anchor date, followed by a band labelled 2026 to 2032 that overlaps them. We propose six changes, of which the first three are the priority. Publish a milestone schedule with absolute dates rebased to the date of adoption, each milestone naming the responsible body and the evidence to be published. Complete Annex F, attaching to every principal indicator a baseline, a numerical target, a target date, a data source, a measurement method, a reporting frequency and a named responsible organisation, with baseline measurement completed within twelve months of adoption. Provide for one mandatory mid-point review in 2029, conducted by an independent external evaluator, published in full and accompanied by a corrective action plan where performance is behind trajectory. Reconcile the adoption targets to a single headline definition. Publish the assumptions behind the productivity and GDP projections or restate them as scenarios. Report annually to the House of Representatives with public debate. On the arithmetic, the figures do not reconcile. The Strategy records enterprise AI adoption at 9.27 per cent in 2025 following annual progression of 17.3 per cent, and sets a target of 75 per cent industry adoption by 2030. Held at the rate the document itself observes, 9.27 per cent compounds to approximately 21 per cent by 2030. Reaching 75 per cent within five years requires sustained annual growth of roughly 52 per cent, about three times the observed rate. Extending the horizon to 2032 still requires roughly 35 per cent annual growth. Comment 24 Affected sections: 2.3.4, 2.5.1, 3.12, Annex A The Strategy positions Cyprus as a bridge between the European Union and neighbouring regions, refers to readiness to participate in the Global Partnership on AI, and aligns with the OECD principles. It does not refer to the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, and it does not describe what the bridge role means in practice. We propose two additions. First, address the Framework Convention explicitly, stating Cyprus's position and how the Convention relates to obligations arising under Union law. This matters because the Convention is the principal instrument through which non-Union states in the region engage with rights-based AI governance, and it is therefore directly relevant to a bridge role. Second, convert the bridge positioning into concrete commitments, for example a regional forum on AI governance hosted in Cyprus, cooperation programmes with Eastern Mediterranean and Middle Eastern partners on assurance and standards, and participation in international capacity building. This is the area where Cyprus has the clearest comparative advantage and the least developed plan. Regulatory credibility is transferable in a way that compute capacity is not. If Cyprus becomes the place where regional actors learn how European AI governance works in practice, the bridge role generates both influence and revenue. Comment 25 Affected sections: 3.6 (International alignment), 2.5.8, 3.12, Annex C Section 3.12 adopts a broad and outward-looking approach to international engagement. The treatment of education and human capital is narrower. Under International alignment, the Strategy provides that the UK National AI Skills Framework will inform occupational pathways and competency structures, complemented by collaboration with Finland, France and Estonia on teacher training, AI literacy and ethics in education. The Strategy separately states that it references international best practices from Finland, France, Estonia, the UK and the UAE across education, governance, infrastructure and public-private collaboration. The criteria for selecting these jurisdictions are not stated, and it is unclear whether the list is illustrative or exhaustive. Section 1.7 describes a wider literature review covering the national strategies of Cyprus, Greece, Malta, France, Estonia, the UAE, Finland and the UK, so the evidence base is broader than the education provisions suggest. We propose two changes. State the criteria on which international reference points for AI literacy have been selected, and state expressly whether the list is illustrative. Reframe the provision as open and non-exhaustive, so that Cyprus can draw on relevant expertise and good practice from a wider range of European and international jurisdictions as the field develops, including emerging and established technology ecosystems beyond Europe such as India, where these offer complementary expertise or opportunities for mutual capacity building. Alignment with Union law, values and standards should remain the governing constraint. AI literacy is unusually broad and fast-moving, spanning technical competency, ethical awareness, responsible use, critical thinking, digital inclusion, workforce preparedness and general societal understanding. No group of four or five jurisdictions is likely to hold the best available practice across all of these, and the distribution will change over the life of the Strategy. Comment 26 Affected sections: 3.3.1 and Figure 2, 3.3.1.4, 3.4.1, 3.9.6, 3.11.2, Annex A, Annex C, Annex F The following are drafting matters rather than questions of policy. We raise them because they are inexpensive to correct and because a document of this standing will be read closely by suppliers, by other Member States and by the institutions of the Union. - The body established under Section 3.3.1.4 is titled the National AI Infrastructure Committee in its own heading, and the National AI Infrastructure Council in the Section 3.3.1 list, in Figure 2 and again in Annex A. - Figure 2 presents the Government AI Accelerator and the Innovation Hub as a single body. The text treats the Government AI Accelerator as a component of the National AI Authority and the Government Innovation Hub as a separate innovation body. - In Figure 2 the description attached to the AI-Industrial Centre of Excellence is the tracking of talent, skills gaps and workforce readiness, which is the function of the AI Skills Observatory and is stated for that body in the tier above. - The names given to the centres of excellence in Figure 2 do not match those used in the Section 3.3.1 list. - The Cyprus AI Security and Certification Authority is referred to in Section 3.9.6 and nowhere else, and is not defined. - Industry adoption targets appear at different values and against different dates in Section 5 and in Annex C, and government adoption targets appear at different values in Section 3.4 and in Annex C. - The implementation timeline in Section 1.5 combines relative time bands with a calendar band beginning in 2026, which overlaps them. - We propose that a single name be adopted for each body and used consistently in the headings, in the Section 3.3.1 list, in Figure 2 and in the annexes, that Figure 2 be redrawn so that it matches the text it illustrates and each body carries its own description, and that the numerical targets be reconciled." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",CITEA,"CITEA Comments and Recommendations on the Cyprus National AI Strategy 2032 Formal policy submission to the Deputy Ministry of Research, Innovation and Digital Policy Cyprus Information Technology Enterprises Association (CITEA) Submitted by the President of CITEA CITEA welcomes the work undertaken in preparing the Cyprus National AI Strategy 2032. The Strategy is ambitious, comprehensive and sets an important direction for Cyprus. It recognises the effect Artificial Intelligence will have on competitiveness, productivity, public services, skills, innovation and economic development. CITEA supports that direction. The priority now is implementation. For the Strategy to succeed, each major initiative needs an identified owner, committed funding, a timetable, defined KPIs and a mechanism for intervention when delivery falls behind. Industry must also have a meaningful role in the decisions that affect adoption, funding and implementation. CITEA submits the following recommendations. 1. National AI Performance Scorecard and KPIs Reference: Section 3.11 - ""Measuring Impact and National KPIs"" Suggestion CITEA recommends strengthening the existing KPI framework through a comprehensive National AI Performance Scorecard, supported by a formal measurement and governance structure. Each KPI should include: • a clear definition; • baseline value; • annual and multi-year targets; • accountable owner; • responsible Ministry or organisation; • data source; • reporting frequency; • calculation methodology; • dependencies; • escalation criteria. The Scorecard needs to distinguish between implementation metrics and impact metrics. Implementation metrics would include matters such as training programmes delivered, AI pilots completed, funding programmes launched, public services digitised, AI infrastructure deployed and the number of organisations participating. Impact metrics need to show what those activities have produced in practice, including AI adoption rates, productivity improvements, economic contribution, investment attracted, export growth, SME adoption, products commercialised, improvement in public services, citizen trust and wider societal outcomes. Justification The Strategy already identifies AI adoption, public-sector modernisation, talent, trust, compliance and economic impact as areas in which progress has to be assessed. What is missing is a common measurement structure that allows Government, industry and other stakeholders to work from the same baselines and targets. Without it, there is a risk that progress will be reported in terms of programmes launched and activities completed rather than the results achieved. A National AI Performance Scorecard would provide a consistent basis for reporting, early identification of underperforming initiatives and timely intervention. 2. Formal Six-Month Implementation Review in 2027 CITEA proposes a formal review of implementation at the end of June 2027. By that point, the Government needs to be in a position to report what has been implemented, how much funding has been committed and deployed, how many companies and SMEs have adopted AI, how many pilots have entered production, how many public-sector projects are operational, and what productivity and economic gains can already be identified. Where agreed KPIs have not been achieved, corrective measures must follow in the second half of 2027. Depending on the cause, these may involve additional funding, budget reallocation, programme redesign, changes in delivery organisations, accelerated procurement mechanisms, removal of administrative barriers or reassignment of responsibility. The purpose of this six-month review is practical. It gives Cyprus an early opportunity to identify what is working, what is not, and what needs to change before delays become embedded. 3. Clear Roles, Responsibilities and Decision-Making Framework Reference: Section 3.3 - ""Governance and Controls"" Suggestion CITEA recommends a detailed Roles, Responsibilities and Decision-Making Framework covering the organisations involved in implementation. This framework needs to set out the responsibilities, decision rights, consultation requirements and reporting obligations of the responsible Ministry or Deputy Ministry, the National AI Authority, the Interministerial AI Council, specialised advisory committees, delivery organisations, regulators, public-sector entities, research institutions, local authorities, private-sector representatives and industry associations. For every major initiative, the Strategy must identify the organisation responsible for delivery, the Ministry with policy ownership, the owner of the relevant KPI, the body controlling the budget, the decision-making authority and the person or organisation answerable for delay. This level of definition is necessary where initiatives cross several Ministries, agencies and sectors. It will reduce overlap, make escalation easier and allow delivery problems to be addressed quickly. 4. Dedicated AI Implementation Body with Budget and Authority CITEA recommends the establishment of a national AI implementation body or executive committee with its own approved budget and delegated authority. Its remit must extend beyond consultation and coordination. It needs the power to initiate projects, approve or recommend funding, accelerate priority initiatives, resolve cross-Ministry obstacles, monitor delivery and intervene where agreed targets are slipping. It must also be able to trigger corrective action when progress falls below plan. A body given responsibility for implementation needs the financial capacity and decision-making authority to carry that responsibility through. 5. Detailed Implementation Roadmap to 2032 Reference: Section 1.5 - ""Implementation Timeline and Success Metrics"" Suggestion CITEA recommends a detailed implementation roadmap covering the period to 2032, with milestones, timelines, deliverables, responsible organisations, dependencies, budgets and KPIs. The roadmap needs to distinguish immediate priorities, 2027 milestones, medium-term targets and long-term outcomes. Annual budget requirements and the organisation responsible for each deliverable must form part of the same plan. For every major initiative, the basic information must be available in one place: who owns it, what budget is available, when delivery is due, which KPI will be used and what result is expected. This would give the Strategy a practical management structure and provide a common basis for monitoring progress across Government and industry. 6. Dedicated €1 Billion National AI Investment Programme 2027-2032 Reference: Section 3.10.3 - ""Funding and Renewal Model"" CITEA strongly recommends that Cyprus commit to a National AI Investment Programme of at least €1 billion for the period 2027-2032. The financial commitment needs to match the ambition set out in the Strategy. AI is becoming a major driver of national competitiveness, productivity, innovation, investment, economic growth, digital sovereignty and public-sector modernisation. A programme of this scale cannot depend on fragmented calls and annual discretionary budgets. CITEA proposes a multi-year national investment envelope with funding planned from 2027 through 2032. Indicative Investment Profile Year Proposed Investment 2027 €100 million 2028 €140 million 2029 €170 million 2030 €190 million 2031 €200 million 2032 €200 million Total €1 billion The programme needs to begin strongly in 2027 and increase as infrastructure, market capacity and AI adoption expand. The €1 billion can be built from a combination of: • Government funding; • European Union programmes; • structural funds; • AI Factory investments; • digital infrastructure; • private-sector co-investment; • public-private partnerships; • SME adoption programmes; • innovation and commercialisation programmes; • skills programmes; • AI infrastructure, cloud, data and compute; • public-sector AI transformation. Financial Transparency CITEA asks that the Strategy report separately how funding is allocated to Research, Innovation, AI Adoption, Infrastructure, Skills and Public-Sector Transformation. Research expenditure must be reported separately from adoption expenditure so that Government, industry and the public can see how much funding is reaching companies and the wider economy. The investment framework also needs to connect expenditure to outcomes. For each major funding line, the Strategy must state the intended result, the amount committed and the economic return or public value expected. 7. Research, Innovation and AI Adoption Must Be Clearly Separated CITEA’s position is that Research, Innovation and AI Adoption are different activities and need different objectives, programmes, funding mechanisms, evaluation criteria and KPIs. Research Research concerns scientific discovery, advanced research, the creation of new knowledge, academic excellence, scientific publications and longer-term technological development. Appropriate Research KPIs include scientific output, publications, research excellence, new knowledge and patents arising from research where applicable. Innovation Innovation concerns the conversion of ideas and intellectual property into products, companies and commercial activity. It includes new products, IP, commercialisation, startups, scale-ups, new markets, investment and exports. Appropriate Innovation KPIs include products reaching the market, IP created, private investment attracted, export revenue, international customers and companies scaling internationally. AI Adoption AI Adoption concerns the use of existing technologies by organisations to improve productivity, competitiveness, cost structures, decision-making, revenue, customer service, operational efficiency and workforce capability. Appropriate Adoption KPIs include the number of companies implementing AI, productivity gains, cost reductions, revenue improvements, employees reskilled, processes automated and operational efficiencies achieved. A company implementing an existing AI solution must not be forced to present that project as research in order to receive support. Cyprus will not achieve broad business adoption if the mechanism for deploying proven technology is treated in the same way as a research grant. 8. Strong Industry Participation in SME AI Funding The ICT industry needs a formal role in the design, implementation and evaluation of AI funding programmes for SMEs. Those programmes have to reflect the costs and barriers businesses face in practice. These include implementation and integration costs, cloud infrastructure, cybersecurity, data readiness, staff training, consultancy and access to specialist expertise. CITEA recommends establishing an AI Adoption for SMEs Committee, with CITEA in a leading or co-leading role alongside the relevant Government authorities and business organisations. CITEA represents many of the companies that will develop, integrate and support the technologies used by SMEs. That experience can help ensure that funding schemes are workable, reach the market quickly and are assessed against business outcomes. 9. Horizontal ""AI for SMEs"" Programme The Strategy needs an AI for SMEs in All Sectors programme with its own budget, adoption targets, implementation mechanism and KPIs. The programme may include AI vouchers, implementation grants, cloud and compute credits, employee training, cybersecurity support, consultancy and integration support. Most SMEs will not develop their own AI technologies. Their immediate opportunity is to adopt available tools and integrate them into existing operations. A national programme focused on that objective can produce productivity gains across a much larger part of the economy than sector-specific research schemes alone. 10. Public Procurement Must Match the Speed of AI Traditional public procurement procedures are generally too slow for technologies developing at the pace of AI. A procurement process lasting 12 to 18 months can result in Government acquiring technology against requirements that were written long before implementation begins. During that period, products, models, costs and technical approaches can change substantially. CITEA recommends specific mechanisms for AI and emerging technologies, including rapid proof-of-concept programmes, AI sandboxes, pre-commercial procurement, innovation partnerships, technology framework agreements, controlled pilot programmes and fast-track procurement procedures suited to emerging technologies. The public sector needs a process that allows it to test a solution, evaluate the result, improve the design and scale what works while maintaining transparency, security and proper oversight. Without a procurement route that reflects the pace of the technology, public-sector AI programmes will face avoidable delays. 11. Conflict-of-Interest and Supplier Neutrality Framework Government needs private-sector expertise to develop and implement AI policy. That participation has to be accompanied by safeguards that prevent an advisory role from creating an unfair commercial advantage. CITEA recommends a formal Conflict-of-Interest and Supplier Neutrality Framework. Where a technology company, consultancy or supplier is engaged to advise a Ministry, public authority or national AI governance body on strategy, architecture, technical specifications, procurement design, funding criteria or supplier evaluation methodologies, that organisation, its parent company, subsidiaries and relevant affiliates must normally be barred from bidding for directly related implementation work arising from the engagement. The restriction must apply for the duration of the advisory engagement and for a defined cooling-off period afterwards. CITEA proposes that a period of approximately 12 to 24 months be considered, depending on the nature of the engagement. Any exception requires an independent assessment and documented approval confirming that no unfair competitive advantage has been created. The same principle applies where companies participate in the design of funding programmes. A firm involved in setting programme criteria must not gain privileged access to the resulting funding or influence conditions in favour of its own technology. The purpose is to preserve industry participation while protecting fair competition and confidence in public decision-making. 12. ICT and Software Must Be a Priority Sector The omission of ICT and software as a standalone priority sector needs to be reconsidered. The ICT sector is an economic sector in its own right, with strong GDP contribution, export potential, high-skilled employment, substantial AI absorptive capacity and the ability to develop products and services that can scale internationally. Cyprus needs to pursue two parallel objectives. The first is AI adoption across the economy. The second is the development of an internationally competitive Cyprus AI industry capable of creating and exporting products, technologies and services. For the ICT and AI industry, relevant indicators include AI software exports, international recurring revenue, new AI products launched, Cypriot IP created and retained, international customers acquired, private investment attracted and high-value technology jobs created. Cyprus must aim to be a producer and exporter of AI technology as well as an adopter. 13. Retail and Wholesale Should Be Explicitly Included Retail and wholesale are significant parts of the Cypriot economy and SME base and need explicit recognition in the Strategy. Retail has particular importance for Cyprus because of its relationship with tourism, hospitality, payments, logistics, e-commerce, consumer experience and the wider visitor economy. Tourist expenditure extends well beyond accommodation, restaurants and transportation. Retail forms part of the visitor experience and of the economic value generated by tourism. AI can deliver practical gains in demand forecasting, inventory optimisation, automatic replenishment, pricing, customer personalisation, multilingual interaction, workforce planning, supply-chain management, e-commerce and payments. CITEA proposes that Retail be added as a priority sector or, alternatively, supported through a specifically funded Retail & Commerce AI Transformation Programme. 14. Broader Sector Coverage The eight priority sectors identified by the Strategy are important, but they do not cover substantial parts of the economy and SME base. Manufacturing, agri-food, energy and utilities, construction, retail and wholesale, transport and logistics, and ICT and software all require access to structured AI adoption programmes. Where the existing eight-sector model is retained, the Strategy needs to specify what support companies outside those sectors can access, under which programme and with what budget. General statements on inclusion are insufficient unless firms outside the priority sectors have an identifiable route to funding and implementation support. 15. Open Architecture, Interoperability and Vendor Independence Public AI investments need to avoid unnecessary long-term dependency on individual suppliers. CITEA recommends that public AI systems, where technically feasible, use open standards, interoperable architectures, documented APIs, portable data structures and defined exit mechanisms. Government entities must retain control and ownership of their data and have practical means of moving data, applications, AI workloads and models between suppliers where required. Procurement evaluation needs to consider vendor dependency, migration cost, interoperability, long-term operating cost and exit cost alongside the initial project price. National AI infrastructure must be designed so that dependence on a single cloud provider, consulting organisation, model provider or technology vendor does not become embedded in public systems. 16. National Data and AI Infrastructure AI adoption requires access to high-quality data, cloud infrastructure and computing capacity. The Strategy needs continued investment in trusted national data platforms, secure Government APIs, interoperable datasets, national data spaces, AI Factory resources, compute infrastructure, cloud capability and cybersecurity infrastructure. Access must extend to SMEs, startups, established technology companies and innovative businesses, alongside universities and large organisations. Pricing, eligibility and allocation rules need to support commercial use as well as research activity. If national infrastructure is intended to support the economy, companies must be able to access it on terms that allow them to build and deploy products. 17. Skills, ICT Upskilling and Workforce Transformation AI skills policy needs to reach well beyond universities and academic research. Cyprus requires rapid reskilling and upskilling across the existing workforce, including SME employees, CEOs and business leaders, managers, professionals, public-sector employees, technical specialists and educators. CITEA also recommends a specific national track for upskilling and reskilling employees working in Cypriot technology companies. The country cannot deliver an ambitious AI programme unless its own ICT sector has the skills to design, integrate, secure, support and export AI solutions. Software developers, data professionals, cloud engineers, cybersecurity specialists, business analysts, consultants, project managers and technical support teams will all require new capabilities as AI becomes embedded in mainstream software and business systems. The ICT skills programme needs to cover applied AI development, AI agents, data engineering, machine learning, AI architecture, cybersecurity for AI, responsible AI, AI governance, model integration, cloud and compute infrastructure, API-based AI development and the commercial deployment of AI solutions. Training needs to be tied closely to real projects and market requirements. The objective is to increase the number of professionals who can build and deploy AI systems successfully for customers in Cyprus and abroad, rather than measuring success by course attendance alone. Special support is also required for ICT SMEs that may find it difficult to release employees for extended training or finance advanced technical certifications. CITEA recommends support for professional AI certifications, executive education, employee reskilling, sector-specific programmes, public-sector training and the attraction of specialised international AI talent where required. Relevant KPIs can include the number of ICT professionals completing advanced AI training, internationally recognised certifications achieved, AI specialists employed by Cypriot companies, companies developing AI products, AI projects successfully deployed and export revenue generated from AI-related products and services. CITEA is prepared to work with Government and training institutions to identify the skills most urgently required by the industry and to help design programmes that remain aligned with rapidly changing technologies. 18. Reconsider the ""AI Judge"" Proposal Reference: Section 3.5 - Legal Services The proposed ""AI Judge Capability"" for low-value, factually uncontested cases creates legal, constitutional and reputational questions that go well beyond the scope of an economic and technology strategy. CITEA takes no position on judicial policy, as this falls outside our sector. We raise the point because the terminology creates a practical risk for the Strategy as a whole. A reference to an ""AI Judge"" could easily become the focus of public and media discussion and distract from the wider programme. The intended benefits can largely be achieved without assigning an adjudicative role to an AI system. CITEA recommends removing the term ""AI Judge"" from the Strategy and reframing the initiative around AI-assisted judicial administration. Appropriate applications include case administration, scheduling, transcription, document processing, document classification, legal research and workflow automation. Judicial decisions must remain within the judicial framework. Any future consideration of automated or AI-supported adjudication requires a separate consultation involving the Supreme Court, the Ministry of Justice, the Cyprus Bar Association and relevant constitutional and legal experts. The other LegalTech initiatives, including transcription, LegalTech sandbox programmes and Cyprus-specific legal language technologies, remain sound and merit continued support. 19. Measure Economic Impact, Not Only Activity Training programmes, workshops, pilots and research projects all have value, but they cannot become the principal measure of success. From 2027 onwards, Cyprus needs to track the number of companies actively using AI in production, SMEs that have adopted AI, productivity gains, cost reductions, revenue growth, AI products commercialised, exports generated, private investment attracted, high-value jobs created, public services improved, citizen satisfaction and contribution to GDP. The purpose of the Strategy is economic and societal progress. The reporting framework must reflect that purpose. 20. Maximum 5% for External Advisory and Consultancy Expenditure CITEA recognises that Government may require external expertise in specific areas during the implementation of the National AI Strategy. Specialist advice can be useful, particularly where Government does not have the necessary expertise internally. At the same time, a national AI investment programme must not become disproportionately focused on consultancy, strategy work and advisory studies at the expense of actual implementation. CITEA recommends that external advisory and consultancy expenditure be capped at a maximum of 5% of the total National AI Investment Programme and at a maximum of 5% of the budget of any individual major programme. The 5% limit must apply to strategy consulting, programme design, management consulting, governance consulting, advisory studies and comparable professional advisory services. It must not apply to companies contracted to develop, integrate, deploy or operate AI systems where the expenditure relates directly to implementation. Any proposed advisory expenditure above the 5% ceiling must require exceptional approval and a published justification explaining why the additional external advice is necessary and why the expertise cannot reasonably be obtained through Government, academia, industry bodies or existing national institutions. The classification of advisory expenditure must also be defined carefully so that consulting work cannot simply be moved into another budget category. CITEA recommends annual disclosure of the amounts spent on external advisory and consultancy services, the organisations engaged, the purpose of each engagement and the percentage of the relevant programme budget consumed. This is particularly important in a programme of the scale proposed by CITEA. With a €1 billion National AI Investment Programme, even relatively small percentages represent significant amounts of public money. A 5% ceiling already permits expenditure of up to €50 million across the full programme. The large majority of the available resources must reach implementation, technology adoption, infrastructure, skills, Cypriot businesses and projects capable of producing economic value. 21. AI Adoption KPIs Must Include Customer Experience The National AI Performance Scorecard needs to measure the effect of AI on the customer experience created by Cypriot businesses, particularly SMEs. Productivity and cost reduction are important measures, but AI adoption also needs to improve how companies serve customers, respond to them and personalise their services. CITEA recommends the inclusion of customer-experience KPIs within SME AI adoption programmes. These may measure customer response times, service resolution times, customer satisfaction, personalisation, multilingual service capability, digital-service usage, reduction in customer complaints, conversion rates and other sector-specific indicators. These KPIs need to be practical and suitable for SMEs. A small retailer, hotel, professional-services company or distributor cannot be expected to build complex measurement systems simply to participate in an AI programme. CITEA is prepared to work with Government, business associations and participating companies to develop practical Customer Experience and AI Adoption KPIs for SMEs. The aim is to demonstrate that AI investment is producing improvements that customers can experience directly, alongside gains in productivity and financial performance. 22. Establish a Major International AI Event in Cyprus Cyprus needs a major annual international AI event capable of attracting technology companies, investors, policymakers, researchers, startups, customers and international media. Countries that are serious about developing their technology ecosystems use major events to create international visibility, attract investment, generate business opportunities and connect local companies with global technology leaders. CITEA recommends establishing a flagship Cyprus International AI and Technology Event, with the ambition over time to develop an event comparable in international reach to major technology and AI exhibitions held in other countries, including events such as GITEX. The event needs to be commercially focused and internationally oriented. It can include exhibitions, product demonstrations, investment meetings, international speakers, B2B meetings, startup participation, Government programmes and opportunities for Cypriot technology companies to present their solutions to overseas customers and partners. The objective is to bring international technology companies, buyers, investors and media to Cyprus, rather than creating another event aimed mainly at the domestic audience. Government, CITEA, the private sector and the wider innovation ecosystem can work together to establish the event and build its international profile. Relevant KPIs should include international exhibitors, overseas visitors, investors attending, B2B meetings, commercial agreements generated, investment leads, international media coverage and export opportunities created for Cypriot technology companies. 23. Preference for Cyprus-Developed AI Solutions in Government Government can play an important role in building a domestic AI industry by becoming an early customer of technologies developed in Cyprus. Where a Cypriot company has developed an AI solution that meets the required technical, security, operational and commercial standards, CITEA recommends that public-sector procurement and AI adoption programmes provide a meaningful preference for Cyprus-developed technology, within the applicable legal and public-procurement framework. Public investment in AI should help create economic value inside Cyprus where suitable local capability already exists. Evaluation criteria can recognise technology and intellectual property developed in Cyprus, local technical capability, local implementation and support, contribution to employment and skills, export potential, knowledge retained in Cyprus and the long-term economic value created by the procurement. Government should also create mechanisms through which Cypriot companies can demonstrate proven AI solutions to Ministries and public organisations before large international procurement exercises are launched. A local company that has already invested in developing a working AI solution needs a realistic opportunity to demonstrate that solution to Government. Government adoption can give a Cypriot technology company an important reference customer. That reference can support international sales, exports, skilled employment, further investment and continued product development in Cyprus. The National AI Strategy needs to treat public-sector adoption as an instrument for developing the domestic AI industry as well as improving Government services. Overall CITEA Position CITEA recognises and supports the significant work undertaken in developing the Cyprus National AI Strategy 2032. The direction is strong. The next phase requires firm ownership, committed budgets, deadlines, KPIs, transparent reporting and faster implementation. CITEA strongly recommends a €1 billion National AI Investment Programme for 2027-2032, supported by an implementation structure with the authority and financial resources to deliver the programme. A formal national review must take place in June 2027. Where KPIs are below target, corrective measures need to be introduced during the second half of 2027 rather than deferred to a later review. Research, Innovation and AI Adoption need separate programmes, budgets and KPIs. ICT and software need recognition as a priority sector in their own right, while Retail requires explicit inclusion because of its economic weight and its connection with tourism and the visitor economy. Industry must have a substantive role in funding decisions, particularly in relation to SME AI adoption. Public procurement needs mechanisms that can operate at the pace of AI. Conflict-of-interest safeguards, open architectures, interoperability and vendor independence are necessary to protect public investment and fair competition. External advisory and consultancy expenditure must remain tightly controlled. CITEA proposes a firm maximum of 5%, ensuring that public resources are concentrated on delivery, adoption, infrastructure, skills and economic outcomes. The national scorecard must also capture customer experience and SME outcomes, while the skills programme needs a strong ICT-sector component so that Cypriot companies can build, deploy and export AI solutions. Cyprus also needs an international AI event with global ambition, and Government procurement should give Cyprus-developed AI solutions a meaningful preference where they meet the required standards and the applicable legal framework. CITEA is ready to take an active role in implementation alongside Government and the wider ecosystem. The Strategy has established the direction. The task now is to convert that direction into funded programmes, completed projects and economic value for Cyprus. For CITEA George Malekkos President, CITEA" "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Lina Lemessiou for NEWinsight","SUBMISSION TO THE PUBLIC CONSULTATION ON THE NATIONAL AI STRATEGY OF THE REPUBLIC OF CYPRUS 2032 BUILDING THE NATIONAL AI ASSURANCE LAYER: MAKING THE ‘TRUSTED JURISDICTION’ PROPOSITION OPERATIONAL Submitted by: Lina Lemessiou, FCA; Founder & Managing Director; NEW Insight Limited (trading as NEWinsight™) Submission basis: This response is submitted on behalf of NEW Insight Limited. Perspective: Corporate reporting, governance, assurance, quality management and professional standards. The comments are made from the standpoint of how responsibilities and obligations are evidenced, reviewed and reported, and how confidence can be supported through appropriate governance, examination and oversight arrangements. Consultation reference: Draft National AI Strategy of the Republic of Cyprus 2032, posted for public consultation on 20 July 2026. INTRODUCTORY ASSESSMENT The draft National AI Strategy 2032 provides an ambitious and thoughtful foundation for positioning Cyprus as a trusted, human-centred and EU-aligned jurisdiction for artificial intelligence. Its emphasis on governance, accountability, organisational readiness, risk-based controls and role-specific capability is particularly welcome. The comments below focus on a specific implementation question: how the Strategy’s trust proposition can be supported by a coherent national assurance framework. The Strategy already refers to governance, auditability, certification and internal or external assurance where appropriate. What remains is to distinguish their respective purposes and translate them into defined responsibilities, criteria, evidence requirements, competence requirements and oversight arrangements. Trust is not produced by governance structures or assertions alone. It is strengthened when responsibilities and criteria are clear, relevant evidence is retained, examinations are performed by competent and appropriately objective or independent parties, and those performing them are themselves subject to suitable quality management and oversight. Different mechanisms provide different forms of confidence and should be designed to complement, rather than substitute for, one another. The following recommendations favour the use and adaptation of existing or already proposed institutions, standards and professional capabilities. They are not intended to prescribe technical testing methodologies, provide legal interpretation or treat professional assurance as a substitute for technical validation, conformity assessment or regulatory supervision. COMMENT 1: DEFINE THE NATIONAL AI ASSURANCE ARCHITECTURE > ARTICLE AND SECTION Sections 2.3 and 2.4, particularly the first key idea in the Vision; Sections 3.3 and 3.3.2; Section 3.5; Section 4.3; Annex A; Annex C; Annex E. > COMMENT AND RECOMMENDATION Insert a new Section 3.3.3, ‘National AI Assurance Framework’, setting out a coherent framework for the different mechanisms through which confidence in AI systems, governance arrangements and reported claims may be obtained. The framework should distinguish clearly between: • management monitoring and operational control; • risk and compliance functions; • internal audit; • technical testing and model validation; • conformity assessment under the EU AI Act; • certification of management systems, products, processes or persons; • independent external assurance; • regulatory supervision and inspection. These activities are complementary but are not interchangeable. The framework should specify which mechanism is intended for which purpose and should prevent a certificate, technical assessment or compliance review from being represented as providing confidence over matters outside its defined scope. For each mechanism, as applicable, the framework should identify: • the subject matter being evaluated; • the applicable criteria and how those criteria are established; • the intended users; • the scope and reporting boundary; • the evidence and documentation requirements; • the nature of the resulting report, certificate, conclusion or regulatory decision; • the competence requirements for those performing the work; • the required degree of objectivity or independence; • how the provider is authorised, registered, licensed or accredited, as appropriate; • the arrangements for provider oversight, quality management, complaints, remediation and, where relevant, sanctions. For independent external assurance engagements, the framework should also identify whether reasonable or limited assurance is intended and the form of the resulting conclusion. These assurance levels should not be applied indiscriminately to certification, conformity assessment or technical testing, which operate through different frameworks. Recognised international standards and frameworks addressing assurance, ethics and quality management should be used where appropriate rather than recreated nationally. The development of the National AI Assurance Framework should involve relevant regulatory, professional, standardisation, accreditation, technical and public-interest bodies. Their respective roles should reflect their competence. Technical specialists should lead technical testing and validation; regulatory authorities should retain their statutory responsibilities; accreditation and standardisation bodies should address conformity-assessment infrastructure; and suitably qualified assurance practitioners should contribute expertise in criteria, evidence, independence, professional scepticism, documentation, quality management and reporting. Cyprus already possesses relevant professional capacity. Regulated audit and assurance firms, internal audit professionals, accountants, governance and risk professionals, lawyers and other regulated professions bring complementary experience in evidence, ethics, professional judgement, reporting, internal control and accountability. This capacity should be recognised as part of the horizontal infrastructure supporting the priority sectors, while acknowledging that AI-specific technical and legal competence will frequently require multidisciplinary teams. > JUSTIFICATION The Strategy makes trust a central part of the economic and institutional positioning of Cyprus. Section 2.3 refers to compliance, assurance and trusted deployment environments as a national advantage, while the Vision at Section 2.4 identifies ‘national AI assurance’ as one of the critical layers Cyprus should control. The Strategy also uses ‘assurance’, ‘audit’, ‘certification’ and related terms in materially different contexts. These include internal or external assurance under Section 3.3; assurance mechanisms supporting delivery under Section 3.5; ‘compliance auditing’ by the Government Innovation Hub; approved and certified delivery partners under Section 3.3.2; an annual audit under Section 3.9.6; and a funding programme ‘audited by’ a ministry under Section 5. Each activity has different purposes, competence requirements, independence implications and forms of reporting. Unless those distinctions are made explicit, organisations and users may attribute more confidence to a certificate, validation exercise or compliance review than its scope supports. A national assurance framework would make the Strategy’s trust proposition operational while avoiding unnecessary duplication. It would also create a common vocabulary through which technical, regulatory, professional and institutional actors could understand their respective responsibilities. COMMENT 2: CLARIFY THE ASSURANCE BODIES, ANNUAL-AUDIT PROPOSAL AND SEPARATION OF ROLES > ARTICLE AND SECTION Sections 3.3.1, 3.3.1.1 and 3.3.2; Section 3.9.6; Annex A; Annex B; Annex E. > COMMENT AND RECOMMENDATION Section 3.9.6 refers to documented conformity assessments ‘complemented by an annual audit by the Cyprus AI Security & Certification Authority’. This body does not appear within the governance structure at Section 3.3.1 and is not otherwise defined. The final Strategy should either: 1. define the Cyprus AI Security & Certification Authority within the governance architecture, including its legal basis, mandate, funding, competence, accountability and relationship with existing competent authorities, notifying and market-surveillance arrangements, notified bodies and sectoral regulators; or 2. remove the reference and rely on the conformity-assessment and regulatory framework established under the EU AI Act, supplemented where appropriate by voluntary accredited certification and appropriately defined external assurance. The wording in Section 3.9.6 concerning registration in the EU database should also be aligned precisely with the roles, system categories and registration obligations established by the EU AI Act. It should not imply an undifferentiated registration or audit requirement applying to every organisation irrespective of its role, AI use, risk profile or legal obligations. If any national audit mechanism is retained, the Strategy or subsequent implementation framework should define: • its legal basis; • the organisations, systems or claims within scope; • its subject matter and applicable criteria; • whether it is an entity-level, system-level or control-level examination; • who may perform it; • the required competence, objectivity and independence; • its frequency and the circumstances in which frequency may change; • materiality or risk thresholds; • reporting, remediation and appeal arrangements; • how duplication with EU AI Act conformity assessments, sectoral supervision and other existing reviews will be avoided; • how proportionality will be maintained for SMEs and lower-risk uses. The mechanism should be risk-based and proportionate. It should not automatically be annual, entity-wide or identical across all systems and organisations. The Strategy should also establish functional separation between enablement, preparation, approval and independent examination. Within the National AI Authority: • policy coordination, adoption support and delivery enablement should be functionally separated from control-gate approval and compliance oversight; • no individual or function should prepare the principal compliance evidence and then be solely responsible for approving the same evidence; • high-risk, citizen-facing or otherwise high-impact systems should be subject to an appropriately objective pre-deployment review by a suitably competent person or function not responsible for preparing or delivering the system; • reporting lines, decision rights and escalation routes should be documented. A maker-checker or independent pre-deployment review principle may be informed by established quality-review disciplines, but it should be adapted to the AI governance context rather than treated as a direct application of audit engagement quality review. Annex E should also clarify the statement that AI Officers act as ‘a point of coordination and assurance’. AI Officers are simultaneously described as implementation coordinators, change agents, capability builders and supporters of compliance documentation. If these responsibilities are retained, the role should be described as coordination, monitoring and challenge, rather than refer to assurance. An AI Officer should not provide assurance over an initiative that the same officer has promoted, designed, coordinated or documented. Independent assurance, where required, should be assigned to a separate person or function. > JUSTIFICATION A national authority with an audit or certification mandate requires a clear legal and institutional basis. An undefined authority attached to a potentially extensive and complex annual-audit requirement creates uncertainty over jurisdiction, cost, competence, accountability and the relationship with EU and sectoral regulatory structures. The Strategy’s wider governance model also gives the National AI Authority several roles. It establishes national frameworks, resources the Government AI Accelerator, coordinates AI Officers, supports delivery and acts as a governance and control gatekeeper. Annex E gives AI Officers responsibilities for use-case prioritisation, compliance documentation, risk oversight, capability-building and organisational change. These responsibilities are individually legitimate, but their combination creates a risk of self-review unless preparation, enablement, approval and independent examination are clearly separated. Functional separation does not necessarily require additional institutions. It can often be achieved through defined responsibilities, separate reporting lines, appropriately objective reviewers, documented escalation arrangements and diligent oversight. This would strengthen the credibility of the governance model while retaining the Strategy’s emphasis on efficient and coordinated delivery. COMMENT 3: ESTABLISH THE ACCREDITATION AND CROSS-BORDER-RECOGNITION PATHWAY > ARTICLE AND SECTION Section 4.3; Section 5, particularly the immediate steps concerning adoption, compliance and certification; Section 3.11.2; Annex A; Annex C, including the Legal Services pillar. > COMMENT AND RECOMMENDATION The Strategy repeatedly positions Cyprus as a location for AI testing, certification, pre-certification and regulatory readiness. It proposes a European AI Certification Lab, a national registry of AI systems certified under EU rules, the National AI Compliance Framework and the implementation of ISO/IEC 42001 and ISO/IEC 27001 across industry and the public sector. The ability to provide internationally recognised certification and related conformity-assessment services depends on a defined accreditation and recognition pathway. Article 7 of Regulation (EC) No 765/2008 permits cross-border accreditation in specified circumstances, including where the national accreditation body does not perform the requested accreditation activity or has not successfully undergone peer evaluation for it. The final Strategy should therefore establish a specific workstream, with an identified owner and timetable, to: 1. confirm with CYS-CYSAB and the European co-operation for Accreditation the current position and the accreditation services required for AI management-system certification, validation and verification and other anticipated AI conformity-assessment activities; 2. determine whether Cyprus intends to extend the scope and peer-evaluated capability of CYS-CYSAB, use permissible cross-border accreditation arrangements while domestic capability is developed, or adopt a combination of the two; 3. identify the competence, assessor and institutional-capability requirements associated with each intended accreditation scope; 4. clarify the relationship between pre-certification support, technical testing, voluntary certification, EU AI Act conformity assessment and regulatory supervision; 5. sequence the certification-hub ambition against the accreditation and recognition milestones on which it depends; 6. state how certification bodies, testing laboratories and other conformity-assessment providers will be approved, monitored and recognised within the national framework. The European AI Certification Lab should not be described or understood as providing final accredited certification unless its legal role, applicable certification scheme, accreditation basis and institutional independence support that function. Pre-certification, readiness assessment, testing and final accredited certification should be distinguished explicitly. > JUSTIFICATION Accreditation provides an authoritative assessment of the competence of conformity-assessment bodies and supports the recognition of accredited certificates and reports across borders. The current EA Multilateral Agreement scope of CYS-CYSAB does not cover all the activities implicated by the Strategy’s ambitions for AI management-system certification, validation and verification. This is a concrete implementation dependency that should be addressed in the Strategy’s sequencing and institutional-capability planning. It does not follow that Cyprus-based bodies are incapable of obtaining internationally recognised accreditation. The European framework provides defined circumstances for cross-border accreditation. The strategic question is therefore how Cyprus will secure the necessary capability and recognition, through domestic scope extension, permitted cross-border arrangements or both. Addressing this question now would protect the Strategy from conflating national testing or pre-certification capability with internationally recognised accredited certification. It would also identify an important area of sovereign institutional capability requiring planning, competent personnel, peer evaluation and sustained quality management. COMMENT 4: ESTABLISH EVIDENCE STANDARDS AND MEANINGFUL HUMAN OVERSIGHT AT THE CONTROL GATES > ARTICLE AND SECTION Section 3.3.2; Section 3.4.3; Sections 3.9.2 and 3.9.3; Annex B; Annex E. > COMMENT AND RECOMMENDATION Annex B should be supplemented with a proportionate minimum evidence specification for each control gate. For each gate, the specification should identify: • the decision to be made and the applicable approval criteria; • the minimum documentation required to support that decision; • the significant assumptions, uncertainties and judgements considered; • the evidence supporting the conclusion; • the identity and role of the preparer; • the identity, competence and role of the reviewer; • the person or body accountable for the final decision; • the dates of preparation, review and approval; • the version of the system and supporting documentation considered; • a defined, risk-appropriate period for completing the gate record; • the custodian, location, access arrangements and retention period for the evidence; • the process for logging subsequent amendments, additional evidence and changes in judgement; • the evidence required to demonstrate that remediation conditions have been completed. The documentation should be sufficient to enable a suitably competent reviewer with no previous involvement in the particular decision to understand: • what was decided; • why it was decided; • which evidence was considered; • which significant judgements were made; • which limitations or uncertainties remained; • who accepted the residual risk; • what subsequent monitoring or remediation was required. The control-gate framework should also define the minimum characteristics of meaningful human oversight. These should include: • clearly assigned responsibility and decision authority; • sufficient understanding of the use case, its limitations and its operating context; • access to relevant and traceable evidence; • authority to challenge, pause, override or escalate; • ability to identify uncertainty, bias, inappropriate reliance and circumstances outside the system’s intended use; • documentation of significant judgements and the rationale for the final decision; • adequate time, resources and organisational support; • safeguards against human oversight becoming a routine, procedural or ‘rubber-stamp’ approval. Human oversight should therefore be assessed not only by whether a person is present, but by whether that person is competent, authorised and practically able to exercise informed challenge and judgement. Evidence requirements should be proportionate to risk, impact and complexity. They should also be designed so that the same properly governed evidence can support, where relevant, internal governance, subsequent conformity assessment, sectoral supervision, incident investigation and independent assurance, rather than requiring organisations to recreate similar records repeatedly. > JUSTIFICATION Annex B establishes a valuable lifecycle and control-gate structure and provides for documentation at different stages. It does not, however, establish a common minimum evidence specification for each gate or define the characteristics of an adequate gate record. An approval is not the same as defensible evidence supporting the approval. Without consistent documentation, it becomes difficult to determine whether the relevant criteria were applied, whether significant risks and uncertainties were considered, whether the reviewer exercised informed challenge or whether the gate operated only as a procedural step. A credible Operational Assurance Review at Control Gate 4 requires a sufficiently complete and traceable record against which continuing performance and compliance can be evaluated. The Strategy correctly states that AI should support rather than replace human judgement. The presence of a named human reviewer is nevertheless insufficient if that person lacks the competence, authority, information, time or organisational support required to challenge the system or its proponents. A disciplined evidence framework would help translate the Strategy’s principles of auditability, traceability, accountability and human oversight into operating requirements. It would also help distinguish substantive implementation from activity that cannot demonstrate its decisions or outcomes. COMMENT 5: CLARIFY GOVERNING-BODY AND SENIOR-MANAGEMENT ACCOUNTABILITY > ARTICLE AND SECTION Sections 3.3 and 3.5; Section 3.9.6; Annex C, particularly the provisions concerning the public sector, regulated private sector and private companies and organisations; Annex E. > COMMENT AND RECOMMENDATION The Strategy or subsequent implementation guidance should specify who holds organisational accountability for approving and overseeing Institutional or Applied AI Strategies. The arrangements should recognise differences between ministries, public bodies, regulated entities, companies and other organisations. They should nevertheless establish the common principle that responsibility remains with the organisation’s existing governing or accountable authority and is not transferred to an AI Officer, technology function, vendor or external adviser. For ministries and public bodies, the relevant Applied AI Strategy should be approved by the minister, governing board, accounting officer, chief executive or other legally accountable authority appropriate to the institution. For companies and regulated entities, the board of directors or equivalent governing body should approve the Institutional AI Strategy where AI use is material, high-risk, critical to the business model or capable of significantly affecting customers, employees, investors, citizens or regulatory obligations. The governing or accountable authority should: • approve the organisation’s overall AI direction and risk appetite; • confirm the allocation of responsibilities and decision rights; • oversee the integration of AI governance with corporate or institutional strategy; • receive appropriate information on material use cases, incidents, control failures, remediation, performance and emerging risks; • review the strategy at a frequency proportionate to the organisation’s AI use, risk exposure and regulatory environment; • retain responsibility for significant judgements and accepted residual risks. Where audit committees, risk committees, internal audit, risk-management or compliance functions exist, their AI-related responsibilities should be mapped onto their existing mandates and applicable legal or regulatory responsibilities. The Strategy should not assume that every organisation has identical governance structures. Institutional AI Strategies should be integrated, as relevant, with: • corporate or institutional strategy; • risk appetite and risk-management frameworks; • internal-control arrangements; • data governance and protection; • cybersecurity; • third-party, procurement and outsourcing governance; • quality management; • corporate and regulatory reporting; • business continuity and operational resilience; • workforce and organisational-change arrangements. AI acceptable-use policies should be approved at an appropriately senior level. Governing-body approval may be appropriate where the policy addresses material, high-risk or organisation-wide use. Operational policies may be approved by management within authority delegated by the governing body. Existing governance structures should be used and adapted before new organisational committees are created. New committees should be established only where a defined responsibility or competence gap cannot be addressed effectively through existing arrangements. > JUSTIFICATION Annex C provides that Institutional AI Strategies for regulated private-sector entities will form part of supervisory reporting ‘with the same legal weight as risk-management frameworks’. The Strategy does not specify which body within the regulated entity approves the Institutional AI Strategy or exercises continuing oversight over it. Risk-management frameworks in regulated sectors are ordinarily subject to governing-body and senior-management responsibilities established through the applicable sectoral regime. Giving an AI strategy comparable significance while leaving its approval and oversight arrangements undefined creates a governance gap. Governance structures differ across companies, public bodies and regulated sectors. The appropriate response is therefore not a universal requirement for a particular committee, but a clear accountability principle combined with proportionate application. AI should not become a separate technology workstream operating outside established governance, reporting and control arrangements. Embedding it within existing structures would strengthen accountability, reduce duplication and help avoid the institutional complexity that could arise from creating new AI-specific bodies at every level. COMMENT 6: ESTABLISH A CONTROLLED BASIS OF PREPARATION FOR NATIONAL AI INDICATORS > ARTICLE AND SECTION Section 1.5; Section 2.5.2; Sections 3.5 and 3.11; Annex C; Annex F; Section 5. > COMMENT AND RECOMMENDATION The Strategy’s national targets and indicators should be reconciled and supported by a published basis of preparation. First, the final Strategy should reconcile the different adoption targets currently stated in the draft: • Section 3.5 refers to increasing AI adoption to 50% across government and priority sectors by 2032; • Annex C refers to 75% AI adoption by 2032, aligned with the Digital Decade target; • Section 5 refers to 75% industry adoption of AI technologies by 2030; • the stated baseline for enterprise adoption is approximately 9.3%. The 15% productivity improvement and 12% GDP expansion presented as expected outcomes should also be accompanied by their source, model, assumptions, baseline trajectory, measurement period and principal limitations. The distinction between an aspirational target, an upper-bound scenario and an outcome against which delivery will be assessed should be clear. Second, the Strategy should require a basis of preparation for every principal national indicator. This should identify: • the precise definition of the indicator; • the unit of measurement; • what constitutes ‘AI adoption’, including whether it is measured at entity, use-case, employee, user or system level; • the reporting population and boundary; • the baseline year and baseline value; • the target year and target value; • the data source and data owner; • the calculation methodology; • the responsible organisation; • the reporting frequency; • relevant assumptions, estimates and limitations; • controls over data collection, consolidation and reporting; • arrangements for internal review, validation or external examination; • the treatment of errors, methodology changes and restatements; • how performance will be compared consistently over time. Third, the adaptive character of Annex F should be supported by formal change control. Indicators may need to evolve as technology, regulation and national priorities change, but any material amendment should be: • approved by an identified authority; • dated and documented; • accompanied by a clear explanation; • assessed for its effect on previously reported performance; • reflected through restatement or appropriate comparative information where practicable; • disclosed in the relevant public report. The ability to update indicators without revising the core Strategy should support learning and relevance, but should not permit targets or measurement methods to change without transparent governance. Fourth, progress should be reported publicly through an annual ‘State of National AI’ report or equivalent mechanism. The report should present: • performance against principal targets; • the relevant basis of preparation; • significant changes in indicators or methodology; • limitations and data-quality matters; • explanations of material variances; • remediation or reprioritisation decisions; • the relationship between expenditure, activity, outputs and outcomes. A defined subset of indicators linked to significant public expenditure, national productivity claims and the ‘trusted jurisdiction’ proposition should be considered for independent external assurance or another appropriate form of external verification once sufficiently suitable and stable criteria have been established. The scope, criteria, provider, nature and level of any assurance should be stated clearly. Independent assurance should not be imposed automatically on every indicator. It should be targeted according to materiality, public interest, risk, maturity of the measurement system and the value that external examination would provide. > JUSTIFICATION Reporting is not merely an output. It is a governance mechanism through which responsibilities are made visible, progress is evaluated, resources are redirected and public claims can be challenged. An indicator without a defined boundary, methodology, data owner and baseline cannot support reliable comparison or accountability. Similarly, an adoption rate can convey materially different information depending on whether it measures organisations using at least one AI tool, production use cases, employee usage or the proportion of processes supported by AI. The current differences between the stated adoption targets make it difficult to identify the principal national target and the population to which it applies. The productivity and GDP figures also require a transparent analytical basis if they are to function as performance measures rather than illustrative scenarios. Annex F correctly recognises that measurement must evolve. Adaptability and accountability can coexist if changes are governed, documented and disclosed while comparative information is preserved as far as practicable. A controlled basis of preparation, transparent public reporting and targeted external examination would strengthen the Strategy’s response to the risk of ‘AI theatre’. They would enable Cyprus to demonstrate not only that activity occurred, but that claimed outcomes were defined in advance, measured consistently and subjected to appropriate challenge and oversight. CONCLUSION The Strategy is right to place trust at the centre of Cyprus’s positioning and to recognise that trust must be built through governance, accountability, human oversight, organisational capability and evidence. The next step is to translate those principles into a coherent set of assurance roles, criteria, evidence requirements, competence requirements and oversight arrangements. The recommendations above draw principally on institutions, standards and professional capabilities that Cyprus already possesses or proposes to develop. They would: • distinguish professional assurance from certification, conformity assessment, technical validation and regulatory supervision; • clarify the responsibilities and independence or objectivity of the bodies involved; • establish the accreditation pathway supporting the certification-hub ambition; • create a traceable evidence base for lifecycle decisions; • make human oversight substantive rather than procedural; • embed accountability within existing governing structures; • make national targets and reported progress more credible and capable of appropriate examination. Adopting these recommendations would make the national trust proposition more operational, proportionate and internationally intelligible, without implying that every AI system or organisation requires the same form or level of assurance." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",DS,"1. Defining a clear role for public universities while respecting institutional and academic autonomy Reference: Annex C – Priority Sectors for Leadership, Section – Education and Human Capital Development, pages 77–81. The National Strategy appropriately recognises that lifelong AI learning extends to higher education and that academia should contribute to the national talent pipeline. However, the specific role of public universities in the implementation of the education pillar is not clearly defined. Public universities should be explicitly recognised as key partners in advanced AI education, skills development, research and knowledge transfer. They should also be actively involved in the design and implementation of national measures affecting higher education, so that these measures benefit from academic expertise, established institutional responsibilities and existing quality-assurance processes. The Strategy should clarify the mechanisms through which public universities will participate in implementation, including consultation, appropriate representation in relevant governance structures, and access to the funding, data and national AI infrastructure required to support education, research and innovation. 2. Defining education-specific measures of successful AI adoption Reference: Annex C – Priority Sectors for Leadership, Section – Education and Human Capital Development, pages 77–81. The Strategy sets a national target for increasing AI adoption across education and labour. However, increased use of AI tools should not, by itself, be treated as evidence of successful educational adoption. Progress should be assessed through clearly defined education-specific outcomes, including improvements in AI literacy and learning, the ability of learners and educators to use AI critically and responsibly, accessibility and inclusion, and evidence of meaningful educational benefit. Major national initiatives should be evaluated against these outcomes before wider implementation, so that their effectiveness can be demonstrated and any necessary adjustments can be made. 3. Distinguishing the implementation approach for higher education Reference: Annex C – Priority Sectors for Leadership, Section – Education and Human Capital Development, pages 77–81. The Strategy brings together school education, higher education, lifelong learning and workforce development under the education and human-capital pillar. However, its principal measures focus on learners aged 6–18 and on the upskilling of the existing workforce, while the role of higher education in preparing future graduates for an AI-enabled economy is less clearly developed. The Strategy should explicitly recognise the role of higher education in ensuring that graduates enter the workforce with appropriate AI knowledge and skills. Depending on their field of study, graduates should be equipped with relevant AI literacy, critical judgement, ethical awareness and the ability to use AI responsibly and effectively in professional contexts. National initiatives should support universities in developing these capabilities through their established academic and quality-assurance processes. Continuing workforce upskilling should complement, rather than substitute for, the preparation provided through undergraduate and postgraduate education. 4. Ensuring equitable access to suitable generative AI tools in public universities Reference: Annex C – Priority Sectors for Leadership, Section – Education and Human Capital Development, pages 77–81; Section 3.7 – Infrastructure, Compute and Digital Sovereignty, pages 38–40. The National Strategy promotes AI literacy, advanced skills development and the responsible adoption of AI across higher education and professional life. Achieving these objectives requires students, academic staff and researchers to have appropriate opportunities to gain practical experience with relevant AI tools, including generative AI and large language models where appropriate. The cost of institution-wide commercial licences may limit access and result in unequal provision between institutions and departments, as well as unequal access among individual users, particularly students. A coordinated national approach should therefore be considered through which public universities could obtain licensed access to suitable generative AI tools under collectively negotiated terms. Such an approach could reduce costs through economies of scale, avoid fragmented procurement and provide more consistent contractual safeguards concerning data protection, security, confidentiality and the use of institutional information. It should remain technology-neutral, allow access to more than one appropriate tool where necessary, and enable each university to determine how licensed services are used within its teaching, research and administrative activities. This would help ensure that access to advanced AI capabilities does not depend on the personal financial means of individual students or staff and would support the development of practical AI skills across the public higher-education system. 5. Using AI to strengthen personalised support for students with disabilities and specific learning difficulties Reference: Annex C – Priority Sectors for Leadership, Section – Education and Human Capital Development, pages 77–81. The National Strategy identifies personalised learning, accessibility and inclusion as important elements of AI adoption in education. It should also explicitly recognise the potential of AI to provide specialised and personalised support for students with disabilities and specific learning difficulties across primary, secondary and higher education. Appropriate AI-enabled tools could support the adaptation of learning materials, accessible formats, assistive communication, personalised feedback and learning support tailored to individual needs. These tools should complement, rather than replace, educators, specialists and existing student-support services, which, due to resource constraints, may rely primarily on group-based provision or may only be able to address basic learning needs. Used appropriately, AI-enabled tools could extend the reach and responsiveness of existing provision by offering additional, more individualised assistance tailored to each student’s needs. Appropriate safeguards should also be in place concerning accessibility, data protection, privacy, reliability and professional oversight, particularly where such technologies are used by children or other vulnerable learners. 6. Ensuring the infrastructure and support required for effective AI education in schools Reference: Annex C – Priority Sectors for Leadership, Section – Education and Human Capital Development, pages 77–81. The National Strategy proposes the introduction of AI literacy across primary and secondary education through national frameworks and AI-enabled learning tools. However, it does not set out how schools, educators and pupils will obtain the hardware, software and technical support required for effective and equitable implementation. Given that the Strategy’s principal school-level measures focus on learners aged 6–18, effective implementation will require pupils to have regular access to modern computing equipment within the public-school environment. The Strategy should recognise this as an important enabling condition, and implementation should include a coordinated plan to strengthen access to suitable devices, licensed software, secure AI tools, digital resources, reliable connectivity and ongoing technical support. Such provision would enable AI literacy to be developed through practical engagement with AI concepts and, where age-appropriate, with suitable AI tools under educator supervision, alongside theoretical learning. Without such provision, access to AI-enabled education may vary between schools and may depend on the resources available to individual families, creating unequal opportunities for pupils. Particular attention should therefore be given to schools and communities with limited resources, so that the implementation of national AI education initiatives does not widen existing inequalities. Infrastructure provision should also be accompanied by appropriate support and training for educators, enabling available technologies to be used effectively, safely and consistently in teaching and learning." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",techisland,"TechIsland Feedback on the Cyprus National AI Strategy TechIsland welcomes the development of the Cyprus National AI Strategy and the opportunity to contribute to the public consultation process. The Strategy provides a strong and necessary framework for Cyprus, particularly through its focus on value-driven use cases, measurable outcomes, organisational readiness, common infrastructure, trusted and EU-aligned AI, and the intention to avoid fragmented pilots and “AI theatre”. The following comments and recommendations reflect feedback gathered from contributors across companies and institutions spanning AI and software, IT services, digital health and diagnostics, enterprise communications, higher education, technology and transformation consulting, AI-enabled recruitment, and diversified sectors including property, hospitality, healthcare and education. The respondent group hold senior roles, including executive or C-suite roles, senior AI and technology leadership roles. Executive Summary TechIsland’s feedback is centred on three priorities that can strengthen the Strategy’s ability to translate ambition into measurable impact: Make transformation ownership explicit by assigning clear authority to change processes, KPIs, responsibilities and organisational structures, and to stop or scale initiatives based on actual value and adoption. Build a Cyprus AI industry by recognising, supporting and deploying solutions already being developed by Cyprus-based technology companies, AI providers, start-ups, entrepreneurs and research centres. Compete on trust, compliance and speed by strengthening Cyprus’ position as a trusted, EU-aligned jurisdiction and exploring an EU AI Act sandbox that can provide a fast and safe pathway from product testing to certification. 1. Transformation Ownership and Decision-Making Authority There is insufficient clarity on who has responsibility and authority when AI-enabled transformation creates conflicts between organisational interests, responsibilities and KPIs. For example, AI and process redesign may improve the overall performance of a public service while reducing the workload, budget, influence or responsibility of a particular department. A local organisational KPI may therefore conflict with the overall outcome the state is trying to achieve. The Strategy should make transformation ownership explicit. It should clarify: which KPI takes priority when system-level and local KPIs conflict; who has the authority to change a local KPI when it incentivises preservation of an inefficient process; who has the authority to redesign or remove an existing process step; who can redistribute responsibilities between organisations; escalation and final decision rights where organisations disagree; who can stop technically successful projects that fail to generate adoption or real value; who can scale successful solutions even when they negatively affect an existing local KPI or organisational interest. The issue is therefore not only who owns an AI system, but who owns the transformation and has the authority to change processes, responsibilities, KPIs and organisational structures when required. 2. Cyprus as an AI Technology and Innovation Hub The Strategy currently places stronger emphasis on Cyprus as an adopter, catalyst or user of AI across citizens, businesses and the public sector than as an AI technology innovator and industry hub. Greater emphasis should be placed on developing and supporting a Cyprus AI industry. The Strategy should capitalise on existing: Cyprus-based technology companies; AI solution providers; digital industry leaders; start-ups; entrepreneurs; research centres. Cyprus does not need to build its AI ecosystem entirely from the beginning. A number of companies and organisations are already developing AI technologies and solutions, including solutions that are successfully used internationally. It is recommended that Government identifies and becomes more aware of Cyprus-developed AI solutions, explores opportunities to use them within ministries and public services, and supports their promotion locally and internationally. TechIsland can support this effort by helping to map Cyprus-based companies and organisations already developing AI technologies and solutions, and by facilitating engagement between Government and relevant industry providers. The objective should be to foster a Cyprus AI industry rather than primarily act as a catalyst for international AI leaders. 3. Cyprus’ Strategic Positioning: Trust, Regulation and Compliance The Strategy’s positioning of Cyprus as a trusted, EU-aligned jurisdiction is a strong direction. There is an opportunity to go further by making regulatory agility a core element of Cyprus’ competitive positioning. Cyprus does not have the scale to compete globally on GPU or computing capacity. It is therefore recommended that Cyprus explores positioning itself as an EU AI Act sandbox, offering international companies a fast and safe pathway from product testing to certification. Under this approach, Cyprus’ competitive advantage would be compliance, trust and speed rather than hardware scale. 4. Prioritisation and Scope The Strategy is highly ambitious in terms of the number of sectors, priorities, programmes and structures it attempts to address simultaneously. There is a risk that the breadth of the roadmap may make successful implementation difficult, particularly given the pace at which AI is developing. It is recommended that: priorities are reduced and focused on a smaller number of areas, potentially four or five; implementation proceeds in clear phases, with a distinction between immediate priorities and initiatives that should follow later; at least one flagship, citizen-facing or compliance-facing AI system is selected, fully resourced and brought into live production within twelve months in order to demonstrate visible and measurable value in practice. 5. Delivery and Implementation The Strategy is currently a high-level, non-binding framework. A clearer delivery mechanism is therefore needed to translate its ambition into practical implementation. It is recommended that the Strategy is complemented by a binding Delivery and Investment Plan, updated annually. This plan should specify: what will be implemented first and what will follow in later phases; the expected cost of each major initiative; the sources of funding; responsibility and accountability for delivery; key milestones; workforce impacts; measurable outcomes; arrangements for independent evaluation. The proposed actions should also be more specific, practical and accompanied by clear budgets. 6. Financing and Funding There is an absence of a clearly defined financing envelope. The Strategy sets out ambition, governance structures and KPIs, but does not provide a costed capital plan, named funding sources or clear phasing of expenditure. It is recommended that a multi-year, phased financing envelope is published alongside the Strategy, identifying national funding and relevant EU co-financing sources, including Digital Europe, Horizon Europe and EuroHPC. Funding should also be directed towards existing Cyprus-based AI companies, entrepreneurs, start-ups and technology organisations already developing and deploying AI solutions. This would help retain capability in Cyprus, keep more data and technical know-how within the jurisdiction, enable shorter iteration cycles with local providers, and recirculate a greater share of AI-related investment within the domestic economy. National AI funding, compute infrastructure, data facilities, sandboxes, skills programmes and commercialisation support should be accessible to all accredited Cyprus higher education and research institutions on transparent, competitive and outcome-based terms, irrespective of whether they are public or private. Access to national AI capabilities should be based on quality, relevance and expected impact rather than institutional status. 7. Research and Industry The Strategy places significant emphasis on universities, research centres and the development of Centres of Excellence. This is important, but the framework should more explicitly connect research capability with commercial, operational and public-sector deployment. The objective should be to create stronger pathways through which research, talent, infrastructure and industry capability translate into tested, scalable solutions and measurable outcomes. Universities, research centres and industry bring complementary capabilities. Universities contribute research, talent development, specialised infrastructure, validation environments and knowledge creation, while industry contributes productisation, integration, operational deployment and scaling. The Strategy should strengthen mechanisms that bring these capabilities together around real-world deployment and measurable outcomes. Universities should also be recognised as important real-world deployment and validation environments for AI, including in education, healthcare, administration and professional services. This would allow solutions to be tested with real users and operational processes before wider deployment, while generating evidence on adoption, effectiveness and scalability. 8. Public-Private Partnerships and Procurement There is insufficient emphasis on Public-Private Partnerships. Implementation of the Strategy cannot rely on the government alone. Public-Private Partnerships should be explicitly incorporated into the implementation model, particularly in areas where industry expertise, market agility and operational experience are required. Furthermore, Public-Private Partnerships should not be limited to consultation or advisory input. They should be designed as practical delivery mechanisms through which government can work with technology companies, AI providers, start-ups, integrators and established enterprises to identify existing solutions, adapt them for public-sector needs, and deploy them at speed. This is particularly important because many of the AI capabilities that can improve public services are already being developed and tested in industry rather than in purely academic settings. For this delivery model to work in practice, public procurement rules and tender design should also enable qualified local and emerging providers to compete on fair terms. Tender thresholds, framework agreements, reference-customer requirements, liability terms and payment schedules should be reviewed so that they do not unintentionally favour only large incumbent integrators or create excessive vendor dependence. Procurement should support competition, interoperability and the ability to pilot and scale solutions from a wider pool of providers. 9. Governance Structure The proposed governance structure appears overly complex. The Strategy includes the National AI Authority, the Interministerial AI Council, specialised or oversight committees, Centres of Excellence, as well as AI Officers and AI Champions within ministries. For a country of Cyprus’ scale and with an already limited AI talent pool, there is a risk that the governance structure itself will consume scarce resources needed for implementation. The governance structure should include a clearer and stronger industry-facing component. While the proposed model includes several public-sector, academic and coordination bodies, it is not sufficiently clear who is responsible for representing the needs of industry or ensuring that implementation decisions reflect real-world adoption challenges. The AI Task Force and related steering structures should therefore include stronger representation from technology companies, AI providers, start-ups, SMEs and large enterprises, so that national priorities are informed by both research expertise and practical deployment experience. In summary, it is recommended that: the governance structure is simplified and consolidated; the AI steering structure is small and composed primarily of experts and stakeholders directly involved in AI; consideration is given to a single empowered delivery unit with its own budget and clear accountability; the distinction and responsibilities between roles such as AI Officer, AI Champion and/or AI Ambassador are clearly defined. 10. Measuring Actual Transformation and Value The success of AI projects should not be measured solely by whether a system, portal or pilot has been successfully launched. A technically successful implementation may still create little value if citizens continue using existing channels and employees continue relying on old systems, spreadsheets and manual processes. Measures of success should therefore include: whether users moved from old channels to new ones; whether the service became faster; whether manual work decreased; whether unnecessary process steps decreased; whether the cost of delivering the service decreased; whether the end-user experience improved. The success of the National AI Strategy should therefore be measured by whether AI changes underlying processes and improves system-level outcomes. 11. Organisational Change and AI Adoption Across the Economy The Strategy discusses workforce augmentation, agentic AI and AI Officers, but provides limited detail on how organisations should redesign workflows, team structures and decision-making processes around AI agents. The role envisaged for AI Officers in government, bridging existing business needs and new technology, is also relevant to the wider economy. The Industrial Centre of Excellence and Change Management components should therefore have a more central role in a national strategy intended to cover the whole economy. Cyprus’ economy relies heavily on SMEs. Reskilling and empowering professionals already working within existing businesses to embrace innovation and develop value-oriented AI use cases from within their organisations should be treated as a high priority. Adding new AI talent is not sufficient unless the transition between new AI capabilities and existing people, processes and technical infrastructure is also addressed. This requires sustainable transformational change management. 12. SME Access to AI Support The Strategy sets out support mechanisms for SMEs, including the AI Sovereign Investment Matching Fund and the AdoptNAICF programme. There is insufficient clarity on how companies will practically access these mechanisms. It is recommended that a “single digital front door” is established, with clear service-level commitments for decision-making. The process for accessing support should be simple and frictionless, particularly where AI adoption can demonstrably improve productivity or reduce costs. 13. Practical Upskilling and AI Literacy The FutureAI CY programme and its proposed stackable micro-credentials are important for long-term education and skills development. However, there is also a need for practical and immediately applicable AI skills. It is recommended that the programme is supplemented by short, practical bootcamps focused on how existing employees can use currently available AI tools in their daily work to reduce costs and accelerate processes. 14. AI Access for Students and Citizens There is a need to create more opportunities for students and citizens to use AI directly. Practical access can help improve adoption, understanding and familiarity with AI. Examples from Malta and the UAE demonstrate approaches that could be considered. It is recommended that Cyprus considers: providing students with access to AI tools; considering free access to AI tools for students and potentially the wider public; organising hackathons, awareness activities and practical programmes covering areas such as AI for cybersecurity, design and advertising; creating programmes and events aimed separately at students and employees. Public discussion around AI is often dominated by concerns that it is a bubble, a scam, will take jobs or replace humans. Giving people practical opportunities to use AI can help them understand how it can be useful in everyday life and reduce the perception that the technology is inaccessible or overwhelming. 15. Talent and International Partnerships In addition to developing the domestic AI talent pool, Cyprus should continue to attract experienced international AI professionals and specialised teams. Cyprus universities should also be used as a pathway for attracting and retaining international AI talent, including through streamlined arrangements for specialist researchers and clear post-study pathways for graduates in high-demand AI and technology fields. The possibility of establishing government-backed Global Capability Centres (GCCs) should also be explored as a mechanism for bringing high-value AI expertise and capabilities to Cyprus. 16. Sovereign AI, Compute, and Data The principle of ""partner for scale, sovereign where it counts"" is appropriate, but the Strategy would benefit from stating explicitly where each half of that principle applies. It is recommended that the distinction is drawn by technology layer. Cyprus should buy at the infrastructure layer, where compute, foundation models and silicon are already commoditised and where national investment competes against capital Cyprus does not have, and build at the application, assurance and data layers, where domestic capability is achievable and where the Cyprus AI industry described in Section 2 already operates. Ambitions around sovereign models, sovereign compute and RISC-V risk spreading limited capital and talent across layers where the return does not justify the expenditure. Computing capacity should instead be accessed through EuroHPC and hyperscaler partnerships, with sovereign investment concentrated on assurance, deployment and trust. Data is the layer where sovereignty genuinely applies, and it receives insufficient attention in the Strategy relative to compute and infrastructure. Secure and interoperable data is named as a national objective, but is treated largely as infrastructure to be built rather than as the precondition on which every proposed use case depends. Public sector data in Cyprus is distributed across ministries in systems that were not designed to interoperate, with uneven quality, incomplete documentation and no consistent access regime. Every flagship initiative contemplated in Section 4 depends on that data being available and usable. National AI programmes fail more often on data availability and quality than on model access, computing capacity or governance design. It is recommended that: a public sector data inventory is compiled, identifying which datasets exist, who owns them, their quality and their current accessibility; interoperability requirements apply by default to new public sector systems; a defined access regime is established for accredited public and private users, with published timelines for access decisions; named accountability is assigned for the quality and maintenance of each significant dataset; data readiness is treated as a selection criterion for the twelve-month flagship proposed in Section 4, so that the initiative chosen is one where the underlying data already exists. accredited universities and research institutions have clear, governed and timely pathways to access appropriate national datasets for legitimate research, validation and innovation purposes; Sovereignty over data, and the capability to use it, will matter more to Cyprus over the period to 2032 than sovereignty over silicon. 17. Energy Consumption Energy consumption represents a major issue and opportunity that is not sufficiently addressed in the Strategy. Greater attention should be given to the relationship between AI adoption, computing infrastructure and energy consumption. 18. Stakeholder-specific Implementation The Strategy would benefit from a clearer segmentation of its proposed actions by stakeholder group. At present, several measures appear to apply across the economy, but it is not always clear which initiatives are intended primarily for start-ups, scale-ups, established technology companies, large enterprises, SMEs, the public sector, research institutions, students or citizens. A practical implementation matrix should be added, showing for each stakeholder group what support, obligations, funding routes, infrastructure access, skills programmes and regulatory measures are relevant to them. This would make the Strategy easier to implement, easier to communicate, and easier for each group to understand how it can participate. Conclusion The Cyprus National AI Strategy 2032 provides an important and necessary foundation for the country. Its success will depend primarily on execution: maintaining focus, translating the Strategy into concrete actions, ensuring sufficient funding, involving existing industry capabilities, establishing clear accountability, and demonstrating practical and measurable results throughout the implementation period." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",GK,"ΔΗΜΟΣΙΑ ΔΙΑΒΟΥΛΕΥΣΗ — ΕΘΝΙΚΗ ΣΤΡΑΤΗΓΙΚΗ ΓΙΑ ΤΗΝ ΤΕΧΝΗΤΗ ΝΟΗΜΟΣΥΝΗ (ΤΝ) 2032 Public Consultation Submission — Republic of Cyprus National AI Strategy 2032 To: Υφυπουργείο Έρευνας, Καινοτομίας και Ψηφιακής Πολιτικής, μέσω της πλατφόρμας «η-Διαβούλευση» Subject: Σχόλια επί του προσχεδίου της Εθνικής Στρατηγικής για την ΤΝ — Πρόταση ενίσχυσης της θεσμικής αρχιτεκτονικής υλοποίησης (National AI Authority) Date: 31 Αυγούστου 2026 1. Executive Position We welcome the draft National AI Strategy 2032 and, in particular, its recognition in Section 3.3 that a National AI Authority, an Interministerial AI Council and a supporting network of specialised committees are required to coordinate AI governance and adoption across the Republic. This submission does not propose an alternative institutional model. It proposes that the Strategy's existing National AI Authority concept be strengthened, before final adoption, along the lines set out below, so that the Authority is unambiguously independent, cross-sectoral in mandate, and equipped with genuine implementation powers granted by the Council of Ministers — rather than a purely advisory or coordinating unit. The central argument is straightforward: artificial intelligence is not a conventional single-sector policy domain. It is a general-purpose, cross-cutting capability that simultaneously reshapes public administration, financial services, healthcare, justice, education, tourism, shipping, and the wider investment and business environment — precisely the eight Priority Sectors the Strategy itself identifies (Section 3.5). A policy area with this horizontal reach across government layers and the economy cannot be implemented effectively through the ordinary machinery of a single ministry acting alone. It requires a dedicated, independent institution with a whole-of-government and whole-of-economy mandate, operating in close coordination with the Deputy Ministry of Research, Innovation and Digital Policy, the Commissioner of Electronic Communications, the Commissioner for Personal Data Protection, sector regulators, the European Artificial Intelligence Board, and other EU and international bodies active in this field. 2. Comments by Section Article / Section No. Comment / Suggestion Rationale Section3.3.1.1 (“National AI Authority”) See 2.5.7 (Target 7) The Strategy correctly proposes designating a National AI Authority “with a clear political mandate”, appointed by the President and ratified by the Council of Ministers. We recommend the final text state explicitly that the Authority be established as an independent legal entity with defined operational and budgetary autonomy — not merely a coordination function nested inside an existing ministry. The founding instrument should specify: (a) legal personality; (b) an explicit Council of Ministers implementation mandate covering AI adoption and governance across both the public sector and the private sector; (c) multi-annual budget and staffing guarantees; and (d) a transparent, merit-based appointment process for its Chief Executive/Commissioner. AI is not a single-sector policy area; it is a horizontal capability cutting across public administration, financial services, healthcare, education, justice, tourism and shipping, as the Strategy's own eight Priority Sectors (Section 3.5) demonstrate. A body without legal personality and secured funding risks becoming, in practice, a subordinate coordination unit unable to give binding direction to sector regulators or to attract technical staff at competitive terms. Comparative practice — Spain's AESIA, Malta's MDIA, and Ireland's planned AI Office of Ireland — shows that credible national AI institutions combine legal independence with a dual mandate spanning trust/compliance and adoption/innovation. Anchoring this in the Strategy itself, rather than leaving it to secondary legislation, reduces the risk that implementation stalls at the design stage and signals credibility to ministries, businesses and investors alike. Section3.3.1.1, part “The Authority does not assume operational control … nor does it replace ministerial authority” We recommend sharpening this language so the Authority's role is not read as purely advisory. Ministries should retain day-to-day accountability for their own AI deployments (consistent with Section 3.4.3), but the Authority should hold an explicit Council of Ministers implementation mandate to: (i) issue binding minimum standards for high-risk public-sector AI systems; (ii) require ministries to align their Applied AI Strategies (Section 3.4) with common national templates within a defined timeframe; and (iii) escalate sustained non-compliance to the Interministerial AI Council and, where unresolved, directly to the Council of Ministers. A body limited to “guidance” and “coordination” without any escalation path risks exactly the “AI theatre” the Strategy itself warns against in Section 1.4 — many pilots, little systemic impact. Because AI adoption touches multiple layers of governance at once (data policy, procurement, cybersecurity, sector regulation), an authority with only soft-coordination powers will struggle to align ministries operating on different timelines and risk appetites. A defined, Council-of-Ministers-backed implementation mandate — while preserving ministerial operational accountability — gives the Authority the institutional weight needed to drive genuinely national, rather than fragmented, adoption. Section3.3.1.1 σε συνδυασμό με Appendix Α (EU AI Act designations) We recommend an explicit clause clarifying the division of labour between the new National AI Authority and the bodies already designated under the EU AI Act — the Deputy Ministry of Research, Innovation and Digital Policy (overall AI Act coordination and Cyprus's seat on the European AI Board) and the Commissioner of Electronic Communications (Notifying Authority, Market Surveillance Authority, Single Point of Contact). A formal cooperation protocol should be published alongside the Authority's founding legal instrument, confirming that the Authority provides technical capacity, Article 57 regulatory-sandbox coordination, and cross-sector adoption support, while statutory AI Act enforcement powers remain with the already-designated competent authorities. Without a clear non-duplication clause, Cyprus risks creating two centres of gravity for AI policy — the Authority and the AI Act competent authorities — recreating the very fragmentation risk the Strategy's governance chapter (Section 3.3) is designed to solve. Ireland's planned AI Office and Malta's MDIA both show that a single national implementation body can coordinate distributed statutory functions without duplicating them, provided the legal instrument defines this relationship explicitly rather than leaving it to informal practice that may not survive changes in political leadership. Section3.3.1.1 (institutional independence) & 3.4.3 (Human Oversight and Accountability) We recommend an explicit conflict-of-interest safeguard: because the state will simultaneously be a major deployer of AI (through the “Government and Public Sector” priority use cases in Section 3.5) and, through the Authority, the source of guidance and standards for that same deployment, the Authority's assurance and testing functions should be organisationally separated internally from its adoption-acceleration functions, with published conflict-of-interest rules for board members and senior staff. Institutional neutrality is essential for public trust, particularly for AI used in sensitive domains such as health, justice, welfare and policing, which the Strategy itself prioritises. If the same unit that helps a ministry deploy an AI system is also responsible for assuring its safety, the credibility of that assurance is undermined. Separating these functions internally — while keeping them under one Authority for efficiency — preserves coherence while safeguarding the impartiality Cyprus needs to be recognised as a “trusted jurisdiction” under Objective 1 (Section 2.5.1). Section3.5 (Priority Sectors) and also Chapter 3 (cross-cutting nature of AI) We recommend the governance chapter state explicitly that AI's cross-sectoral character is itself the institutional justification for a single, sufficiently senior Authority, rather than sector-by-sector coordination alone. The Authority's founding mandate should include a statutory duty to publish an annual, cross-sector “State of AI Adoption and Governance” report to the Council of Ministers and the House of Representatives, consolidating inputs from all eight Priority Sectors, so that cross-cutting risks and opportunities in data infrastructure, skills and trust are visible nationally rather than siloed within each sector's own review cycle. The Strategy's own priority-sector analysis — financial services, healthcare, tourism, legal services, education, shipping, entrepreneurship and government — shows that the same underlying enablers (data governance in Section 3.2, compute infrastructure in Section 3.7, skills in Section 3.6, and trust in Section 3.9) recur across every sector. Without one body with visibility across all of them, ministries and regulators risk duplicating investment (already flagged as a risk for compute in Section 3.7) or developing inconsistent standards for the same underlying AI capability. A cross-sector reporting duty operationalises the whole-of-system approach the Strategy already commits to in Section 3. Section1.5 (Implementation Timeline: “0–8 months: Governance activation, authority establishment”) Given the Strategy's own 0–8 month target for “authority establishment,” we recommend the Council of Ministers fast-track the drafting and adoption of the founding legal instrument for the National AI Authority in parallel with, rather than after, finalisation of the Strategy text, so that the institutional vehicle exists before the first wave of ministry Applied AI Strategies and flagship “moonshot” programmes (Section 3.5) is due to launch. Comparable jurisdictions show that the institutional design phase is frequently the longest-running item on the critical path (e.g., Ireland's AI Office was announced well before its planned August 2026 operational date). If Cyprus sequences legal establishment after strategy adoption rather than alongside it, the Authority may not be operational when ministries are expected to begin implementation, undermining the Strategy's own timeline and creating exactly the execution gap identified in Section 1.4 (“limited applied AI experience within ministries … risk of AI theatre”).   3. Reasoning of the appraisal and the suggestion: Why AI requires an Independent Implementation Authority? Beyond the specific drafting comments above, we set out the broader institutional rationale for the Council of Ministers' consideration: 3.1 AI is a horizontal, not a vertical, policy domain Unlike sector-specific technologies, AI simultaneously affects data governance, cybersecurity, procurement, competition, labour markets, fundamental rights, financial supervision, healthcare regulation, judicial administration and education policy — often within a single use case. The Strategy's own structure, built around eight Priority Sectors sharing common enablers (data, compute, skills, trust — Sections 3.2, 3.6, 3.7, 3.9), is itself evidence that no single sectoral ministry can own AI implementation end-to-end. A cross-cutting problem requires a cross-cutting institution with the standing to convene, and where necessary direct, action across ministries that would not otherwise coordinate. 3.2 Independence protects both innovation and public trust The state will simultaneously be one of the largest deployers of AI in Cyprus (through the Government and Public Sector priority use cases) and the entity responsible for setting the rules that govern that deployment. Only a body with genuine operational and budgetary independence — rather than a unit embedded within a single ministry's hierarchy — can provide guidance and assurance that is, and is seen to be, impartial. This is particularly important for AI used in health, justice, welfare, migration and policing, where citizens must be able to trust that oversight is not simply the ministry marking its own homework. 3.3 A Council of Ministers mandate gives the Authority the authority to act A body created by administrative circular or informal designation can be diluted or bypassed the moment a competing ministerial priority emerges. A mandate formally granted and periodically reaffirmed by the Council of Ministers — covering both public-sector and private-sector implementation — gives the institution the political weight to require ministries to align their Applied AI Strategies (Section 3.4), to coordinate the national AI regulatory sandbox under Article 57 of the EU AI Act, and to represent Cyprus credibly in EU and international AI governance forums, including the European Artificial Intelligence Board, the Global Partnership on AI, and relevant OECD, WHO and ITU processes referenced in Section 3.8 of the Strategy. 3.4 Cross-sector economic and investment stakes require a single point of institutional accountability The Strategy sets ambitious national targets — up to 15% productivity improvement, 12% GDP expansion, and over 3,000 new AI professionals by 2032 (Section 2.5.2, Section 2.5.5). These targets span government, financial services, healthcare, tourism, legal services, education, shipping and the startup ecosystem simultaneously. Investors, SMEs and international partners need one credible institutional counterpart for AI policy in Cyprus — not eight separate sectoral conversations. A single, independent, adequately resourced Authority, operating under a clear Council of Ministers mandate and in structured cooperation with the Deputy Ministry, the Commissioner of Electronic Communications, EU institutions and international bodies such as the OECD and GPAI, is the institutional design most likely to deliver on the Strategy's own ambition. 4. Conclusion We support the Strategy's direction and its recognition, in Section 3.3, that a National AI Authority is required. We urge that, in the final version submitted to the Council of Ministers, the Authority's independence, legal personality, cross-sectoral and dual (public/private) mandate, non-duplication protocol with existing EU AI Act competent authorities, and internal separation between assurance and adoption functions be stated explicitly rather than left to future secondary legislation. This would ensure Cyprus moves, in practice and not only on paper, from a strategy document to an operational, trusted and internationally credible AI implementation capability by the Strategy's own 2032 horizon. Dr. G. Kentas, Associate Professor of Politics and Governance, Director of the Master Program of Public Administration at the University of Nicosia" "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",WDD-IT,"The Water Development Department welcomes the proposed Cyprus National Artificial Intelligence Strategy and supports its objective of establishing a coordinated, secure, human-centred, and outcomes-driven framework for the adoption of artificial intelligence across government and the wider economy. We particularly welcome the Strategy’s emphasis on trustworthy AI, human oversight, data governance, interoperability, shared national infrastructure, cybersecurity, public-sector capability development, and measurable public value. We also support the recognition of Energy, Environment and Resource Management, including water management, as a national priority for AI research and innovation. The Strategy specifically identifies water-scarcity monitoring, precision irrigation, and water-use optimisation as relevant areas for development. Given Cyprus’s exposure to water scarcity, drought, climate variability, energy-intensive water production, and increasing pressure on water infrastructure, we recommend that Water Resources Management be identified more explicitly as a strategic national AI application area. The Water Development Department should be included as a key stakeholder in the relevant governance, research, data, infrastructure, and implementation workstreams. 1. Priority AI Applications for Water Management AI can provide significant public value by improving forecasting, monitoring, operational planning, infrastructure management, and evidence-based decision-making. The following use cases should be considered for inclusion in the Department’s initial Applied AI portfolio: 1. Water-demand forecasting: Combining historical consumption, weather, seasonal activity, population, and other relevant data to support operational and infrastructure planning. 2. Reservoir inflow and drought forecasting: Using hydrological, meteorological, catchment, and historical data to improve storage projections and provide early warning of water-scarcity conditions. 3. Leakage and network-anomaly detection: Analysing flow, pressure, smart-meter, and telemetry data to identify abnormal network behaviour and support the prioritisation of inspections. 4. Predictive maintenance: Using sensor data, operating hours, fault histories, and maintenance records to estimate failure risk for pumps, treatment facilities, pipelines, telemetry systems, and other critical assets. 5. Energy optimisation: Supporting the efficient scheduling of water production, treatment, pumping, and distribution while considering demand, storage, electricity costs, infrastructure constraints, and service-continuity requirements. 6. Water-quality monitoring: Detecting unusual patterns in sensor or laboratory data, subject to verification by qualified personnel and established regulatory procedures. 7. Geospatial and remote-sensing analytics: Supporting catchment monitoring, infrastructure inspection, environmental assessment, and analysis of changes affecting water resources. 8. Secure departmental knowledge services: Improving access to legislation, technical manuals, policies, contracts, correspondence, and institutional knowledge through shared government document-intelligence and knowledge-search capabilities. AI should initially operate primarily in a monitoring, forecasting, or advisory capacity. Decisions involving water allocation, public health, critical infrastructure, or continuity of essential services must remain subject to authorised human oversight. 2. Data, Infrastructure and Interoperability The effective application of AI in water management depends on reliable and interoperable data from telemetry systems, GIS platforms, reservoirs, hydrological monitoring, water-quality systems, laboratories, smart meters, maintenance systems, asset registers, remote-sensing platforms, and administrative applications. We support the Strategy’s proposed federated national data architecture, secure API-based exchange, common standards, and treatment of data as a strategic national asset. The proposed National AI Infrastructure should provide secure experimentation, testing, validation, and production environments, including protected services for sensitive public-sector data. Shared services should include model and dataset registries, secure integration gateways, monitoring and logging, document intelligence, multilingual assistance, and government knowledge-search capabilities. Architecture and procurement frameworks should also require data portability, open and documented interfaces, transparent licensing, clear intellectual-property arrangements, exit provisions, and protection against unauthorised reuse of government data for external model training. 3. Cybersecurity and Critical Infrastructure AI used in connection with operational technology, telemetry, industrial control systems, or critical water infrastructure must be distinguished from general administrative AI and subjected to enhanced safeguards. Minimum requirements should include: • separation and segmentation of IT and operational-technology (ΟΤ) environments; • least-privilege access and controlled integration interfaces; • independent security and technical validation; • tested manual overrides and fail-safe operating procedures; • business-continuity and disaster-recovery arrangements; • model, software, and supply-chain assurance; • comprehensive logging and continuous monitoring; • secure update and change-management procedures; • incident reporting and response; and • periodic security assessment and penetration testing. AI should not be permitted to exercise direct autonomous control over water production, treatment, pumping, or distribution systems unless the use case has passed formal risk, safety, security, and operational-readiness assessments and has been expressly approved by the competent authorities. A common public-sector AI cybersecurity baseline should address AI-specific threats, including data poisoning, prompt injection, model manipulation, insecure agents and connectors, compromised updates, information leakage, excessive permissions, and dependency on external providers. 4. Principal Recommendations The Water Development Department recommends that the final Strategy and implementation roadmap: 1. explicitly recognise water-resource management as a strategic national AI application area; 2. include the Water Development Department in relevant national AI workstreams; 3. establish common data-governance, interoperability, API, and data-quality standards; 4. provide secure shared AI infrastructure and reusable government services; 5. issue enhanced safeguards for AI connected to critical infrastructure and operational technology; 6. publish a common public-sector AI cybersecurity baseline; 7. provide specialised training and implementation support to public-sector personnel; and 8. fund data preparation, integration, security, testing, monitoring, and organisational change, not only the acquisition of AI software. 5. Conclusion The Water Development Department supports the overall direction of the Cyprus National Artificial Intelligence Strategy. AI can strengthen the sustainable and resilient management of Cyprus’s water resources through better forecasting, early warning, leakage detection, predictive maintenance, water-quality monitoring, energy optimisation, and decision support. Successful implementation will depend on trusted data, secure and interoperable infrastructure, clear accountability, appropriate human oversight, specialist skills, sustainable funding, and enhanced protection for critical infrastructure. The Water Development Department is well positioned to contribute its operational expertise, technical knowledge, sectoral data, and practical use cases to the implementation of the National AI Strategy." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",CSEO,"SUBMISSION TO THE PUBLIC CONSULTATION ON THE NATIONAL ARTIFICIAL INTELLIGENCE STRATEGY 2032 OF THE REPUBLIC OF CYPRUS Submitted by: Cyprus Space Exploration Organisation (CSEO) Date: 31 August 2026 Subject: Strategic Alignment, Structural Feedback, and Institutional Implementation Pathways 1. INTRODUCTION AND GENERAL STATEMENT OF SUPPORT The Cyprus Space Exploration Organisation (CSEO) commends the Deputy Ministry of Research, Innovation and Digital Policy, the Chief Scientist for Research, Innovation and Technology, and the National AI Taskforce on the formulation and publication of the Cyprus National AI Strategy 2032: A Strategic Blueprint. The Strategy articulates a coherent, forward-looking roadmap for the Republic of Cyprus. CSEO strongly endorses its foundational pillars: its human-centred design, its disciplined focus on strategic differentiation rather than unconstrained scale, its commitment to digital sovereignty through trusted international partnerships, and its focus on translating frontier research into measurable societal and economic impact. From an aerospace, mission-critical, and international governance perspective, Artificial Intelligence represents a transformative, dual-use general-purpose technology with profound societal, economic, and geopolitical implications. Historically analogous to the governance imperatives surrounding nuclear capabilities, advanced AI presents a defining duality: immense potential for human augmentation and economic productivity on the one hand, and systemic, existential risks to security, privacy, and social stability if left unregulated on the other. As an International Space Innovation Centre and a globally recognized Centre of Excellence selected by the Committee on Space Research (COSPAR) to act as a multi-continental bridge for space innovation, CSEO operates as a trusted, neutral interlocutor across the international scientific landscape. Through institutional leadership within COSPAR and its Panel on Innovative Solutions (PoIS), the NASA Artemis Accords, the Global Expert Group on Sustainable Lunar Activities (GEGSLA), and the Mars Upper Atmosphere Network (MUAN), CSEO actively positions Cyprus at the core of multilateral technological cooperation. Domestically, through the Cyprus Space Research and Innovation Centre (C-SpaRC), the organisation develops mission-critical, AI-driven applications, including space weather predictive modelling, downstream satellite data analytics, and autonomous systems. CSEO submits the following feedback to reinforce the Strategy's implementation, strengthen its governance architecture, and present concrete operational pathways through which our ecosystem will actively support the realization of the national vision under the Quadruple Helix framework (Government, Academia, Industry, and Society). 2. STRATEGIC OBSERVATIONS AND STRUCTURAL CONTRIBUTIONS POINT 1: STRATEGIC TECH DIPLOMACY AND HIGH-LEVEL EU AI LEADERSHIP Strategy Reference: Section 1.1 (The Vision), Section 2.5.8 (Objective 8: Develop Sovereign Capability through Partnerships), Section 3.12 (International Cooperation and EU Alignment). Observation and Recommendation: The Strategy correctly identifies Cyprus's potential to serve as an EU-to-regional bridge. To elevate this geographic advantage into an active geopolitical capability, Cyprus should establish a proactive Tech Diplomacy doctrine. Furthermore, the Republic of Cyprus should advocate at the European level for the creation of a High-Tier EU AI Standardization and Regulatory Committee, positioning Cyprus and its technocratic leadership (such as the Chief Scientist) in a prominent role in shaping EU-wide regulatory and technical standards. Additionally, the Republic should establish strategic bilateral government-to-government dialogues with leading EU Member States that host major global AI enterprises (such as Ireland) to exchange regulatory sandbox models, compliance architectures, and high-tech investment attraction strategies. Operational Alignment and Ecosystem Contribution: Leveraging its standing as a COSPAR-designated global Centre of Excellence bridging the US, Europe, and Asia, CSEO will facilitate high-level multilateral technical exchanges, supporting the Republic's international standing as a trusted technological broker. POINT 2: MISSION-CRITICAL STANDARD-SETTING: SPACE WEATHER (SWx) AI FOR AVIATION AND ASTRONAUTICS Strategy Reference: Section 3.7 (Infrastructure, Compute and Digital Sovereignty), Section 3.8.1 and Annex D (Focus Area 4: Security, Defence and Space), Annex C (Shipping, Maritime and Critical Infrastructures). Observation and Recommendation: Advanced predictive AI is indispensable for safeguarding critical national and global infrastructure against severe solar events and geomagnetic disruptions, which directly threaten high-altitude civil aviation, satellite constellations, maritime communications, GNSS/GPS navigation, and terrestrial power distribution. AI-driven Space Weather (SWx) predictive modelling is a national strategic niche where Cyprus can establish European and global technical standards. Operational Alignment and Ecosystem Contribution: Through C-SpaRC and in cooperation with global space industry leaders, including members of the COSPAR Committee on Industry Relations (CIR), CSEO is actively advancing high-accuracy AI predictive models for Space Weather. CSEO will work to integrate these capabilities into European resilience frameworks, positioning Cyprus as an international reference node for aviation and astronautics protection. POINT 3: ETHICAL GOVERNANCE AND DUAL-USE RISK MANAGEMENT (""THE NUCLEAR ANALOGY"") Strategy Reference: Section 1.1 (Fundamental Principles), Section 2.5.7 (Objective 7: Embed strong governance, ethics and accountability), Section 3.9 (Ethics, Trust and Responsible AI). Observation and Recommendation: The Strategy's rigorous alignment with the EU AI Act and human-centric governance should be highlighted as a vital protective framework for citizens, public institutions, and national resilience, rather than an administrative burden. Because advanced AI models possess dual-use characteristics with systemic risks analogous to nuclear technology, strict regulatory guardrails, continuous assurance, and human-in-the-loop oversight are fundamental prerequisites for sustainable societal adoption. Operational Alignment and Ecosystem Contribution: Drawing on its international experience as an honest broker within multilateral governance frameworks (such as the Artemis Accords and GEGSLA), CSEO will support the National Ethics and Values Committee and the National AI Misinformation and Security Council, providing specialized expertise on dual-use risk assessment and international compliance alignment. POINT 4: PROTECTING CITIZEN RIGHTS: PRIVACY, BIOMETRICS AND DIGITAL IDENTITY IN PERPETUITY Strategy Reference: Section 3.1.2 (Trust and Transparency), Section 3.9.6 (AI Social Contract Principles), Annex C (Legal Services). Observation and Recommendation: In response to public and industry concerns surrounding synthetic media, voice synthesis, and digital cloning, the Strategy should state that national policy guarantees the protection of personal data, biometric likeness, voice, and artistic creation in perpetuity. The legal and regulatory framework must prevent unauthorized commercial exploitation, synthetic imitation, or perpetual digital replication (such as digital avatars) of individuals, actors, and creators without verifiable, revocable, and legally audited consent. Operational Alignment and Ecosystem Contribution: CSEO will collaborate with competent authorities to support the technical validation of cryptographic provenance, content integrity, and digital rights protection architectures across research and innovation testbeds. POINT 5: WORKFORCE TRANSFORMATION, HIGH-SKILL JOB CREATION AND THE QUADRUPLE HELIX Strategy Reference: Section 2.5.2 (National Productivity and Employment Effects), Section 2.5.5 (Objective 5: Develop, attract and retain AI-related skills and talent), Section 3.6 (Talent, Skills and Workforce Transformation), Annex C (Education and Human Capital Development). Observation and Recommendation: Demonstrating that the National Strategy acts as an engine for high-value job creation is essential for maintaining broad public and institutional confidence. The target of developing 3,000+ certified AI professionals by 2032 should be operationalized through an active Quadruple Helix model, linking academia and specialized research facilities directly to high-skill industrial employment and domestic talent retention (brain gain). Operational Alignment and Ecosystem Contribution: CSEO and C-SpaRC will support the FutureAI CY programme by hosting postgraduate fellowships, master's and doctoral research tracks, and specialized training modules in machine learning for physical sciences, satellite data engineering, and autonomous systems. POINT 6: DOWNSTREAM SPACE DATA INTEGRATION AND ENERGY-EFFICIENT COMPUTING Strategy Reference: Section 3.2 (Data as a Strategic National Asset), Section 3.7 (Infrastructure, Compute and Digital Sovereignty), Section 3.10 (Sustainability and Green AI). Observation and Recommendation: The National Data Architecture should explicitly incorporate downstream Earth Observation (such as Copernicus and Sentinel) and maritime tracking data spaces, enabling AI-driven early detection of wildfires, flood monitoring, precision agriculture, and maritime surveillance. To ensure digital infrastructure development remains environmentally sustainable, the Strategy should balance sovereign infrastructure with access to European Supercomputing (EuroHPC and Pharos-CY) for large-scale training, while prioritizing energy-efficient Onboard Edge AI that processes data directly on satellite payloads and low-power edge nodes. Operational Alignment and Ecosystem Contribution: CSEO will contribute its expertise in low-power Edge AI payload design (developed for CubeSat platforms such as C-SpaRC-1) and downstream satellite data processing to support public-sector environmental and maritime use cases without overburdening the national energy grid. 3. CONCLUSION The Cyprus National AI Strategy 2032 establishes a balanced and authoritative roadmap that positions Cyprus as a trusted, highly competitive European jurisdiction. CSEO reaffirms its commitment to supporting the Deputy Ministry of Research, Innovation and Digital Policy, the Chief Scientist, and the National AI Taskforce in translating these strategic priorities into durable national capabilities and international leadership." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",PhilipposPanayi,"1. Overall quality and standard for future strategies: This is a comprehensive, well-structured and implementation-oriented strategy. Particularly positive is its focus on measurable national outcomes — including productivity, economic impact and AI workforce development —supported by defined governance, accountability and delivery mechanisms. This approach should serve as a benchmark for the development of future national strategy documents by the Government of Cyprus. 2. Immediate commencement of data preparation and cleansing: Data readiness is a fundamental prerequisite for successful AI implementation. Ministries and public-sector organisations should therefore begin data cleansing, classification and quality improvement activities immediately. Clear ownership and accountability for data quality should be assigned within each organisation. 3. Dedicated organisation for AI strategy execution: The proposed National AI Authority should be established as a dedicated, appropriately empowered and adequately resourced execution body, with clear responsibility and accountability for driving implementation of the Strategy across Government. 4. Healthcare as an early priority for implementation: Healthcare should be elevated to one of the first sectors for implementation. GESY already provides a significant advantage by generating and maintaining structured digital health data, including patient records, diagnoses, prescriptions, referrals, laboratory activity and other healthcare transactions. This existing body of organised health data can provide a strong starting point for AI applications such as clinical decision support, predictive and preventive care. Subject to confirmation of data quality and governance readiness, healthcare could provide an early opportunity to demonstrate measurable national impact from AI." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",yanahumen,"IBM welcomes the opportunity to participate in the ongoing public consultation on the National AI Strategy 2032 of the Republic of Cyprus and appreciates the efforts of the Chief Scientist, the National AI Taskforce and the Deputy Ministry of Research, Innovation and Digital Policy in developing a comprehensive national vision for artificial intelligence. We also recognise and strongly support the significant effort undertaken by the Strategy Committee. The Strategy sets out an ambitious objective for Cyprus to become a trusted AI hub in the Eastern Mediterranean, a reliable European jurisdiction for AI-enabled services, and a bridge between the European Union and neighbouring regions by 2032. IBM strongly supports the Strategy's overarching goal of fostering trustworthy and responsible AI adoption and welcomes the Government's commitment to engaging stakeholders through this public consultation process. In this spirit, we offer our recommendations with the objective of strengthening the Strategy's contribution to innovation, competitiveness, cybersecurity, and the development of an open and globally connected AI ecosystem. In our comments, we highlight that the strategy should remain technology-neutral, risk-based, and aligned with the EU Single Market. Achieving the Strategy’s objectives will also require sustained investment in future-ready skills and close alignment between the Strategy’s AI ambitions and the evolution of hybrid cloud and quantum technologies, which together will underpin the next generation of secure and high-performance computing. 1. Coordinate AI, quantum computing and cybersecurity strategies The AI Strategy should be implemented with holistic approach, in coordination with policies and investments in quantum computing, high-performance computing and cybersecurity. These technologies are increasingly complementary: AI can accelerate the design, calibration and operation of quantum systems, while quantum computing may open new avenues for machine learning, optimisation and scientific discovery. Policymakers should therefore foster integrated ecosystems in which AI, quantum processors and classical high-performance computing resources can be combined through open, interoperable and hybrid computing architectures. This should include coordinated investment in infrastructure, research, skills and early-stage industrial experimentation, as well as collaboration with international technology providers and research partners. This coordination must also address the cybersecurity implications of quantum computing. Future cryptographically relevant quantum computers could undermine widely used public-key cryptography, while “harvest now, decrypt later” attacks already create risks for sensitive data with a long confidentiality life. Our recommendation is therefore to start integrating post-quantum cryptography into AI, cybersecurity and critical-infrastructure planning now, rather than treating quantum safety as a future issue. AI solutions can help critical organisations accelerate specific stages of the migration process, including the preparation of cryptographic asset inventories and quantum-risk assessments. Ultimately, these efforts should align with the EU’s coordinated PQC roadmap and internationally recognised standards, while accounting for supply-chain dependencies and the long lifecycle of operational technology and critical infrastructure. 2. Preserve technical approach and avoid origin-based sovereignty criteria IBM supports the objective of strengthening digital sovereignty and trust in AI. However, sovereignty should be assessed based on the degree of technical, operational, and legal control exercised by customers over their data, systems, and business continuity, rather than provider’s nationality or headquarters location. In particular, we welcome the Strategy’s focus on building partnerships in Section 3.7 – however, the approach should be clearer to avoid interpretations that discriminate companies based on their country of origin. Requirements should be based on verifiable security, resilience, transparency, and governance outcomes, ensuring open competition and access to best-in-class technologies. 3. Avoid national gold-plating beyond the EU AI Act The strategy should build on existing EU legislation, including the AI Act, GDPR, and sectoral frameworks, without introducing additional national requirements that could create regulatory fragmentation. Consistency with EU rules will reduce compliance burdens, improve legal certainty, and support the development and deployment of AI solutions across the Single Market. 4. Accelerate AI adoption in priority sectors IBM welcomes the Strategy’s focus on sectors in which Cyprus has established economic strengths and where AI can deliver significant productivity, competitiveness and public-value gains, as outlined in Section 3.5. We recommend that the Strategy translates into concrete sectoral roadmaps, supported by access to trusted data, secure hybrid-cloud infrastructure, skilling initiatives, testbeds and regulatory sandboxes. Particular attention should be given to the following sectors: - Tourism and hospitality: AI can support demand forecasting, personalised visitor services, multilingual assistance, destination management, resource optimisation and more sustainable tourism. - Healthcare and life sciences: AI can augment clinical decision-making, improve patient pathways and preventive care, support resource planning and accelerate research, subject to strong protections for sensitive health data, governance and human oversight. - Financial services and fintech: AI can strengthen fraud detection, risk management, compliance, customer due diligence and operational efficiency. - Energy: while this sector is not highlighted in the Strategy, we emphasise that AI can optimise grids and renewable-energy integration, forecast demand, improve asset maintenance and energy efficiency, and increase the resilience of critical infrastructure. A coordinated approach across these sectors would create reusable capabilities and economies of scale, accelerate diffusion among smaller enterprises, and enable successful solutions developed in Cyprus to expand across the EU Single Market and internationally. 5. Foster innovation through proportionate governance Trustworthy AI provides the foundation for sustainable innovation. At the same time, Governance mechanisms should be proportionate, risk-based, and targeted at high-risk use cases. The strategy should encourage experimentation, AI sandboxes, public-private collaboration, and rapid adoption of beneficial AI applications. Excessive approval layers, mandatory certifications, or broad compliance obligations risk slowing deployment, increasing costs, and reducing the attractiveness of Cyprus as a destination for AI investment and innovation. The Strategy should also recognise the shift from governance based primarily on policies, assessments, and periodic human review towards the technical enforcement of risk and compliance requirements at runtime. While not every control can be automated, this evolution is particularly important for agentic AI systems, where risks may emerge dynamically across multi-step workflows and cannot be addressed adequately through human processes alone. Section 3.3.2 should therefore explicitly promote the implementation of proportionate runtime controls to complement organisational governance and enable scalable, trustworthy deployment. 6. AI skills IBM welcomes the Strategy's strong focus on AI skills, workforce development, and lifelong learning. We particularly support the recognition that AI should be used to augment human capabilities and productivity, enabling people to work more effectively alongside AI systems rather than simply automating tasks. To ensure that skills programmes remain aligned with rapidly evolving technologies and labour market needs, Cyprus should promote close collaboration between government, academia, and industry in the design and delivery of AI education, training, and reskilling initiatives. Such partnerships will be critical to developing a future-ready workforce and supporting the successful adoption of AI across the economy. Conclusion We recommend that the Strategy positions Cyprus as an open, innovation-friendly AI hub by combining strong security and governance with technology neutrality, support for AI development, interoperability with international standards, and full alignment with the EU Single Market." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",ppsavva@outlook.com,"The Digital Transformation & Fintech Committee of the American Chamber of Commerce in Cyprus (AmCham Cyprus) welcomes the publication of the Cyprus National AI Strategy 2032 and commends the Chief Scientist, the National AI Taskforce, the Deputy Ministry of Research, Innovation and Digital Policy, and all contributing stakeholders for developing a comprehensive and ambitious framework for the future of Artificial Intelligence in Cyprus. The Strategy reflects a clear vision to position Cyprus as a trusted AI hub in the Eastern Mediterranean, a reliable European jurisdiction for AI-enabled services, and a bridge between Europe and neighboring markets. Its focus on innovation, productivity, public sector transformation, skills development, data governance, cybersecurity, ethics, and international cooperation provides a strong foundation for the country's digital future. The Committee is fully supportive of the Strategy's overarching objectives and recognizes the significant effort invested in creating a forward-looking roadmap that aligns with European values, regulatory frameworks, and the opportunities presented by emerging AI technologies. We particularly welcome the emphasis on trustworthy, human-centered AI, the commitment to strengthening Cyprus's competitiveness, and the aspiration to create an ecosystem that fosters innovation, investment, entrepreneurship and talent development.  At the same time, the successful implementation of the Strategy will depend not only on vision but also on execution. The Committee therefore offers the following recommendations in a constructive spirit, with the objective of strengthening the Strategy's practicality, investment attractiveness, governance effectiveness, cybersecurity resilience, and ability to deliver measurable economic and societal outcomes. These recommendations reflect common themes and areas of consensus that emerged during the Committee's discussion and from stakeholder feedback received from businesses, technology providers, professional services organizations and industry experts. We submit these observations with the shared objective of helping Cyprus establish itself as a leading trusted AI Nation, capable of combining strong governance and regulatory certainty with openness, innovation, international collaboration, and sustainable economic growth: 1. Create a National AI Delivery Office The successful implementation of the Strategy will require dedicated execution capacity, not only governance and advisory structures. The Committee recommends establishing a compact, empowered and appropriately resourced National AI Delivery Office responsible for coordinating the national implementation portfolio. The Delivery Office should bring together program management, enterprise architecture, data governance, cybersecurity, procurement, legal and regulatory expertise, change management and benefits realization. It should support ministries and public bodies, coordinate dependencies, maintain visibility across publicly funded AI initiatives, and prevent fragmented or duplicative investments. Its role should be clearly distinguished from that of the authorities responsible for regulatory supervision, market surveillance, data protection, and sector-specific enforcement. Ministries and public bodies should retain accountability for their respective services and outcomes, while the Delivery Office provides central coordination, common implementation standards, and practical delivery support. 2. Add a Funded Delivery Roadmap The Committee recommends complementing the Strategy with a funded, three-year rolling delivery roadmap that translates its ambitions into an executable national program. For every major initiative, the roadmap should define: -The accountable owner and participating organizations. -The approved budget and funding source. -The delivery timeline and key milestones. -The procurement and implementation route. -Dependencies on data, infrastructure, skills or legislation. -Expected economic, operational or societal benefits. -Measurable performance indicators. -Risk, review and exit criteria. -Arrangements for periodic public reporting. The roadmap should reconcile the different adoption targets and implementation dates contained in the Strategy, establish realistic sequencing, and distinguish between immediate priorities, medium-term initiatives and longer-term ambitions. No significant initiative should enter the national AI portfolio without a defined owner, budget, delivery date, and measurable outcome. 3. Strengthen the Data Implementation Layer The Committee considers data readiness to be the most important prerequisite for scaling AI responsibly. The Strategy should therefore strengthen its practical data implementation layer and ensure that data governance progresses before, or in parallel with major technology procurement. The Committee recommends: -Assigning an accountable data owner and data steward for every priority public-sector dataset. -Establishing minimum standards for data quality, classification, metadata, lineage, retention and lawful use. -Creating a national catalogue of high-value datasets that identifies ownership, availability, access conditions and permitted uses. -Prioritising secure APIs, common data standards and interoperability over point-to-point integrations. -Requiring a formal data-readiness assessment before approving or funding a significant AI project. -Developing governed sectoral data spaces and secure testing environments that permit controlled use without unnecessary copying or centralisation. -Defining clear rules for confidentiality, intellectual property, anonymisation, pseudonymisation, audit rights and derived data or model outputs. -Clarifying lawful cross-border data access and transfer arrangements under applicable European legislation. This implementation layer should be closely aligned with the National Data Policy and the National Data Governance Framework to avoid parallel or inconsistent structures. 4. Prioritise a Limited First Wave The Strategy contains a broad portfolio of sectors, institutions, platforms, funds, centers, sandboxes, and transformational projects. While these ambitions are strategically valuable, attempting to launch too many initiatives simultaneously risks spreading limited funding, leadership attention and specialist expertise too thinly. The Committee recommends selecting a limited first wave of national AI missions based on economic and public value, data readiness, implementation, feasibility, scalability, cybersecurity risk and the potential to create reusable capabilities. The initial portfolio could concentrate on: 1. AI-enabled government and citizen services, particularly high-volume services with repetitive processing, significant document requirements or long response times. 2. AI for regulated financial, fintech and professional services, including AML/KYC, compliance, regulatory reporting, audit support and administrative efficiency. 3. AI for healthcare administration and care navigation, implemented with strong data protection, clinical accountability and human oversight. Other strategic sectors should continue through research, preparation, and controlled experimentation, but the first major funding and implementation cycle should be concentrated on a manageable number of missions. Each first-wave mission should begin with a validated problem, confirmed data readiness, an accountable owner, a funded business case, and measurable success criteria. 5. Make Cybersecurity and Resilience a Foundational Requirement Cybersecurity should be embedded horizontally across the entire AI lifecycle, from data preparation and system design through procurement, deployment, monitoring, material modification, and decommissioning. Every publicly funded, critical or high-impact AI system should pass a proportionate AI Security and Resilience Assessment before entering production. The assessment should address: -Data protection and information classification. -Identity, privileged access and machine identities. -APIs, AI agents and system integrations. -Models, training data and AI supply chains. -Third-party and supplier risk. -Data poisoning, adversarial manipulation and prompt-based attacks. -Secure logging, monitoring and auditability. -Model performance, drift and misuse detection. -Human intervention, override and rollback. -Incident reporting and coordinated response. -Business continuity, portability and secure exit arrangements. High-impact and critical systems should be subject to independent assurance where appropriate. AI-related incidents should also be integrated into existing national cybersecurity, data-protection, and sector-specific incident-management structures. 6. Support SME Adoption SMEs are central to the Cypriot economy but often lack the specialist expertise, financial capacity and infrastructure required to adopt AI responsibly. The Strategy should therefore include a practical, accessible and proportionate SME AI Adoption Program. The program should provide: -AI readiness and data-readiness assessments. -Implementation and advisory vouchers. -Standard AI policies and governance templates. -Risk-classification and impact-assessment tools. -Vendor-assessment questionnaires and procurement guidance. -Cybersecurity and compliance support. -Affordable access to compute, testbeds and sector sandboxes. -Access to recognised advisers and implementation partners. -Guidance on intellectual property, data use and contractual protections. -Market-access and export support for validated AI solutions. Requirements should be proportionate to organizational size, use-case risk and potential impact. Low-risk productivity tools should not be subject to the same burden as high-risk or rights-impacting systems. Public support should be released progressively and linked to measurable results, such as productivity improvement, reduced administrative costs, improved service quality, new revenue, export potential or successful progression from pilot to responsible production use. 7. Develop Role-Based Skills and Professional Capability AI skills policy should extend beyond technical specialists. The Committee recommends role-based education and professional-development pathways for: -Executives and board members. -Public servants and policymakers. -Accountants, auditors and finance professionals. -Legal and compliance professionals. -Procurement and commercial teams. -Data owners and data stewards. -Cybersecurity and risk professionals. -Educators and trainers. -Regulators and assurance professionals. -SME leaders and frontline personnel. Training should combine AI literacy with governance, cybersecurity, data protection, responsible use, procurement, change leadership and practical sector applications. Programs should be aligned with labor-market needs, recognized for continuing professional development frameworks, and applied workplace projects. Cyprus should also build local AI governance, cybersecurity, implementation, testing and assurance capabilities that can support domestic adoption and develop into exportable professional services. 8. Measure Outcomes, Not Activities The Strategy’s measurement framework should prioritize economic, operational, citizen and societal outcomes. Each national KPI should have a clearly defined baseline, calculation methodology, accountable owner, data source, reporting frequency, and target trajectory. Priority measures should include: -Productivity improvements. -Reductions in service-processing times. -Reductions in administrative cost and backlog. -Improvements in citizen and customer experience. -SME adoption and progression to production. -Investment attraction and business expansion. -Creation of high-skilled employment. -Workforce reskilling and transition outcomes. -Growth in AI-enabled products and exportable services. -System reliability, cybersecurity and compliance. -Public trust and responsible-use indicators. The number of pilots, committees, systems purchased, individuals trained or events organized may provide useful supporting information but should not be treated as the principal evidence of success. Underperforming initiatives should be redesigned or discontinued, while successful and reusable capabilities should be scaled across ministries and sectors. 9. Preserve Openness, Investment and Trusted International Partnerships Cyprus’s ambition to develop strategic AI capability should be pursued through openness, interoperability and trusted international cooperation. The Committee recommends defining AI sovereignty and strategic autonomy in terms of effective governance, security, resilience, legal control, portability and strategic choice, rather than domestic ownership, supplier nationality or blanket data localization. Cyprus should retain meaningful control over critical data, services and operational decisions while leveraging trusted European, United States and other international partners to obtain the technology, compute capacity, expertise, investment and access to global markets required to achieve scale. International partnerships should be assessed using objective criteria, including security, transparency, legal enforceability, supply-chain assurance, operational continuity, and alignment with European law and values. The Committee recommends: -Ensuring that public procurement, infrastructure access, funding programmes and testing environments apply transparent, proportionate and technology-neutral criteria. -Avoiding origin-based preferences or localisation requirements unless objectively justified by applicable law, national security, data sensitivity or demonstrated operational risk. -Supporting lawful cross-border data access and transfers under applicable European data-protection legislation. -Protecting pre-existing intellectual property, confidential business information, trade secrets and cybersecurity-sensitive technical evidence. -Defining clear rights for public-sector data, supplier data, project-created intellectual property, derived outputs and model improvements. -Requiring interoperability, data portability, supplier-transition arrangements and tested exit plans to reduce concentration and vendor lock-in. -Recognising equivalent international standards, technical evidence and assurance practices where permitted by European law. -Creating clear and coordinated pathways for trusted international investors, technology providers, research institutions and implementation partners to establish, test, develop and scale AI-enabled services from Cyprus. -Strengthening structured cooperation between Cyprus, the European Union, the United States and other trusted jurisdictions in areas such as research, skills, cybersecurity, standards, testing, investment and responsible AI deployment. Strategic autonomy should provide Cyprus with control, resilience and choice without limiting access to global innovation. A clear and investment-compatible approach will strengthen Cyprus’s position as a trusted European jurisdiction, attract international capital and expertise, support domestic companies and researchers, and enable AI solutions developed or validated in Cyprus to scale into European and neighboring markets. This directly addresses the attached AmCham position paper’s concerns around sovereignty, localization, procurement, cross-border data flows and intellectual property protection.  The Committee values the opportunity to contribute to this important national dialogue and stands ready to support the next phase through continued cooperation among government, industry, academia, professional bodies and civil society." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",UiPath,"Public Consultation Submission — Cyprus National AI Strategy 2032 Consultation: Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας Submitted by: Christos Michas Date: 31 August 2026 Note It is encouraging to see Cyprus develop a National AI Strategy and make it available for public consultation. The Deputy Ministry of Research, Innovation and Digital Policy, the Chief Scientist for Research, Innovation and Technology, the National AI Taskforce and all those involved in preparing the Strategy should be congratulated. Our comments below come from twenty years of building automation for enterprises and, more recently, watching what actually happens when AI agents get put in front of real processes — not demos. Daniel Dines, UiPath's founder, wrote a whole book about this recently (The Work That Remains - https://www.uipath.com/resources/automation-whitepapers/the-work-that-remains), and the short version of the argument is the one we keep coming back to here: an agent proposes, a person decides, and deterministic automation executes — and the thing that has to be governed is the map (the description of how the work actually happens: who decides what, where the exceptions are, what gets audited) and the rails (the machinery that carries out the approved, stable parts of that map, exactly the same way every time). The agent sits on top of both. It isn't either one. The Strategy talks a lot about AI agents and use cases but never quite separates the agent from the process it's dropped into. That's the gap our four comments are about. We've kept them short. We'd also flag that this isn't just our house view. Independent commentary elsewhere in the industry has been making the same point from a different angle recently: model capability keeps expanding fast enough that anything an organisation hard-wires into an agent today is likely to be rebuilt or replaced within a year or two, while a well-written description of the process — the goal, the constraints, who signs off, what counts as done — stays valid across that churn. Whoever ends up building or supplying the agents to Cyprus's public sector, that description is the thing worth Cyprus owning. Comment 1 — Govern the process, not the agent Άρθρο: Annex G Glossary (pp. 95–96); Section 3.3.2 Control Framework (pp. 27–28); Annex B Control Gate 1 (pp. 57–58) Σχόλιο: Add ""AI agent"" and ""process/workflow"" as separate terms in the Glossary, and say explicitly in Section 3.3.2 and Annex B that risk classification, approval gates and human oversight attach to the process the agent is used in, not to the agent itself. Αιτιολόγηση: An agent's ability to produce a good answer doesn't automatically give anyone permission to act on it — that permission comes from who owns the decision, what gate the work has to pass through, and what gets recorded afterward. Those things live in the process, not in the model. One agent can sit inside a low-risk internal task this week and a citizen-facing benefits decision next week, completely unchanged. Certifying ""the agent"" once tells nobody whether this particular use of it, right now, in this particular process, is safe. This is also how the AI Act itself works: Annex III classifies risk by use case, not by the technology underneath it. Comment 2 — Map the process before automating it, and write down why each step is RPA, an agent, or a person Άρθρο: Section 3.4.1 (p. 28) and 3.4.2 (p. 28); Annex B Stage 1 / Control Gate 1 (pp. 57–58) Σχόλιο: Before a use case clears Control Gate 1, require a short written map of the process — what it touches, who decides what, where the exceptions live — with each step assigned to RPA, an AI agent, or a human. Drop the ""AI-first procurement"" commitment in 3.4.1 in favour of this. Αιτιολόγηση: Not everything needs an agent. Rule-based, high-volume steps are usually cheaper and more predictable on deterministic automation; steps that need judgement should stay with a person. Annex B already lists RPA as a ""quick win"" option at Stage 1 (p. 58), so the thinking is already there — it just doesn't make it into the procurement principle. ""AI-first"" as a default pushes the opposite way: reaching for an LLM where a rule-based bot would be faster, cheaper, and have a lot less that can go wrong. Most process charts also only describe the happy path; the exceptions are where the real risk sits, and they're worth mapping honestly rather than assumed away. Comment 3 — Testing and monitoring can't stop at launch, and capability should be earned in stages Άρθρο: Annex B, Stage 4 ""Deployment and Operation"" and Control Gate 4 ""Operational Assurance Review"" (p. 59) Σχόλιο: Turn ""ongoing monitoring"" and ""periodic reviews"" at Stage 4 / Control Gate 4 into something concrete: a defined test cadence per process, a fixed test set re-run whenever the underlying model changes, and a rule that an agent doesn't get more autonomy on a process until it has earned it through evidence — and loses it automatically if performance drops. Αιτιολόγηση: An agent checking its own work has the same blind spots as the agent that did the work, so production systems need an independent check — a test, a rule, a person, something outside the agent itself. Models also don't hold still: the one behind an agent gets updated by its provider, a prompt changes, upstream data shifts, often without anyone downstream noticing. ""Periodic review"" without a number attached to it tends to quietly stop happening once the launch is old news — we've watched that happen plenty of times, and not only in government. A cheap, repeatable test set that runs on a schedule, plus a simple rule that trust is earned gradually and can be taken back, catches drift before a citizen does. Comment 4 — Measure ROI on the process, and treat the map — not the agent — as the durable asset Άρθρο: Section 3.11.1 and 3.11.2 (pp. 44–45); Annex F (pp. 93–94); Section 3.1.2 ""Reuse and interoperability"" (p. 19) Σχόλιο: Measure ROI (cycle time, cost per case, rework, citizen satisfaction) at the process level, not the agent level, and treat the documented process map as the thing worth keeping — a simple registry of what each redesigned process does, how each step is executed, and what its risk classification is — so ministries stop rebuilding the same process twice. Αιτιολόγηση: Section 3.11.1 already says the right thing — focus on what AI enables, not how many systems get deployed (p. 44) — but the actual indicators in 3.11.2 and Annex F still count use cases and systems deployed. An agent can score perfectly on accuracy and leave the process just as slow if nothing else around it changed. Agents will be swapped out, upgraded, replaced by better ones; that's normal and healthy. What shouldn't get thrown away every time is the documented knowledge of how the process actually works — who decides what, where the exceptions are, what happened last time something went wrong. That's the part worth Cyprus owning centrally, and it's what future agents plug into, not the other way round." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Monica Polemitis","1. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο:** Ενότητες 2.3, 2.4 και 2.5.1, τοποθέτηση της Κύπρου ως «Trusted AI Jurisdiction / Hub» Σχόλιο / Εισήγηση:Προτείνεται να αποσαφηνιστεί και να συγκεκριμενοποιηθεί το ανταγωνιστικό πλεονέκτημα της Κύπρου ως «trusted AI jurisdiction». Η συμμόρφωση με το ευρωπαϊκό κανονιστικό πλαίσιο αποτελεί αναγκαία προϋπόθεση για όλα τα κράτη μέλη και, από μόνη της, δεν συνιστά διαφοροποίηση. Η Στρατηγική θα πρέπει να προσδιορίζει με σαφήνεια γιατί μία επιχείρηση, επενδυτής ή οργανισμός θα επέλεγε την Κύπρο έναντι άλλης ευρωπαϊκής δικαιοδοσίας. Ενδεικτικά, η διαφοροποίηση θα μπορούσε να στηριχθεί στην ταχύτερη κανονιστική καθοδήγηση, στην εύκολη πρόσβαση σε regulatory sandboxes και testbeds, στην εξειδίκευση σε συγκεκριμένους ρυθμιζόμενους κλάδους, στην πρόσβαση σε αξιόπιστα δεδομένα και στην ταχεία μετάβαση από το pilot σε παραγωγική εφαρμογή. Αιτιολόγηση σχολίου / Εισήγησης: Μία εθνική στρατηγική χρειάζεται σαφή στρατηγική επιλογή και όχι μόνο έναν γενικό στόχο τοποθέτησης. Το ζητούμενο δεν είναι απλώς να δημιουργηθεί ένα αξιόπιστο περιβάλλον για την ΤΝ, αλλά να προσδιοριστεί σε ποιους συγκεκριμένους τομείς η Κύπρος μπορεί να είναι καλύτερη, ταχύτερη ή πιο αποτελεσματική από άλλες χώρες. Η συγκεκριμενοποίηση αυτής της πρότασης αξίας θα επιτρέψει επίσης τη δημιουργία μετρήσιμων δεικτών, όπως χρόνος πρόσβασης σε sandbox, χρόνος παροχής κανονιστικής καθοδήγησης, αριθμός εφαρμογών που περνούν από δοκιμή σε παραγωγή, επενδύσεις που προσελκύονται και εξαγωγές υπηρεσιών ΤΝ. 2. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Ενότητα 3.4.1, Παράρτημα Β και Ενότητα 5, «AI-first procurement» και υποχρέωση εντοπισμού πέντε περιπτώσεων χρήσης ΤΝ ανά Υπουργείο Σχόλιο / Εισήγηση: Προτείνεται η έννοια «AI-first» να αντικατασταθεί από μία προσέγγιση «problem-first» και outcome-based, όπου η ΤΝ εξετάζεται συστηματικά ως πιθανή λύση, χωρίς όμως να θεωρείται εκ των προτέρων η κατάλληλη τεχνολογία. Αντίστοιχα, η απαίτηση κάθε Υπουργείο να εντοπίσει συγκεκριμένο αριθμό περιπτώσεων χρήσης ΤΝ θα ήταν προτιμότερο να αντικατασταθεί από υποχρέωση εντοπισμού και ιεράρχησης προβλημάτων ή ευκαιριών μετασχηματισμού, βάσει αναμενόμενης αξίας, διαθεσιμότητας και ποιότητας δεδομένων, εφικτότητας, κόστους και κινδύνου. Αιτιολόγηση σχολίου / Εισήγησης: Η απαίτηση συγκεκριμένου αριθμού εφαρμογών ΤΝ ενέχει τον κίνδυνο να δημιουργήσει κίνητρο για χρήση της τεχνολογίας ακόμη και εκεί όπου δεν αποτελεί την καλύτερη λύση. Αυτό έρχεται σε αντίθεση με την ίδια τη φιλοσοφία της Στρατηγικής, η οποία ορθά αναφέρεται στην ανάγκη αποφυγής του «AI theatre» και στην αξιολόγηση της πραγματικής αξίας κάθε εφαρμογής. Ο στόχος του Δημοσίου θα πρέπει να είναι η βελτίωση υπηρεσιών, παραγωγικότητας και αποτελεσμάτων. Σε ορισμένες περιπτώσεις αυτό θα επιτυγχάνεται με ΤΝ, σε άλλες με αυτοματοποίηση, καλύτερη διασύνδεση συστημάτων, επανασχεδιασμό διαδικασιών ή απλούστερες τεχνολογικές λύσεις. 3. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Ενότητες 3.5, 4.4 και 5, υποστήριξη επιχειρηματικής υιοθέτησης της ΤΝ και μηχανισμοί κινήτρων Σχόλιο / Εισήγηση: Προτείνεται η Στρατηγική να ενισχύσει σημαντικά τη διάσταση δημιουργίας επιχειρηματικής ζήτησης για ΤΝ, με τη δημιουργία ενός συστηματικού μηχανισμού που θα βοηθά επιχειρήσεις να μετατρέπουν πραγματικές επιχειρηματικές ανάγκες σε ώριμα και υλοποιήσιμα έργα. Ο μηχανισμός θα μπορούσε να περιλαμβάνει επιδοτούμενες αξιολογήσεις AI και data readiness, χαρτογράφηση διαδικασιών και σημείων συμφόρησης, identification και prioritisation συγκεκριμένων use cases, εκτίμηση οικονομικού οφέλους και κόστους, καθώς και συγχρηματοδότηση της υλοποίησης για τις περιπτώσεις όπου τεκμηριώνεται θετικό business case. Προτείνεται επίσης η δημιουργία sector-specific challenge calls, όπου επιχειρήσεις θα υποβάλλουν πραγματικά επιχειρηματικά προβλήματα και θα υποστηρίζονται στη μετάβασή τους από το πρόβλημα στην εφαρμογή. Αιτιολόγηση σχολίου / Εισήγησης: Η αύξηση της προσφοράς τεχνολογίας, υποδομών, δεξιοτήτων ή χρηματοδοτικών εργαλείων δεν δημιουργεί αυτομάτως αντίστοιχη ζήτηση. Ιδιαίτερα στις ΜΜΕ, το βασικό εμπόδιο συχνά προηγείται της επιλογής τεχνολογίας: η επιχείρηση δεν γνωρίζει ποια προβλήματα αξίζει να αντιμετωπίσει με ΤΝ, ποια δεδομένα απαιτούνται, τι αλλαγές χρειάζονται στις διαδικασίες της ή ποιο θα είναι το οικονομικό αποτέλεσμα. Για να επιτευχθούν οι φιλόδοξοι στόχοι υιοθέτησης της Στρατηγικής χρειάζεται επομένως ένας ενεργός μηχανισμός δημιουργίας και ωρίμανσης της ζήτησης και όχι μόνο ένα οικοσύστημα προσφοράς λύσεων. Η δημόσια στήριξη θα πρέπει να λειτουργεί καταλυτικά ώστε περισσότερες επιχειρήσεις να φθάνουν σε τεκμηριωμένες επενδυτικές αποφάσεις και τελικά σε παραγωγικές εφαρμογές ΤΝ. 4. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Ενότητες 3.5, 3.6, 4.4 και 5, υιοθέτηση ΤΝ από επιχειρήσεις και ΜΜΕ Σχόλιο / Εισήγηση: Προτείνεται η δημιουργία ενός συγκεκριμένου προγράμματος «AI Adoption and Productivity» για κυπριακές επιχειρήσεις και ιδιαίτερα για ΜΜΕ, το οποίο να μην περιορίζεται στη χρηματοδότηση τεχνολογικών λύσεων ή στην κατάρτιση. Το πρόγραμμα θα μπορούσε να περιλαμβάνει δομημένες αξιολογήσεις AI και data readiness, χαρτογράφηση και επανασχεδιασμό διαδικασιών, εντοπισμό και οικονομική αξιολόγηση περιπτώσεων χρήσης, πρόσβαση σε εξειδικευμένη υποστήριξη υλοποίησης, συγχρηματοδότηση εφαρμογών που έχουν τεκμηριωμένη επιχειρηματική αξία και υποχρεωτική μέτρηση των αποτελεσμάτων μετά την εφαρμογή. Αιτιολόγηση σχολίου / Εισήγησης: Για μεγάλο μέρος των κυπριακών επιχειρήσεων, το βασικό εμπόδιο στην αξιοποίηση της ΤΝ δεν είναι η πρόσβαση σε μοντέλα ή υπολογιστική ισχύ. Είναι η ποιότητα και κατακερματισμένη μορφή των δεδομένων, οι μη τυποποιημένες διαδικασίες, τα απομονωμένα πληροφοριακά συστήματα, η περιορισμένη δυνατότητα εντοπισμού κατάλληλων περιπτώσεων χρήσης και η έλλειψη ικανότητας διαχείρισης της οργανωτικής αλλαγής. Εάν η πολιτική περιοριστεί στην προσφορά τεχνολογίας, training ή χρηματοδότησης pilots, υπάρχει κίνδυνος να αυξηθεί ο αριθμός των πειραματικών εφαρμογών χωρίς αντίστοιχη αύξηση παραγωγικότητας. Η επιτυχία της Στρατηγικής θα πρέπει να μετράται κυρίως από την οικονομική αξία που δημιουργείται από την πραγματική παραγωγική χρήση της ΤΝ. 5. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Ενότητες 3.2, 3.5 και 4.4, Data Infrastructure, Supporting SMEs και AI Adoption Enablers Σχόλιο / Εισήγηση: Προτείνεται η έννοια του AI readiness να διευρυνθεί ώστε να περιλαμβάνει ρητά την ετοιμότητα δεδομένων, διαδικασιών και συστημάτων μιας επιχείρησης και οι σχετικές παρεμβάσεις να αποτελούν επιλέξιμες δαπάνες στα προγράμματα στήριξης. Η χρηματοδότηση της υιοθέτησης ΤΝ δεν θα πρέπει να αφορά αποκλειστικά την αγορά ή ανάπτυξη της τελικής εφαρμογής, αλλά και τις απαραίτητες προπαρασκευαστικές παρεμβάσεις, όπως data integration, data quality, interoperability, workflow redesign και διασύνδεση υφιστάμενων συστημάτων. Αιτιολόγηση σχολίου / Εισήγησης: Πολλές αποτυχημένες ή περιορισμένης αξίας εφαρμογές ΤΝ δεν αποτυγχάνουν λόγω της ίδιας της τεχνολογίας, αλλά επειδή επιχειρούν να λειτουργήσουν πάνω σε κατακερματισμένα δεδομένα, μη τυποποιημένες διαδικασίες και ασύνδετα πληροφοριακά συστήματα. Εάν τα χρηματοδοτικά εργαλεία καλύπτουν μόνο το τελευταίο επίπεδο, δηλαδή την εφαρμογή ΤΝ, υπάρχει κίνδυνος να χρηματοδοτούνται τεχνολογικές λύσεις χωρίς τις απαραίτητες προϋποθέσεις για πραγματική αξιοποίηση. Η αντιμετώπιση του data και process readiness ως μέρος της επένδυσης στην ΤΝ θα αυξήσει σημαντικά την πιθανότητα οι επιδοτούμενες εφαρμογές να φθάσουν σε παραγωγική χρήση και να δημιουργήσουν μετρήσιμη αξία. 6. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Ενότητες 3.5, 3.8, 4.4 και Παράρτημα ΣΤ, επιχειρηματική υιοθέτηση, testbeds και δείκτες αποτελεσμάτων Σχόλιο / Εισήγηση: Προτείνεται να θεσπιστεί ένας σαφής μηχανισμός «pilot-to-scale», ώστε οι επιχειρήσεις που ολοκληρώνουν επιτυχώς ένα pilot ή proof of concept να μπορούν να προχωρούν γρήγορα στην παραγωγική εφαρμογή, εφόσον επιτυγχάνονται προκαθορισμένοι δείκτες. Η δεύτερη φάση στήριξης θα μπορούσε να αφορά integration, deployment, change management, monitoring και scaling και να ενεργοποιείται βάσει τεκμηριωμένων αποτελεσμάτων του pilot. Παράλληλα, στους εθνικούς δείκτες θα πρέπει να καταγράφεται όχι μόνο ο αριθμός των pilots, αλλά το ποσοστό που περνά σε production και η οικονομική αξία που δημιουργείται. Αιτιολόγηση σχολίου / Εισήγησης: Ένα από τα μεγαλύτερα προβλήματα διεθνώς στην αξιοποίηση της ΤΝ είναι το χάσμα μεταξύ πειραματισμού και παραγωγικής εφαρμογής. Ένας μεγάλος αριθμός pilots μπορεί να δημιουργεί την εικόνα έντονης δραστηριότητας χωρίς αντίστοιχη οικονομική επίδραση. Η Στρατηγική ορθά αναγνωρίζει τον κίνδυνο του «AI theatre». Συνεπώς, τα χρηματοδοτικά και υποστηρικτικά εργαλεία θα πρέπει να σχεδιαστούν ώστε να επιβραβεύουν τη μετάβαση από experimentation σε measurable business value. Βασικοί δείκτες επιτυχίας θα πρέπει να είναι το pilot-to-production conversion rate, η βελτίωση παραγωγικότητας, η εξοικονόμηση κόστους, η δημιουργία νέων εσόδων και ο χρόνος που απαιτείται για την κλιμάκωση μιας επιτυχημένης εφαρμογής." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",ppsavva@outlook.com,"The Digital Transformation & Fintech Committee of the American Chamber of Commerce in Cyprus (AmCham Cyprus) welcomes the publication of the Cyprus National AI Strategy 2032 and commends the Chief Scientist, the National AI Taskforce, the Deputy Ministry of Research, Innovation and Digital Policy, and all contributing stakeholders for developing a comprehensive and ambitious framework for the future of Artificial Intelligence in Cyprus. The Strategy reflects a clear vision to position Cyprus as a trusted AI hub in the Eastern Mediterranean, a reliable European jurisdiction for AI-enabled services, and a bridge between Europe and neighboring markets. Its focus on innovation, productivity, public sector transformation, skills development, data governance, cybersecurity, ethics, and international cooperation provides a strong foundation for the country's digital future. The Committee is fully supportive of the Strategy's overarching objectives and recognizes the significant effort invested in creating a forward-looking roadmap that aligns with European values, regulatory frameworks, and the opportunities presented by emerging AI technologies. We particularly welcome the emphasis on trustworthy, human-centered AI, the commitment to strengthening Cyprus's competitiveness, and the aspiration to create an ecosystem that fosters innovation, investment, entrepreneurship and talent development.  At the same time, the successful implementation of the Strategy will depend not only on vision but also on execution. The Committee therefore offers the following recommendations in a constructive spirit, with the objective of strengthening the Strategy's practicality, investment attractiveness, governance effectiveness, cybersecurity resilience, and ability to deliver measurable economic and societal outcomes. These recommendations reflect common themes and areas of consensus that emerged during the Committee's discussion and from stakeholder feedback received from businesses, technology providers, professional services organizations and industry experts. We submit these observations with the shared objective of helping Cyprus establish itself as a leading trusted AI Nation, capable of combining strong governance and regulatory certainty with openness, innovation, international collaboration, and sustainable economic growth: 1. Create a National AI Delivery Office The successful implementation of the Strategy will require dedicated execution capacity, not only governance and advisory structures. The Committee recommends establishing a compact, empowered and appropriately resourced National AI Delivery Office responsible for coordinating the national implementation portfolio. The Delivery Office should bring together program management, enterprise architecture, data governance, cybersecurity, procurement, legal and regulatory expertise, change management and benefits realization. It should support ministries and public bodies, coordinate dependencies, maintain visibility across publicly funded AI initiatives, and prevent fragmented or duplicative investments. Its role should be clearly distinguished from that of the authorities responsible for regulatory supervision, market surveillance, data protection, and sector-specific enforcement. Ministries and public bodies should retain accountability for their respective services and outcomes, while the Delivery Office provides central coordination, common implementation standards, and practical delivery support. 2. Add a Funded Delivery Roadmap The Committee recommends complementing the Strategy with a funded, three-year rolling delivery roadmap that translates its ambitions into an executable national program. For every major initiative, the roadmap should define: The accountable owner and participating organizations. The approved budget and funding source. The delivery timeline and key milestones. The procurement and implementation route. Dependencies on data, infrastructure, skills or legislation. Expected economic, operational or societal benefits. Measurable performance indicators. Risk, review and exit criteria. Arrangements for periodic public reporting. The roadmap should reconcile the different adoption targets and implementation dates contained in the Strategy, establish realistic sequencing, and distinguish between immediate priorities, medium-term initiatives and longer-term ambitions. No significant initiative should enter the national AI portfolio without a defined owner, budget, delivery date, and measurable outcome. 3. Strengthen the Data Implementation Layer The Committee considers data readiness to be the most important prerequisite for scaling AI responsibly. The Strategy should therefore strengthen its practical data implementation layer and ensure that data governance progresses before, or in parallel with major technology procurement. The Committee recommends: Assigning an accountable data owner and data steward for every priority public-sector dataset. Establishing minimum standards for data quality, classification, metadata, lineage, retention and lawful use. Creating a national catalogue of high-value datasets that identifies ownership, availability, access conditions and permitted uses. Prioritising secure APIs, common data standards and interoperability over point-to-point integrations. Requiring a formal data-readiness assessment before approving or funding a significant AI project. Developing governed sectoral data spaces and secure testing environments that permit controlled use without unnecessary copying or centralisation. Defining clear rules for confidentiality, intellectual property, anonymisation, pseudonymisation, audit rights and derived data or model outputs. Clarifying lawful cross-border data access and transfer arrangements under applicable European legislation. This implementation layer should be closely aligned with the National Data Policy and the National Data Governance Framework to avoid parallel or inconsistent structures. 4. Prioritise a Limited First Wave The Strategy contains a broad portfolio of sectors, institutions, platforms, funds, centers, sandboxes, and transformational projects. While these ambitions are strategically valuable, attempting to launch too many initiatives simultaneously risks spreading limited funding, leadership attention and specialist expertise too thinly. The Committee recommends selecting a limited first wave of national AI missions based on economic and public value, data readiness, implementation, feasibility, scalability, cybersecurity risk and the potential to create reusable capabilities. The initial portfolio could concentrate on: AI-enabled government and citizen services, particularly high-volume services with repetitive processing, significant document requirements or long response times. AI for regulated financial, fintech and professional services, including AML/KYC, compliance, regulatory reporting, audit support and administrative efficiency. AI for healthcare administration and care navigation, implemented with strong data protection, clinical accountability and human oversight. Other strategic sectors should continue through research, preparation, and controlled experimentation, but the first major funding and implementation cycle should be concentrated on a manageable number of missions. Each first-wave mission should begin with a validated problem, confirmed data readiness, an accountable owner, a funded business case, and measurable success criteria. 5. Make Cybersecurity and Resilience a Foundational Requirement Cybersecurity should be embedded horizontally across the entire AI lifecycle, from data preparation and system design through procurement, deployment, monitoring, material modification, and decommissioning. Every publicly funded, critical or high-impact AI system should pass a proportionate AI Security and Resilience Assessment before entering production. The assessment should address: Data protection and information classification. Identity, privileged access and machine identities. APIs, AI agents and system integrations. Models, training data and AI supply chains. Third-party and supplier risk. Data poisoning, adversarial manipulation and prompt-based attacks. Secure logging, monitoring and auditability. Model performance, drift and misuse detection. Human intervention, override and rollback. Incident reporting and coordinated response. Business continuity, portability and secure exit arrangements. High-impact and critical systems should be subject to independent assurance where appropriate. AI-related incidents should also be integrated into existing national cybersecurity, data-protection, and sector-specific incident-management structures. 6. Support SME Adoption SMEs are central to the Cypriot economy but often lack the specialist expertise, financial capacity and infrastructure required to adopt AI responsibly. The Strategy should therefore include a practical, accessible and proportionate SME AI Adoption Program. The program should provide: AI readiness and data-readiness assessments. Implementation and advisory vouchers. Standard AI policies and governance templates. Risk-classification and impact-assessment tools. Vendor-assessment questionnaires and procurement guidance. Cybersecurity and compliance support. Affordable access to compute, testbeds and sector sandboxes. Access to recognised advisers and implementation partners. Guidance on intellectual property, data use and contractual protections. Market-access and export support for validated AI solutions. Requirements should be proportionate to organizational size, use-case risk and potential impact. Low-risk productivity tools should not be subject to the same burden as high-risk or rights-impacting systems. Public support should be released progressively and linked to measurable results, such as productivity improvement, reduced administrative costs, improved service quality, new revenue, export potential or successful progression from pilot to responsible production use. 7. Develop Role-Based Skills and Professional Capability AI skills policy should extend beyond technical specialists. The Committee recommends role-based education and professional-development pathways for: Executives and board members. Public servants and policymakers. Accountants, auditors and finance professionals. Legal and compliance professionals. Procurement and commercial teams. Data owners and data stewards. Cybersecurity and risk professionals. Educators and trainers. Regulators and assurance professionals. SME leaders and frontline personnel. Training should combine AI literacy with governance, cybersecurity, data protection, responsible use, procurement, change leadership and practical sector applications. Programs should be aligned with labor-market needs, recognized for continuing professional development frameworks, and applied workplace projects. Cyprus should also build local AI governance, cybersecurity, implementation, testing and assurance capabilities that can support domestic adoption and develop into exportable professional services. 8. Measure Outcomes, Not Activities The Strategy’s measurement framework should prioritize economic, operational, citizen and societal outcomes. Each national KPI should have a clearly defined baseline, calculation methodology, accountable owner, data source, reporting frequency, and target trajectory. Priority measures should include: Productivity improvements. Reductions in service-processing times. Reductions in administrative cost and backlog. Improvements in citizen and customer experience. SME adoption and progression to production. Investment attraction and business expansion. Creation of high-skilled employment. Workforce reskilling and transition outcomes. Growth in AI-enabled products and exportable services. System reliability, cybersecurity and compliance. Public trust and responsible-use indicators. The number of pilots, committees, systems purchased, individuals trained or events organized may provide useful supporting information but should not be treated as the principal evidence of success. Underperforming initiatives should be redesigned or discontinued, while successful and reusable capabilities should be scaled across ministries and sectors. 9. Preserve Openness, Investment and Trusted International Partnerships Cyprus’s ambition to develop strategic AI capability should be pursued through openness, interoperability and trusted international cooperation. The Committee recommends defining AI sovereignty and strategic autonomy in terms of effective governance, security, resilience, legal control, portability and strategic choice, rather than domestic ownership, supplier nationality or blanket data localization. Cyprus should retain meaningful control over critical data, services and operational decisions while leveraging trusted European, United States and other international partners to obtain the technology, compute capacity, expertise, investment and access to global markets required to achieve scale. International partnerships should be assessed using objective criteria, including security, transparency, legal enforceability, supply-chain assurance, operational continuity, and alignment with European law and values. The Committee recommends: Ensuring that public procurement, infrastructure access, funding programmes and testing environments apply transparent, proportionate and technology-neutral criteria. Avoiding origin-based preferences or localisation requirements unless objectively justified by applicable law, national security, data sensitivity or demonstrated operational risk. Supporting lawful cross-border data access and transfers under applicable European data-protection legislation. Protecting pre-existing intellectual property, confidential business information, trade secrets and cybersecurity-sensitive technical evidence. Defining clear rights for public-sector data, supplier data, project-created intellectual property, derived outputs and model improvements. Requiring interoperability, data portability, supplier-transition arrangements and tested exit plans to reduce concentration and vendor lock-in. Recognising equivalent international standards, technical evidence and assurance practices where permitted by European law. Creating clear and coordinated pathways for trusted international investors, technology providers, research institutions and implementation partners to establish, test, develop and scale AI-enabled services from Cyprus. Strengthening structured cooperation between Cyprus, the European Union, the United States and other trusted jurisdictions in areas such as research, skills, cybersecurity, standards, testing, investment and responsible AI deployment. Strategic autonomy should provide Cyprus with control, resilience and choice without limiting access to global innovation. A clear and investment-compatible approach will strengthen Cyprus’s position as a trusted European jurisdiction, attract international capital and expertise, support domestic companies and researchers, and enable AI solutions developed or validated in Cyprus to scale into European and neighboring markets. This directly addresses the attached AmCham position paper’s concerns around sovereignty, localization, procurement, cross-border data flows and intellectual property protection.  The Committee values the opportunity to contribute to this important national dialogue and stands ready to support the next phase through continued cooperation among government, industry, academia, professional bodies and civil society." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","CMMI CYPRUS MARINE AND MARITIME INSTITUTE","PUBLIC CONSULTATION SUBMISSION Priority Comments on the Cyprus National AI Strategy 2032 A Centre-of-Excellence and maritime perspective Submitted by: CMMI Cyprus Marine and Maritime Institute Submitted to: Deputy Ministry of Research, Innovation and Digital Policy Consultation: National AI Strategy – public consultation Date: 31 August 2026 Scope: The submission supports the Strategy’s overall vision and concentrates on the few amendments most likely to convert Cyprus’s maritime and Centre-of-Excellence strengths into safe, investable and publicly valuable AI capability. __________________________________________________________________________ COMMENT 1: Make marine autonomy a first-wave European flagship Article and paragraph to which the comment refers: Section 3.8.5, “National Testbeds” (paragraphs beginning “The Cyprus AI Strategy calls…” and “These testbeds will…”); Chapter 5, item 4, “Accelerating Adoption and Industry Readiness” (bullet “Development of an Autonomous Systems Park”); Annex C, “Shipping and Maritime” → “Flagship programme(s)” (paragraph beginning “A national Maritime AI programme…”); Annex D, “Focus Area 2: Autonomous Systems”. Comment / Suggestion: Marine autonomy should be included in the initial national testbed programme. The Strategy should establish a named flagship: a European Centre for Testing, Validation and Assurance of Marine Autonomous Systems in Cyprus. CMMI proposes to develop and operate this facility under a national mandate and joint governance with the competent authorities, the Shipping Deputy Ministry, industry, universities and research organisations. The Centre should provide an open pathway from simulation and digital twins through software- and hardware-in-the-loop testing to supervised harbour, coastal and open-water trials. Its scope should cover surface and underwater vessels, supporting aerial systems, multi-vehicle coordination, remote operations, communications and navigation degradation, cyber-resilience, human supervisory control and environmental performance. It should produce repeatable test protocols, validated datasets, safety-case support and evidence suitable for regulatory, classification and conformity-assessment review. Development, independent validation and formal certification functions must remain clearly separated. CMMI should be tasked to coordinate the preparatory feasibility study, business plan and European partnership model, with investment conditional on open access, competent-authority participation, independent governance and measurable public and economic outcomes. Justification: The Strategy already contains the necessary components—an Autonomous Systems Park, national testbeds, an EU shipping and maritime testbed, a regulatory sandbox and autonomous-systems research—but leaves them dispersed and postpones maritime participation. Cyprus can build rapidly on complementary CMMI assets and investments: MARIC expertise in heterogeneous marine robotics, CyMON mission-control and marine-data capabilities, MDigi-I testbeds and laboratories, the MARTA concept, expanded laboratory capacity and the demonstrated EONIOS autonomy concept. Federating these assets would reduce duplication and create a durable European-facing capability for safer shipping, port operations, search and rescue, pollution monitoring, environmental protection, emergency response and critical-infrastructure inspection. Supporting evidence: CMMI MARIC (https://www.cmmi.blue/marine-autonomous-robotic-intelligent-systems-centre/) | CyMON (https://www.cmmi.blue/the-cyprus-marine-observation-network/) | MDigi-I (https://www.cmmi.blue/mdigi-i/) | EONIOS (https://www.cmmi.blue/eonios-unoc3/) __________________________________________________________________________ COMMENT 2: Use a federated Centre-of-Excellence delivery model Article and paragraph to which the comment refers: Section 1.2, paragraph beginning “To support the objectives, it is imperative to build world-class Centres of Excellence”; Section 3.3.1, “Governance Structure”, including “National AI Industrial Centre of Excellence”; Section 4.2.1, “AI Infrastructure Enablers”; Chapter 5, item 3, “Setting Up the Innovation Infrastructure”. Comment / Suggestion: The Strategy should define a federated, mission-oriented national network of Centres of Excellence before creating additional institutions. The National AI Authority should set portfolio priorities and common governance; the proposed Industrial AI Centre of Excellence should provide horizontal AI engineering, compliance blueprints and reusable architectures; and designated existing thematic Centres should lead sector missions, data spaces and testbeds under transparent performance agreements. The model should specify mandates, decision rights, infrastructure access, procurement roles, funding, intellectual-property and data rules, conflict-of-interest controls and outcome accountability. Mission leadership should be assigned through capability-based partnerships involving domain Centres, competent authorities, industry and universities. For maritime missions, CMMI proposes to serve as the thematic delivery node, subject to national governance, open participation and performance review. The final Strategy should also use one consistent name and mandate for the “Industrial Centre of Excellence”, “National AI Industrial Centre of Excellence” and “AI Industrial Centre of Excellence”, and clarify its interface with sector-specific Centres. Justification: The draft correctly recognises world-class Centres of Excellence as a national capability, but does not formally position existing thematic Centres as delivery assets and assigns overlapping functions to several proposed bodies. This creates a material risk of duplicating laboratories, scarce specialist teams and public investment. A federated model combines national consistency with the domain knowledge required for safe deployment in regulated sectors. It would mobilise mature infrastructure and industry networks faster, preserve accountability and avoid implying an exclusive entitlement to future funding. It also reflects the Strategy’s own principles of shared services, interoperability and reduced fragmentation. Supporting evidence: CMMI institutional profile (https://www.cmmi.blue/who-we-are/) | European CoE cooperation (https://www.cmmi.blue/signature-of-a-memorandum-of-understanding-mou-between-centres-of-excellence-cmmi-coe-marble-inesctec-ocean/) __________________________________________________________________________ COMMENT 3: Fund infrastructure through mature, stage-gated business plans Article and paragraph to which the comment refers: Section 3.3, “Governance and Controls” → “Roles, Accountability and Decision-making” (paragraph on budget allocations); Section 3.7.2, “Compute Capacity and Access”; Section 3.10.3, “Funding and Renewal Model”; Section 3.11.4, “Learning and Continuous Development”; Chapter 5, items 2–4 on funding, innovation infrastructure and industry readiness. Comment / Suggestion: Add an Investment and Sustainability Framework governing allocations across the Strategy’s six research focus areas, sector missions, data spaces and enabling infrastructure. Begin with a national map of assets, capabilities, utilisation and gaps; prioritise the upgrade or federation of existing assets where this offers better value than parallel facilities. Every material infrastructure or Centre-of-Excellence proposal should require an independently reviewed, phased business and implementation plan covering demonstrated demand; beneficiaries and public value; relationship to existing assets; capital and multi-year operating costs; total cost of ownership and renewal; staffing; governance and open-access model; pricing and cost recovery; liability and insurance; cybersecurity and environmental impact; procurement, State-aid and regulatory compliance; European and private co-financing; milestones, KPIs and go/no-go, consolidation or decommissioning criteria. Create a preparatory funding window for feasibility studies and mature business plans, together with a dedicated investment line for shared sectoral testing, validation and assurance infrastructure. Funding must cover safe operation, maintenance, data stewardship and affordable SME and public-authority access—not equipment acquisition alone. Justification: The Strategy identifies several funds and facilities but does not define a common method for comparing investments or financing their full lifecycle. Testbeds are service infrastructures: without predictable operating resources, specialist staff and renewal, capital expenditure can produce underused or stranded assets. A stage-gated portfolio approach would improve value for money, make resource allocation transparent and allow underperforming initiatives to be adapted or stopped. It would also enable CMMI to mature one integrated maritime investment case around CyMON, the MARTA concept, MDigi-I, EONIOS and expanded laboratories for the forthcoming DMRIDP Investment Pillar, while exposing the proposal to the same objective tests as every other national investment. Supporting evidence: MDigi-I infrastructure (https://www.mdigii.eu/the-project) | CMMI research-infrastructure access (https://www.cmmi.blue/cmmi-research-infrastructure-access/) __________________________________________________________________________ COMMENT 4: Operationalise the Trusted Maritime Data Space Article and paragraph to which the comment refers: Sections 3.2.1, “Strategic Role of Data”, 3.2.3, “Interoperability and Secure Data Sharing”, and 3.2.5, “Capability and Infrastructure” (including “National Intelligent Digital API Fabric”); Annex C, “Shipping and Maritime” → “Implementation, evidence and compliance” (paragraph beginning “To enable these capabilities…”) and “Flagship programme(s)”. Comment / Suggestion: Convert the commitment to a Trusted Maritime Data Space into an implementation specification for a federated, standards-based and European-interoperable maritime data ecosystem. The Strategy should define the accountable authority and operator or trustee; stakeholder governance; participation incentives and decision rights; data licences and permitted uses; commercial confidentiality and intellectual-property safeguards; provenance, quality and common metadata; secure APIs; role-based access, retention, audit and withdrawal rules; and cybersecurity controls. The design should support secure processing environments, federated analytics and learning, synthetic data and other privacy-preserving approaches where anonymisation or central pooling is unsuitable. It should connect with the National Intelligent Digital API Fabric and relevant European data initiatives. Priority datasets should support vessels, ports, maintenance, inspection, trials, metocean conditions, emissions, incidents, safety, pollution response and marine environmental monitoring. Non-sensitive results of publicly funded trials should be reusable for research and public-interest purposes. Justification: Maritime operational data are distributed among ships, companies, ports, public authorities and research infrastructures; they are often commercially sensitive, safety-critical and difficult to anonymise without losing utility. The current formulation—company contributions of anonymised datasets for national model training—is therefore too narrow and may not earn industry trust. A governed federated model would allow algorithms to learn from protected data without requiring organisations to surrender commercial know-how. It would also provide SMEs, authorities and researchers with trusted reference data for digital twins, maintenance, routing, regulatory support and autonomous-system validation. CyMON’s data architecture and EMODnet relationship, together with MDigi-I, provide practical seed capabilities. Supporting evidence: CyMON and EMODnet (https://www.cmmi.blue/cmmi-becomes-an-associated-member-of-the-european-marine-observation-and-data-network/) | MDigi-I Hub (https://www.mdigii.eu/) __________________________________________________________________________ COMMENT 5: Add marine public-interest and environmental missions Article and paragraph to which the comment refers: Section 3.5, priority sector 7, “Shipping and Maritime”; Annex C, “Shipping and Maritime”; Annex D, “Focus Area 1: Energy, Environment and Resource Management”, “Focus Area 2: Autonomous Systems”, and “Focus Area 4: Security, Defence and Space”. Comment / Suggestion: Expand the Shipping and Maritime pillar beyond fleet and ship-management productivity to include marine and blue-economy missions of direct public value. Add explicit priorities for maritime situational awareness and search and rescue; oil-spill, chemical-pollution, illegal-discharge and marine-litter detection, forecasting and response; navigational and port safety; inspection of coastal and subsea critical infrastructure; marine ecosystem, biodiversity and climate monitoring; sustainable aquaculture; and support for emergency-response authorities. Add to Annex D, Focus Area 1: “AI-enabled marine and coastal environmental monitoring, including detection, forecasting, source attribution and response support for pollution and ecosystem stress, integrating Earth observation, airborne platforms, fixed and mobile sensors, autonomous surface and underwater systems, and digital twins.” Where missions are dual-use, require proportionality, human command authority, access and data-classification controls, auditability, cyber-adversarial testing, applicable export controls, fundamental-rights safeguards and protection of the marine environment. Justification: The current maritime pillar concentrates mainly on fuel efficiency, predictive maintenance, compliance and logistics. For an island state, maritime AI also affects human life, environmental protection, food systems, coastal communities and national resilience. The environmental research priorities list wildfire, air, water scarcity, grids and buildings but omit the marine environment. This addition would link Research Focus Areas 1, 2 and 4, create shared civil-security uses for expensive sensing and validation infrastructure, and ensure visible public benefit. It can build on the Shipping Deputy Ministry’s pollution-monitoring direction and CMMI capabilities including CyMON, MDigi-I, iMERMAID and the EONIOS demonstrated concept. Supporting evidence: CMMI iMERMAID pollution monitoring (https://www.cmmi.blue/imermaid/) | CMMI marine observation (https://www.cmmi.blue/the-cyprus-marine-observation-network/) __________________________________________________________________________ COMMENT 6: Create a domain-specific marine autonomy assurance framework Article and paragraph to which the comment refers: Section 3.3.2, “Control Framework”; Annex B, “AI Use Case Lifecycle and Control Gates”; Section 4.3, “AI Governance Enablers” → “National AI Compliance Framework”; Annex C, “Shipping and Maritime” → “International alignment” and “Flagship programme(s)”; Annex D, Focus Areas 2 and 4; Section 3.11.2, paragraph referring to ISO 42001 and ISO 27001. Comment / Suggestion: Develop a Marine Autonomous Systems Assurance Framework under the National AI Compliance Framework and testbed programme. It should define operational design domains, scenario libraries, performance measures and acceptance criteria; safety-case templates; human supervisory control, intervention and abort mechanisms; collision-avoidance behaviour; operation under communications, navigation and sensor degradation; perception uncertainty; cyberattack resilience; multi-agent and swarm behaviour; logging, traceability and incident reporting; and environmental effects. The framework should layer the EU AI Act where applicable with maritime safety, security, environmental and operational law and standards. It should be co-designed with competent maritime, port, AI, cybersecurity, data-protection, defence and emergency authorities, together with classification and standards bodies, insurers, operators, research organisations and Centres of Excellence. Reusable evidence packages should support procurement, trial authorisation, regulatory review, classification, insurance and cross-border trials. Clarify that ISO 42001 and ISO 27001 can support governance and security evidence but do not, by themselves, establish compliance with the EU AI Act or maritime-sector legislation. Justification: Marine autonomous systems are cyber-physical systems operating in variable, safety-critical environments and across overlapping legal regimes. General AI control gates or a regulatory sandbox cannot alone demonstrate safe navigation, resilient remote operations, adequate human control or acceptable environmental performance. The timing is strategic: the IMO adopted the non-mandatory MASS Code in May 2026, effective from 1 July 2026, and plans an experience-building phase on the route to a mandatory code expected to enter into force in 2032. A Cyprus assurance and test programme could generate credible evidence during that transition, reducing uncertainty for regulators, developers, operators and insurers while distinguishing Cyprus as a trusted European validation location. Supporting evidence: IMO MASS Code, 22 May 2026 (https://www.imo.org/en/mediacentre/pressbriefings/pages/imo-adopts-mass-code.aspx) | EU AI Act (https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng) __________________________________________________________________________ COMMENT 7: Set credible maritime KPIs and correct material inconsistencies Article and paragraph to which the comment refers: Section 3.11, “Measuring Impact and National KPIs”; Annex C, “Shipping and Maritime” → “Strategic objectives and 2032 target”, “Shipping and Maritime Pillar – What this pillar is expected to deliver”, and Figure 11; Annex F, “National KPIs and Measurement Framework”. Comment / Suggestion: Replace or qualify promotional superlatives and aggregate savings estimates with baseline-defined, independently verifiable outcomes. By 2027, establish for each maritime KPI a baseline, scope, data source, method, accountable owner, target, reporting frequency and independent evaluation route. Report results by use case and user group rather than implying uniform sector-wide effects. The maritime scorecard should cover verified fuel, emissions, downtime and maintenance outcomes; safety incidents and near-misses; systems and scenarios independently tested; authorised trial hours; time and cost to produce validation evidence; progression from testing to supervised trial, deployment or export; SME, research and public-authority access; use of datasets and shared services; specialised personnel trained; EU and private co-investment; and public-interest outcomes such as pollution alerts, search-and-rescue support and environmental coverage. Before final adoption, align the maritime text and figures: reconcile the 2032 target with Figure 11’s 2035 date; repair the interrupted “Strategic objectives” paragraph and remove the unrelated sentence on personalisation and citizen experience; standardise Centre-of-Excellence and Infrastructure Council/Committee names; and replace tertiary sources with primary official data where available. Justification: The Strategy’s outcomes-focused approach is sound, but its maritime annex presents 10–20% fuel savings and 30–40% maintenance-cost reductions without defining baselines, attribution or verification. It also describes a 2032 ambition while Figure 11 states 2035. These weaknesses can misdirect investment and undermine confidence in otherwise valuable priorities. A transparent scorecard would connect public funding to accessibility, safety, environmental and economic outcomes, not merely pilot counts. Correcting the visible textual and institutional inconsistencies would improve legal and operational clarity and strengthen the Strategy’s credibility with industry, European partners and citizens." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",CCCI,"Παρατηρήσεις του ΚΕΒΕ επί της Προτεινόμενης Εθνικής Στρατηγικής για την Τεχνητή Νοημοσύνη Το ΚΕΒΕ θεωρεί ότι το προτεινόμενο Σχέδιο Δράσης για την Τεχνητή Νοημοσύνη είναι ιδιαίτερα φιλόδοξο και αντανακλά τη δέσμευση για την προώθηση του ψηφιακού μετασχηματισμού της κυπριακής οικονομίας. Ωστόσο, θεωρούμε ότι ορισμένα σημαντικά ζητήματα χρήζουν περαιτέρω ανάλυσης και διευκρίνισης, προκειμένου να διασφαλιστεί η αποτελεσματική και χωρίς αποκλεισμούς υλοποίηση της στρατηγικής. Καταρχάς, θα ήταν χρήσιμο να εξεταστεί η εντονότερη ανάδειξη και ενσωμάτωση των τομέων του εμπορίου και της ενέργειας, οι οποίοι αναμένεται να επηρεαστούν άμεσα και ουσιαστικά από την εφαρμογή τεχνολογιών τεχνητής νοημοσύνης. Δεδομένης της σημασίας των συγκεκριμένων τομέων για την κυπριακή οικονομία, κρίνεται αναγκαία η σαφέστερη ενσωμάτωσή τους στο πλαίσιο του Σχεδίου Δράσης. Παράλληλα, παρότι γίνεται αναφορά στις μικρομεσαίες επιχειρήσεις (ΜμΕ), δεν λαμβάνονται επαρκώς υπόψη οι ιδιαίτερες ανάγκες των πολύ μικρών επιχειρήσεων (micro-enterprises), οι οποίες αποτελούν τη συντριπτική πλειονότητα των επιχειρήσεων στην Κύπρο. Οι επιχειρήσεις αυτές αντιμετωπίζουν διαφορετικές προκλήσεις σε σχέση με τις μεγαλύτερες ΜμΕ και, ως εκ τούτου, απαιτούν στοχευμένα μέτρα και εξατομικευμένη υποστήριξη για την υιοθέτηση και αξιοποίηση των εφαρμογών τεχνητής νοημοσύνης. Επιπρόσθετα, θα ήταν χρήσιμο να παρουσιαστούν με μεγαλύτερη σαφήνεια τα βήματα που προβλέπονται για την ανάπτυξη των απαραίτητων υποδομών που θα στηρίξουν την εφαρμογή του Σχεδίου. Θα ήταν χρήσιμο να παρουσιαστούν με μεγαλύτερη σαφήνεια το χρονοδιάγραμμα, οι προβλεπόμενες επενδύσεις και η πρακτική υλοποίηση των σχετικών δράσεων. Παρόλο που γίνεται αναφορά σε εθνικές υποδομές AI και υπολογιστικής ισχύος, θα ήταν χρήσιμο να παρουσιαστούν πιο συγκεκριμένες πληροφορίες για τη χωρητικότητα, το χρονοδιάγραμμα και την επάρκεια των υποδομών που θα απαιτηθούν. Παράλληλα, θα ήταν χρήσιμο να παρουσιαστούν εκτιμήσεις σχετικά με τις απαιτούμενες δυνατότητες και τη χωρητικότητα των εν λόγω υποδομών, καθώς και αξιολόγηση του κατά πόσο οι υφιστάμενες υποδομές της χώρας μπορούν να ανταποκριθούν στις ανάγκες που αναμένεται να προκύψουν από την υλοποίηση του Σχεδίου. Το ΚΕΒΕ θεωρεί ιδιαίτερα σημαντικό να διασφαλιστεί η ουσιαστική συμμετοχή των αντιπροσωπευτικών φορέων της επιχειρηματικής κοινότητας και ιδιαίτερα των οργανισμών που εκπροσωπούν τις ΜμΕ στις προτεινόμενες δομές διακυβέρνησης, παρακολούθησης και αξιολόγησης της Στρατηγικής, ώστε να διασφαλίζεται η συστηματική μεταφορά της εμπειρίας και των αναγκών της αγοράς κατά την εφαρμογή και αξιολόγησή της. Επιπρόσθετα, θεωρούμε ότι θα ήταν χρήσιμο να παρουσιαστεί με μεγαλύτερη σαφήνεια η τεκμηρίωση και η μεθοδολογία βάσει των οποίων καθορίστηκαν οι ποσοτικοί στόχοι και οι βασικές κατευθύνσεις της Στρατηγικής. Παρόλο που γίνεται αναφορά σε διεθνείς και ευρωπαϊκούς δείκτες, θα ήταν χρήσιμο να παρουσιαστεί συνοπτικά η τεκμηρίωση, οι παραδοχές και τα δεδομένα που λήφθηκαν υπόψη κατά τον καθορισμό των ποσοτικών στόχων, καθώς και η ανάλυση που αποτυπώνει την υφιστάμενη κατάσταση, τον βαθμό ετοιμότητας και τις πραγματικές ανάγκες των κυπριακών επιχειρήσεων και της οικονομίας γενικότερα. Η διευκρίνιση των στοιχείων, των παραδοχών και της μεθοδολογίας που οδήγησαν στον καθορισμό ιδιαίτερα φιλόδοξων στόχων, όπως η ευρεία υιοθέτηση της Τεχνητής Νοημοσύνης σε επιλεγμένους τομείς, η σημαντική αύξηση της παραγωγικότητας και η ανάπτυξη χιλιάδων επαγγελματιών Τεχνητής Νοημοσύνης, θα ενίσχυε την αξιοπιστία, τη διαφάνεια και την πρακτική εφαρμοσιμότητα της Στρατηγικής, ενώ θα διευκόλυνε και την αξιολόγηση της προόδου κατά την υλοποίησή της. Το ΚΕΒΕ χαιρετίζει την πρόβλεψη συνεργατικών μηχανισμών και τη σαφή αναγνώριση της σημασίας της συμμετοχής της βιομηχανίας, των επιχειρήσεων και των ΜμΕ στην υλοποίηση της Εθνικής Στρατηγικής Τεχνητής Νοημοσύνης. Εντούτοις, θεωρεί ότι η συμμετοχή των αντιπροσωπευτικών επιχειρηματικών φορέων θα μπορούσε να ενισχυθεί περαιτέρω και να αποκτήσει σαφέστερο θεσμικό και λειτουργικό ρόλο στο πλαίσιο εφαρμογής της Στρατηγικής. Προς τούτο, εισηγούμαστε τη θεσμοθέτηση μόνιμων μηχανισμών διαβούλευσης και συμμετοχής των επιχειρηματικών φορέων στα αρμόδια συμβουλευτικά και συντονιστικά όργανα της Στρατηγικής, ώστε να αξιοποιείται συστηματικά η εμπειρία της αγοράς, να αναδεικνύονται έγκαιρα οι ανάγκες των επιχειρήσεων και να ενισχύεται η αποτελεσματικότητα των σχετικών δράσεων. Παράλληλα, θα πρέπει να διασφαλιστεί η ενεργός συμμετοχή των επιχειρηματικών φορέων στη διαμόρφωση των προγραμμάτων στήριξης και κατάρτισης, καθώς και στον σχεδιασμό, την υποστήριξη και την υλοποίηση δράσεων ενημέρωσης, ευαισθητοποίησης και υποστήριξης των ΜμΕ. Επιπρόσθετα, θα ήταν χρήσιμο να εξεταστεί η δυνατότητα αξιοποίησης των οργανωμένων επιχειρηματικών φορέων ως ενδιάμεσων οργανισμών διάχυσης γνώσης, κατάρτισης και υποστήριξης των ΜμΕ, μέσω κατάλληλων συνεργατικών σχημάτων, προγραμμάτων στήριξης ή άλλων μηχανισμών που θα διευκολύνουν την αποτελεσματική μεταφορά γνώσης και τεχνογνωσίας προς τις επιχειρήσεις. Οι φορείς αυτοί μπορούν να λειτουργήσουν ως κρίσιμος σύνδεσμος μεταξύ κράτους και επιχειρήσεων για την προώθηση της υιοθέτησης της Τεχνητής Νοημοσύνης, ιδιαίτερα από τις ΜμΕ. Δεδομένου ότι η επιτυχία της Στρατηγικής θα εξαρτηθεί σε μεγάλο βαθμό από τον βαθμό υιοθέτησης της Τεχνητής Νοημοσύνης από τις επιχειρήσεις και ιδιαίτερα τις ΜμΕ, θεωρούμε σημαντικό η επιχειρηματική κοινότητα να αποτελεί ενεργό εταίρο τόσο στον σχεδιασμό όσο και στην υλοποίηση των σχετικών δράσεων. Επιπρόσθετα, θεωρούμε ότι η Στρατηγική θα ενισχυόταν περαιτέρω εάν συνοδευόταν από ένα ενδεικτικό χρηματοδοτικό πλάνο, το οποίο να παρουσιάζει το εκτιμώμενο κόστος υλοποίησης των βασικών δράσεων, τις πιθανές πηγές χρηματοδότησης και την ενδεικτική κατανομή πόρων ανά πυλώνα παρέμβασης. Η ύπαρξη ενός τέτοιου πλαισίου θα συνέβαλλε στην καλύτερη αξιολόγηση της εφικτότητας των προτεινόμενων μέτρων και των ιδιαίτερα φιλόδοξων στόχων της Στρατηγικής, καθώς και στην αποτελεσματικότερη παρακολούθηση της υλοποίησής της. Τέλος, ενώ η Στρατηγική περιλαμβάνει συγκεκριμένους και φιλόδοξους ποσοτικούς στόχους αναφορικά με την υιοθέτηση της Τεχνητής Νοημοσύνης, την παραγωγικότητα, την ανάπτυξη δεξιοτήτων και την κατάρτιση του ανθρώπινου δυναμικού, θα μπορούσε να εξεταστεί η συμπερίληψη πρόσθετων δεικτών που να αποτυπώνουν τον βαθμό συνεργασίας μεταξύ δημόσιου και ιδιωτικού τομέα στο πλαίσιο εφαρμογής της Στρατηγικής. Ενδεικτικά, οι δείκτες αυτοί θα μπορούσαν να αφορούν τον αριθμό θεσμοθετημένων διαβουλεύσεων με την επιχειρηματική κοινότητα, τη συμμετοχή φορέων της αγοράς σε δράσεις υλοποίησης της Στρατηγικής, τον αριθμό επιχειρήσεων που προσεγγίζονται μέσω οργανωμένων δικτύων υποστήριξης και την αξιοποίηση συνεργατικών μηχανισμών για τη στήριξη των ΜμΕ. Συνοπτικά, το ΚΕΒΕ υποστηρίζει τους στόχους του προτεινόμενου Σχεδίου Δράσης για την Τεχνητή Νοημοσύνη. Ωστόσο, θεωρεί ότι απαιτείται μεγαλύτερη έμφαση στις ανάγκες των πολύ μικρών επιχειρήσεων, στους τομεακούς αντίκτυπους, στις απαραίτητες υποδομές, στη συμμετοχή των βασικών ενδιαφερόμενων μερών και στην τεκμηριωμένη διακυβέρνηση, ώστε να διασφαλιστεί η επιτυχής εφαρμογή και η μακροπρόθεσμη αποτελεσματικότητα της στρατηγικής. CCCI Comments on the Proposed National Artificial Intelligence Strategy The CCCI considers that the proposed Artificial Intelligence Action Plan is highly ambitious and reflects a strong commitment to advancing the digital transformation of the Cypriot economy. However, we believe that certain important issues warrant further analysis and clarification in order to ensure the effective and inclusive implementation of the Strategy. First, it would be beneficial to consider a stronger emphasis on and integration of the trade and energy sectors, which are expected to be directly and substantially affected by the deployment of artificial intelligence technologies. Given the importance of these sectors to the Cypriot economy, their clearer incorporation into the Action Plan is considered necessary. At the same time, although the Strategy refers to small and medium-sized enterprises (SMEs), it does not sufficiently address the specific needs of micro-enterprises, which constitute the overwhelming majority of businesses in Cyprus. These enterprises face challenges that differ from those of larger SMEs and therefore require targeted measures and tailored support to facilitate the adoption and effective use of artificial intelligence applications. Furthermore, it would be useful to provide greater clarity regarding the steps foreseen for the development of the infrastructure necessary to support the implementation of the Strategy. Additional information on the timeline, expected investments, and practical implementation of the relevant actions would be beneficial. While reference is made to national AI infrastructure and computing capacity, more specific information regarding the capacity, timeline and adequacy of the required infrastructure would be valuable. In addition, it would be useful to provide estimates concerning the required capabilities and capacity of such infrastructure, as well as an assessment of whether the country's existing infrastructure will be able to meet the demands expected to arise from the implementation of the Strategy. CCCI considers it particularly important to ensure the meaningful participation of representative business organisations, especially those representing SMEs, in the proposed governance, monitoring and evaluation structures of the Strategy, so as to facilitate the systematic transfer of market knowledge and business needs throughout its implementation and evaluation. In addition, we believe that greater clarity should be provided regarding the evidence base and methodology used in determining the quantitative targets and overall direction of the Strategy. Although reference is made to international and European indicators, it would be helpful to present, in summary form, the evidence, assumptions and data considered when establishing the quantitative targets, as well as the analysis reflecting the current situation, the level of preparedness and the actual needs of Cypriot businesses and the economy more broadly. Clarifying the evidence, assumptions and methodology underpinning highly ambitious targets, such as the widespread adoption of Artificial Intelligence across selected sectors, significant productivity gains and the development of thousands of AI professionals, would further strengthen the credibility, transparency and practical applicability of the Strategy, while also facilitating the monitoring and evaluation of progress during its implementation. CCCI welcomes the inclusion of collaborative mechanisms and the clear recognition of the importance of involving industry, businesses and SMEs in the implementation of the National Artificial Intelligence Strategy. Nevertheless, we believe that the participation of representative business organisations could be further strengthened and provided with a clearer institutional and operational role within the implementation framework of the Strategy. To this end, we propose the establishment of permanent consultation and participation mechanisms for business organisations within the relevant advisory and coordination bodies of the Strategy, so that market expertise can be systematically utilised, business needs identified at an early stage, and the effectiveness of the relevant initiatives enhanced. At the same time, the active involvement of business organisations should be ensured in the design of support and training programmes, as well as in the planning, support and implementation of awareness-raising, outreach and SME support initiatives. Furthermore, consideration could be given to leveraging organised business organisations as intermediary bodies for the dissemination of knowledge, training and support to SMEs through appropriate collaborative schemes, support programmes or other mechanisms that facilitate the effective transfer of know-how and expertise to businesses. Such organisations can serve as a critical link between government and the business community in promoting the adoption of Artificial Intelligence, particularly among SMEs. Given that the success of the Strategy will largely depend on the degree of AI adoption by businesses, and SMEs in particular, we consider it important for the business community to be an active partner both in the design and implementation of the relevant actions. In addition, we believe that the Strategy would be further strengthened if it were accompanied by an indicative financing plan outlining the estimated implementation costs of the key actions, potential sources of funding, and an indicative allocation of resources across the various pillars of intervention. Such a framework would contribute to a more informed assessment of the feasibility of the proposed measures and ambitious targets, while also supporting more effective monitoring of implementation. Finally, while the Strategy includes specific and ambitious quantitative targets regarding AI adoption, productivity, skills development and workforce training, consideration could be given to the inclusion of additional indicators that capture the level of cooperation between the public and private sectors in the implementation of the Strategy. Indicative indicators could include the number of institutionalized consultations with the business community, the participation of market stakeholders in implementation activities, the number of businesses reached through organised support networks, and the use of collaborative mechanisms aimed at supporting SMEs. In conclusion, CCCI supports the objectives of the proposed Artificial Intelligence Action Plan. However, we believe that greater emphasis should be placed on the needs of micro-enterprises, sector-specific impacts, the required infrastructure, stakeholder participation and evidence-based governance, in order to ensure the successful implementation and long-term effectiveness of the Strategy." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Anthi Chatzikyriakou",. "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Vasso Kriticou","ΣΑΙΕΕΚ Ο ΣΑΙΕΕΚ είναι Σωματείο Αντιπροσώπων Ιατρικού και Επιστημονικού Εξοπλισμού Κύπρου, ιδρύθηκε το 1999 και περιλαμβάνει 50 και πλέον εταιρείες μέλη, που ασχολούνται με τους τομείς Ιατροτεχνολογικού, Αναλυτικού και Life Science εξοπλισμού και αναλωσίμων, εξυπηρετώντας τα Δημόσια και Ιδιωτικά Νοσηλευτήρια, Πανεπιστήμια, Ερευνητικά Κέντρα κλπ. Πριν την κατάθεση των σχολίων μας, θα θέλαμε να συγχαρούμε την Εθνική Ομάδα Εργασίας για την Τεχνητή Νοημοσύνη και τον Επικεφαλής Επιστήμονα για την Έρευνα, την Καινοτομία και την Τεχνολογία για ένα εκτεταμένο και τεκμηριωμένο προσχέδιο Στρατηγικής, για το χρόνο που διέθεσαν να επικοινωνήσουν το όραμα και τη Στρατηγική και για την προθυμία τους να δηλώσουν τους περιορισμούς και τις φιλοδοξίες τους. Τα χαρακτηριστικά που μας κέντρισαν την προσοχή και είναι ιδιαίτερα ευπρόσδεκτα είναι: 1. Human-Centric AI & Citizen Empowerment (""Technology for Citizens"") 2. Public Sector Modernization & Smart Governance 3. Research, Innovation & Commercial Ecosystem Development 4. Data Ecosystem, Infrastructure & Connectivity 5. Talent Acquisition & Workforce Transformation Όντας εταιρείες που ασχολούμαστε με την Υγεία χαιρετίζουμε ότι θα υπάρξει Εθνική Στρατηγική για την ΤΝ, που ήδη εφαρμόζεται σε συστήματα νέας τεχνολογίας σε ευρή φάσμα της Ιατρικής. Στο σημείο αυτό θα πρέπει να τονιστεί ότι είναι αναγκαία η επιβολή τέτοιων συστημάτων, που μπορούν να επιταχύνουν τη διάγνωση των ασθενών και να κερδηθεί χρόνος και χρήματα στο σύστημα, διότι πρόωρη διάγνωση σημαίνει αποτελεσματικότερη και πιο σύντομη θεραπεία. Το κόστος αυτών των νέων τεχνολογιών μπορεί να φαίνεται αρχικά υψηλό, όμως αν συνυπολογιστούν τα οφέλη και η αποσυμφόρηση του ΓΕΣΥ είναι απόλυτα διαχειρίσιμο. Σχόλιο 1: 1.5 Implementation Timeline and Success Metrics Το χρονοδιάγραμμα όπως παρατίθεται είναι ιδιαίτερα φιλόδοξο, όταν προϋποθέτει εμπλοκή δημόσιων φορέων/δημόσιων λειτουργών κλπ. Εισήγηση 1: Για να επιτευχθούν οι στόχοι εντός τόσο απαιτητικού χρονοδιαγράμματος, θα πρέπει να υπάρχει απόλυτος συντονισμός, πολιτική βούληση και επίβλεψη των στόχων σε Παγκύπριο επίπεδο. Αυτή τη στιγμή, όσον αφορά τον τομέα της Υγείας και συγκεκριμένα στα προϊόντα καταλόγου ΖC που χειρίζεται ο ΟΑΥ, υπάρχει καθυστέρηση εγκρίσεων νέων τεχνολογιών με ΤΝ ως και 5 χρόνια για ένταξη στο ΓΕΣΥ. Πως θα μπορούσε με διαφάνεια να βελτιωθεί η κατάσταση; Σχόλιο 2: Healthcare and Life Sciences, p75 Η ΤΝ στον ιατρικό χώρο εμπίπτει σε αυστηρές νομοθεσίες και κανονισμούς (π.χ. Medical Device Regulation 2017/45)αλλά πρέπει να λαμβάνει υπόψη το ΕU AI Act και την επικείμενη ψήφιση του περί Τεχνητής Νοημοσύνης Νόμο του 2026. Εισήγηση 2: Δημιουργία σαφών και διαφανών, fast-track διαδικασιών έγκρισης/ενσωμάτωσης στο σύστημα υγείας λογισμικών (από εταιρείες του εξωτερικού) και τεχνολογιών ΤΝ, διασφαλίζοντας την ασφάλεια δεδομένων, την πιστοποίηση και την κατανομή ευθύνης. Η υιοθέτηση τέτοιων λογισμικών από Νοσοκομεία/κλινικές, διαγνωστικά κέντρα και κλινικά εργαστήρια απαιτεί έξτρα επενδύσεις και θα πρέπει να δοθούν οικονομικά κίνητρα ή/και ειδικές αποζημιώσεις (π.χ. μέσω ΟΑΥ ή Υπουργείου Υγείας ή Ευρωπαϊκών κονδυλίων) για ιατρικές ή/και διαγνωστικές πράξεις που χρησιμοποιούν τεχνολογίες με ενσωμάτωση ΤΝ, οι οποίες μειώνουν το χρόνο, αυξάνουν την ακρίβεια, βελτιώνοντας έτσι την υπηρεσία στον Κύπριο ασθενή. Σχόλιο 3: Κατηγοριοποίηση ιατροτεχνολογικού εξοπλισμού και ιατρικών αναλωσίμων με ΤΝ Εισήγηση 3: Να καταρτιστούν συγκεκριμένες προϋποθέσεις που πρέπει να πληρούν ο ιατροτεχνολογικός εξοπλισμός ή/και αναλώσιμα για να μπορούν να κατηγοριοποιούνται ή/και να ονομάζονται ως είδη με ΤΝ, είτε είναι για επαγγελματική χρήση ή για προσωπική χρήση. Αν υπάρχουν διεθνή ή/και ευρωπαϊκά standards που καθορίζουν την κατηγοριοποίηση αυτή, να ενσωματωθούν στην Κυπριακή Εθνική Στρατηγική και Governance Γενικές Θέσεις ΣΑΙΕΕΚ 1. Υιοθέτηση έτοιμων λύσεων Θέση: Η Εθνική στρατηγική δεν πρέπει να εστιάζει μόνο στην έρευνα, αλλά στην άμεση εφαρμογή έτοιμων λύσεων, που προσφέρονται μέσω λογισμικών ΤΝ. Στόχος: Αναγνώριση των μελών του ΣΑΙΕΕΚ ως των επίσημων φορέων που εισάγουν, παραδίδουν και υποστηρίζουν τεχνικά ώριμα πιστοποιημένα λογισμικά ΤΝ στην καθημερινή κλινική πράξη. 2. Συνεργασία με ομάδα Chief Scientist και ο θεσμικός ρόλος ΣΑΙΕΕΚ Θέση: Επιθυμούμε ανάπτυξη της συνεργασίας μεταξύ της ομάδας του Chief Scientist κι άλλων κρατικών φορέων, ώστε ο ΣΑΙΕΕΚ να καταστεί το θεσμικό όργανο του ιδιωτικού τομέα και της βιομηχανίας για θέματα ΤΝ στον ιατρικό χώρο. Στόχος: Ορισμός σημείου επαφής μεταξύ ΣΑΙΕΕΚ και της ομάδας για την Εθνική Στρατηγική για την ΤΝ, ώστε η γραπτή τοποθέτηση του Συνδέσμου στην πλατφόρμα ⁠e-consultation.gov.cy⁠ να αξιοποιηθεί ουσιαστικά. 3. Καμπάνια ενημέρωσης και επαγρύπνησης με τη συνδρομή του ΣΑΙΕΕΚ Θέση: Πρέπει να υπάρξει καμπάνια επαγρύπνησης για τα οφέλη της ΤΝ, η οποία έρχεται να συνδράμει και όχι να αντικαταστήσει τον επιστήμονα, ο οποίος έχει τον τελικό λόγο και απόφαση. Στόχος: Θα πρέπει και με τη συμβολή του ΣΑΙΕΕΚ να υπάρξουν ενημερώσεις στους διάφορους φορείς, που θα συμμετάσχουν στον εγχείρημα (ΟΑΥ, ΟΚΥΠΥ, ΥΥ), ώστε να μπορέσει να γίνει αντιληπτό το όφελος της εφαρμογής της Εθνικής Στρατηγικής για την ΤΝ." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",Yiorgos,"It is suggested that the Research and Innovation focus areas be reviewed to consider the inclusion of Culture and Creativity as a dedicated Research Focus Area or strategic cross-cutting research domain. This could represent an area in which Cyprus has the potential to develop a distinctive position at European level. Cyprus already has a strong foundation on which to build, including an established creative and cultural ecosystem, a growing games and digital creative industries sector, and a solid base of researchers, technologists and experts. Bringing these capabilities together could create a strong environment for applied research and innovation at the intersection of AI, culture, creativity, digital heritage, gaming and immersive technologies. This direction is also increasingly aligned with EU research and innovation priorities. Initiatives such as the Culture Compass for Europe, Horizon Europe, the New European Bauhaus, EIT Culture & Creativity and S+T+ARTS increasingly recognise the convergence of culture, creativity, research and technology as an important driver of innovation, competitiveness and societal impact. Such a focus could also have a direct positive impact on tourism, by enabling the development of new cultural experiences, immersive heritage applications, AI-enhanced visitor experiences and innovative ways of presenting Cyprus’s cultural assets. In this way, investment in culture and creativity could also contribute to strengthening the competitiveness and attractiveness of Cyprus as a destination. Similarly, it could support the growth of the games industry by fostering the development and adoption of AI, immersive technologies, digital storytelling and creative technologies, while creating stronger links between research, talent and the emerging games and digital creative industries ecosystem in Cyprus." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",Yiorgos,"It is suggested that, before considering the establishment of additional standalone Centres of Excellence, the Strategy explore the potential for a coordinated national structure that builds on and further strengthens the capabilities of Cyprus’s existing Centres of Excellence. Such a structure could take the form of a network, consortium or distributed Centre, bringing together existing teams, infrastructure, research expertise and industry-facing services under a common strategic and governance framework. As a first step, a national mapping of available expertise, infrastructure and services could be undertaken to identify the capabilities already present within the ecosystem and determine any areas where genuine gaps remain. Where additional capacity is required, personnel, infrastructure or specialised units could potentially be developed within, or jointly across, the existing Centres. Such an approach could also allow the Strategy to be implemented more rapidly, as many of the key experts and teams required to address the priority areas are already established within Centres of Excellence. The Centres have also established administrative and operational structures, as well as experience in recruiting additional personnel, which could facilitate the development of any additional capacity required within a relatively short timeframe. By comparison, a new standalone Centre would naturally require time to build its teams, infrastructure, operational structures and networks before reaching a comparable level of maturity. There may also be significant opportunities to achieve greater cost-effectiveness by building on existing capabilities. Attracting a sufficient number of high-calibre senior experts to independently cover all the priority areas identified in the Strategy could be both costly and challenging. Many of these areas are already represented within the existing Centres, allowing a coordinated structure to leverage established expertise while focusing new investment on areas where additional capacity is genuinely needed. The existing Centres could also provide a strong foundation for the industry-facing dimension of such a structure. They are already connected to major European and national initiatives, including the AI Factory Antenna and European Digital Innovation Hubs (EDIHs), and have established mechanisms, networks and experience for engaging with and supporting industry. Building on these existing structures could therefore facilitate a more immediate connection between research capabilities and industry needs. In addition, maintaining this expertise within an active research environment could offer an important long-term advantage. Experts working within the existing Centres benefit from close interaction with researchers, research teams and international academic networks in their respective fields, helping them remain connected to emerging technologies and developments. This continuous exposure to the research ecosystem could be particularly valuable in rapidly evolving technology areas and may be more challenging to maintain within a structure focused primarily on industry support. It is therefore suggested that a coordinated national model leveraging the capabilities of existing Centres be explored as a potentially faster, more cost-effective and scalable approach to achieving the objectives of the Strategy. The establishment of a completely new institutional structure could then be considered where a clearly identified capability gap cannot be effectively addressed through the existing ecosystem." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",chrdio,"ΣΧΟΛΙΟ 1 Αρ. Άρθρου και εδαφίου Παράρτημα Β «AI Use Case Lifecycle and Control Gates», Control Gates 1 έως 4 (σελ. 57–59), σε συνδυασμό με την παράγραφο 3.3.2 «Control Framework», εδάφιο «Approval gates before procurement, deployment, scaling or material modifications» (σελ. 27). Σχόλιο / Εισήγηση Να καθοριστούν ρητά, ανά πύλη ελέγχου, το αρμόδιο εγκριτικό όργανο και τα κριτήρια αξιολόγησης. Για συστήματα που δεν χαρακτηρίζονται υψηλού κινδύνου κατά τον Καν. (ΕΕ) 2024/1689, οι εγκρίσεις να διενεργούνται από τον ίδιο τον φορέα υλοποίησης. Όπου απαιτείται κεντρική έγκριση, να τεθεί δεσμευτική προθεσμία απόκρισης, η άπρακτη πάροδος της οποίας να λογίζεται ως έγκριση. Να προβλεφθεί διαδικασία ένστασης σε περίπτωση απόρριψης. Αιτιολόγηση σχολίου / Εισήγησης Το κείμενο εισάγει τέσσερα σημεία υποχρεωτικής έγκρισης ανά έργο, χωρίς να προσδιορίζει αρμόδιο όργανο, κριτήρια αξιολόγησης, προθεσμία απόκρισης ή δικαίωμα ένστασης. Οι φορείς δεν μπορούν να προγραμματίσουν χρόνο ή πιστώσεις, με αποτέλεσμα η ρύθμιση να λειτουργεί ως αντικίνητρο υλοποίησης έργων και όχι ως μηχανισμός διασφάλισης ποιότητας. Υφίσταται και εσωτερική αντίφαση εντός της Στρατηγικής: το Κεφάλαιο 5 θέτει προθεσμία οκτώ μηνών για την προκήρυξη των πρώτων έξι μεγάλων έργων και δώδεκα μηνών για τον εντοπισμό πέντε εφαρμογών ανά Υπουργείο, ενώ ταυτόχρονα εισάγονται τέσσερις εγκρίσεις ανοικτού χρόνου. Δεδομένου του ρυθμού εξέλιξης της τεχνολογίας, λύση που εγκρίνεται με σημαντική καθυστέρηση ενδέχεται να έχει καταστεί τεχνολογικά παρωχημένη πριν τεθεί σε λειτουργία. Επισημαίνεται τέλος ότι ο Καν. (ΕΕ) 2024/1689 δεν προβλέπει οποιαδήποτε εκ των προτέρων έγκριση από εθνική αρχή, για τα συστήματα υψηλού κινδύνου του Παραρτήματος III η αξιολόγηση συμμόρφωσης διενεργείται με εσωτερικό έλεγχο του ίδιου του φορέα (Παράρτημα VI του Κανονισμού). Πρόκειται συνεπώς για εθνική προσθήκη, η οποία επιδέχεται προσαρμογή χωρίς κίνδυνο μη συμμόρφωσης με το ενωσιακό δίκαιο. ΣΧΟΛΙΟ 2 Αρ. Άρθρου και εδαφίου Παράγραφος 3.5, ενότητα «Government and Public Sector», εδάφια «Common Intelligent Government Platform» και «Adoption Principles – Build Once, Reuse Everywhere» (σελ. 30–31), σε συνδυασμό με Παράρτημα Γ, «Government and Public Sector – Flagship programme(s)» (σελ. 62). Σχόλιο / Εισήγηση Η αρχή «Build Once, Reuse Everywhere» και η χρήση της κοινής κυβερνητικής πλατφόρμας να διατυπωθούν ως δυνατότητα και όχι ως υποχρέωση, με ρητή πρόβλεψη εξαίρεσης όπου υφίσταται ήδη λειτουργούσα λύση ή όπου συντρέχουν ειδικές επιχειρησιακές απαιτήσεις τις οποίες η κοινή πλατφόρμα δεν καλύπτει. Η υποχρέωση επαναχρησιμοποίησης να περιοριστεί ρητά στο τεχνικό υπόστρωμα και να μην επεκτείνεται στην επιχειρησιακή λογική των φορέων. Αιτιολόγηση σχολίου / Εισήγησης Η κοινή πλατφόρμα περιλαμβάνει ονομαστικά τη διαχείριση υποθέσεων και την επεξεργασία εγγράφων. Οι όροι αυτοί είναι γενικοί, όμως το περιεχόμενό τους διαφέρει ριζικά ανά φορέα. Ενδεικτικά: η επεξεργασία εγγράφων για την αξιολόγηση επιλεξιμότητας σε επίδομα πρόνοιας αφορά τραπεζικές καταστάσεις, ενοικιαστήρια και βεβαιώσεις εισοδήματος, με αντιστοίχιση σε κανόνες που μεταβάλλονται νομοθετικά. Στον τελωνειακό έλεγχο αφορά ανάλυση εικόνων σαρωτή και παραστατικών μεταφοράς σε πραγματικό χρόνο, δηλαδή τεχνολογία υπολογιστικής όρασης. Στον τομέα της υγείας αφορά ιατρικά δεδομένα υπό κλινική ευθύνη, με ενδεχόμενη υπαγωγή σε καθεστώς ιατροτεχνολογικού προϊόντος. Στις νομικές υπηρεσίες αφορά ανάλυση νομοθεσίας και νομολογίας. Το πράγματι επαναχρησιμοποιήσιμο τμήμα περιορίζεται στο τεχνικό υπόστρωμα, ενώ η επιχειρησιακή λογική, η νομική βάση επεξεργασίας, οι περίοδοι τήρησης, τα απαιτούμενα επίπεδα ακρίβειας και η κατάταξη κινδύνου κατά τον Καν. (ΕΕ) 2024/1689 διαφέρουν εξ ολοκλήρου. Επιπροσθέτως, η υποχρεωτική επαναχρησιμοποίηση προϋποθέτει κοινό μοντέλο δεδομένων μεταξύ φορέων, το οποίο δεν υφίσταται, η ίδια η Στρατηγική διαπιστώνει κατακερματισμό υποδομών και ανώριμη διακυβέρνηση δεδομένων. Η διατύπωση της αρχής ως δεσμευτικής, με δηλωμένο σκοπό την εξάλειψη των διπλών προμηθειών, καθιστά την εφαρμογή της πρακτικά ανέφικτη και ενδέχεται να εμποδίσει φορείς από την ανάπτυξη λύσεων προσαρμοσμένων στις πραγματικές τους ανάγκες. ΣΧΟΛΙΟ 3 Αρ. Άρθρου και εδαφίου Παράγραφος 3.3.2 «Control Framework», εδάφιο «Use of approved and certified delivery and implementation partners in line with established governance and procurement requirements» (σελ. 27). Σχόλιο / Εισήγηση Να απαλειφθεί η πρόνοια ή να μετατραπεί σε μη δεσμευτική σύσταση. Εφόσον διατηρηθεί, να διευκρινιστεί ρητά ότι δεν υποκαθιστά και δεν περιορίζει τη διαδικασία επιλογής αναδόχου κατά τη νομοθεσία περί δημοσίων συμβάσεων, ότι γίνονται δεκτά ισοδύναμα πιστοποιητικά και άλλα αποδεικτικά μέσα, και να προβλεφθεί μεταβατική ρύθμιση για τις ενεργές συμβάσεις. Αιτιολόγηση σχολίου / Εισήγησης Η πρόνοια δημιουργεί παράλληλο μηχανισμό προεπιλογής προμηθευτών εκτός της διαδικασίας του διαγωνισμού και εκτιμάται ότι αντίκειται στο ισχύον πλαίσιο δημοσίων συμβάσεων για τέσσερις λόγους. Πρώτον, η καταλληλότητα των οικονομικών φορέων κρίνεται από την αναθέτουσα αρχή ανά διαγωνισμό, με κριτήρια που συνδέονται και είναι ανάλογα προς το συγκεκριμένο αντικείμενο, γενικά συστήματα προεπιλογής προβλέπονται μόνο για τους φορείς κοινής ωφέλειας και όχι για τις κλασικές δημόσιες συμβάσεις. Δεύτερον, όπου επιτρέπεται απαίτηση πιστοποίησης, η αναθέτουσα αρχή υποχρεούται να αποδέχεται ισοδύναμα πιστοποιητικά και άλλα αποδεικτικά μέσα, δυνατότητα την οποία ο κλειστός κατάλογος καταργεί στην πράξη. Τρίτον, η τήρηση του καταλόγου ανατίθεται στην Εθνική Αρχή ΤΝ, η οποία ταυτόχρονα λειτουργεί τον Government AI Accelerator και τις κοινές πλατφόρμες, το ίδιο όργανο δηλαδή που παρέχει λύσεις αποφασίζει ποιοι τρίτοι επιτρέπεται να τις ανταγωνιστούν, γεγονός που εγείρει ζήτημα σύγκρουσης συμφερόντων. Τέταρτον, ο περιορισμός θίγει την πρόσβαση μικρομεσαίων επιχειρήσεων και οικονομικών φορέων άλλων κρατών μελών, με προβλέψιμο αποτέλεσμα τη μείωση των υποβαλλόμενων προσφορών και την αύξηση του κόστους. Σημειώνεται ότι ο Καν. (ΕΕ) 2024/1689 δεν περιέχει καμία πρόβλεψη περί καταλόγων εγκεκριμένων αναδόχων. ΣΧΟΛΙΟ 4 Αρ. Άρθρου και εδαφίου Παράγραφος 3.9.6 «AI Social Contract Principles», εδάφιο περί καταχώρισης στη βάση δεδομένων της ΕΕ και ετήσιου ελέγχου από την «Cyprus AI Security & Certification Authority» (σελ. 43). Σε συνδυασμό με: παράγραφο 3.3.1 «Government AI Accelerator» (σελ. 25), παράγραφο 3.5 «Portfolio Governance and Review» (σελ. 31), Παράρτημα Γ «Public Sector» (σελ. 60) και Κεφάλαιο 5, σημεία 4 και 6 (σελ. 51–52). Σχόλιο / Εισήγηση Οι υποχρεώσεις καταχώρισης, αναφοράς και ελέγχου να περιοριστούν σε όσα ήδη επιβάλλει ο Καν. (ΕΕ) 2024/1689. Ειδικότερα, να απαλειφθεί η πρόβλεψη ετήσιου ελέγχου σε κάθε οργανισμό «χωρίς εξαίρεση» και να προβλεφθεί ενιαίο σημείο καταχώρισης και υποβολής αναφορών, αντί των τριών παράλληλων μητρώων. Για Υπηρεσίες που υπάγονται σε Υπουργείο ή Υφυπουργείο, η υποβολή να γίνεται μέσω του εποπτεύοντος Υπουργείου και όχι χωριστά ανά Υπηρεσία. Να ενοποιηθεί επίσης η ορολογία και η συχνότητα επικαιροποίησης της στρατηγικής ΤΝ ανά φορέα, η οποία σήμερα αναφέρεται ως τριετής στην παράγραφο 3.3.1 και ως ετήσια στο Παράρτημα Γ. Αιτιολόγηση σχολίου / Εισήγησης Σωρευτικά επιβάλλονται: ετήσια δημοσίευση στρατηγικής ΤΝ ανά φορέα με προθεσμία τον Μάρτιο 2027, τριμηνιαίες αναφορές χαρτοφυλακίου, εντοπισμός πέντε νέων εφαρμογών ανά έτος, καταχώριση σε τρία διαφορετικά μητρώα και ετήσιος εξωτερικός έλεγχος σε κάθε οργανισμό χωρίς εξαίρεση. Το άθροισμα συνιστά μόνιμη διοικητική απασχόληση την οποία οι φορείς, με τη σημερινή τους στελέχωση, δεν μπορούν να απορροφήσουν χωρίς να θιγεί το κύριο έργο τους, ενώ σημαντικό μέρος της ζητούμενης πληροφορίας είναι ταυτόσημο και απλώς επαναλαμβάνεται. Από το σύνολο αυτό, ο Καν. (ΕΕ) 2024/1689 απαιτεί μόνο την καταχώριση στη βάση δεδομένων της ΕΕ. Ετήσιος έλεγχος από εθνική αρχή πιστοποίησης δεν προβλέπεται πουθενά στον Κανονισμό, ενώ τα πρότυπα ISO 42001 και ISO 27001 έχουν εθελοντικό χαρακτήρα. Επισημαίνεται περαιτέρω ότι η αναφερόμενη «Cyprus AI Security & Certification Authority» δεν περιλαμβάνεται στο μοντέλο διακυβέρνησης της παραγράφου 3.3.1 ούτε περιγράφεται σε άλλο σημείο του κειμένου, με αποτέλεσμα να ανατίθεται υποχρέωση ετήσιου ελέγχου σε φορέα του οποίου η σύσταση, οι αρμοδιότητες και η διαδικασία δεν έχουν καθοριστεί. ΣΧΟΛΙΟ 5 Αρ. Άρθρου και εδαφίου Παράρτημα Β «AI Use Case Lifecycle and Control Gates», Control Gate 1 και Control Gate 2 (σελ. 57–58). Σχόλιο / Εισήγηση Να προστεθεί ρητή μεταβατική διάταξη ώστε έργα τεχνητής νοημοσύνης που έχουν ήδη ανατεθεί και βρίσκονται σε στάδιο υλοποίησης να συνεχίζονται κανονικά και να εντάσσονται στο πλαίσιο από το επόμενο σημείο ελέγχου και εφεξής, χωρίς αναδρομική εφαρμογή εγκρίσεων. Σε κάθε περίπτωση, οι εθνικές προθεσμίες συμμόρφωσης δεν πρέπει να είναι συντομότερες από τις μεταβατικές προθεσμίες που ορίζει το άρθρο 111 του Καν. (ΕΕ) 2024/1689 για τους δημόσιους φορείς. Αιτιολόγηση σχολίου / Εισήγησης Τα σημεία έγκρισης τοποθετούνται πριν την προμήθεια και πριν την ανάπτυξη, χωρίς καμία αναφορά σε έργα που βρίσκονται ήδη σε εξέλιξη κατά την έναρξη ισχύος του πλαισίου. Χωρίς μεταβατική ρύθμιση, ενεργές συμβάσεις ενδέχεται να κληθούν να περάσουν αναδρομικά από εγκρίσεις που δεν υφίσταντο κατά τον χρόνο της ανάθεσης, με κίνδυνο αναστολής συμβατικών χρονοδιαγραμμάτων και δημοσιονομικών δεσμεύσεων. Επισημαίνεται ότι ο ενωσιακός νομοθέτης έχει ήδη αναγνωρίσει την ανάγκη μεταβατικής περιόδου για τον δημόσιο τομέα, ορίζοντας στο άρθρο 111 του Κανονισμού προθεσμία συμμόρφωσης για συστήματα υψηλού κινδύνου που προορίζονται για χρήση από δημόσιες αρχές. Εθνικό κείμενο πολιτικής δεν θα πρέπει να θέτει αυστηρότερα χρονικά όρια από την υπερκείμενη ενωσιακή ρύθμιση. ΣΧΟΛΙΟ 6 Στο άρθρο 3.3.1.7 αναφέρεται ότι “every ministry deploying AI will be required to maintain its own Applied AI Strategy aligned with the National AI Strategy and in line with the EU AI Act, with an updated adoption plan every 3 years’’ Στο Annex C αναφέρεται ότι “All ministries and public bodies will publish their Institutional AI Strategies by March 2027 and update them annually”. Σχόλιο / Εισήγηση Στο άρθρο 3.3.1.7 αναφέρεται σε κάθε Υπουργείο καθώς και στην υποχρέωση ανανέωσης της Στρατηγικής του κάθε 3 χρόνια ενώ στο Annex C αναφέρεται και σε δημόσια σώματα πέραν απο τα Υπουργεία αναφέροντας υποχρέωση ετήσιας ανανέωσης της Στρατηγικής . Αιτιολόγηση σχολίου / Εισήγησης Το ερώτημα είναι η υποχρέωση διατήρησης Στρατηγικής ΤΝ εκτείνετεται πέραν απο τα Υπουργεία και σε Υφυπουργεία; Επίσης η εν λόγω στρατηγική θα πρέπει να ανανεώνεται κάθε 3 χρόνια ή ετησίως; To ερώτημα υποβάλλεται για λόγους διασαφήνισης της υποχρέωσης και ομοιομορφίας του χρονικού πλαισίου. ΣΧΟΛΙΟ 7 Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο – Το άρθρο 1 αναφέρει “The development of the National AI Strategy considers elements that act as the ethical and operational guardrails for all AI activities in Cyprus» Σχόλιο / Εισήγηση Είναι χρήσιμο να δοθεί πιο εξειδικευμένη ερμηνεία του «AI activities in Cyprus» και να καθοριστεί το πεδίο εφαρμογής της εν λόγω Στρατηγικής (για ποιά ακριβώς εργαλεία ΤΝ θα εφαρμόζεται). Αιτιολόγηση σχολίου / Εισήγησης Με τον τρόπο αυτό θα γίνει πιο κατανοητό το εύρος εφαρμογής της Στρατηγικής κατά την εκτέλεση επαγγελματικών δραστηριοτήτων." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Ludmila Kousoulidou","Associate Scientist at the Cyprus Institute of Neurology and Genetics; Member of the Cyprus Review Bioethics Committee for Biomedical Research and Clinical Trials on Medicinal Products of Human Use A'. The comments below refer to Section 2 and are relevant to the main objectives and priorities of the National AI strategy. 1. 2.4.: I suggest two additions to the five key ideas, specifically: a) Continuously monitored AI: ensure ongoing evaluation of its socio-economic and environmental impact based on real-time data and allow for interventions where necessary to optimise cost-benefit balance. b) AI strictly regulated by law: prioritize the establishment of a detailed legal framework for AI regulation across all sectors, prior to nation-wide implementation. The above key ideas should also be reflected in the description of the Priorities and Objectives: 2. 2.4.1: Healthcare and Life Sciences: regulate legal accountability for medical decisions assisted by AI. Education and Human Capital Development: establish a legal age limit for using AI within primary and secondary education. Institutions should have a clear regulation code regarding the acceptable applications of AI by students and teaching personnel. Monitoring systems should be in place to assess educational outcomes. This will ensure that essential brain development in young children will not be hindered by excessive reliance on AI and that students will have the opportunity to acquire basic critical thinking and research skills before employing AI-assisted learning. Add Agriculture as a priority sector for AI: agriculture in Cyprus has a great potential of becoming one of the major economy drivers and build the foundation for a less tourist-dependant economy with higher resilience to geopolitical turbulence. It is also one of the areas where the impact of AI can be substantial, especially where automation and optimisation are required e.g. for crops management and processing of produce. 3. 2.5: Add a separate Objective addressing legal regulation (see comment 1b above), including all relevant sectors. In addition to healthcare and education, issues such as patents, copyright and plagiarism should be examined considering AI application in innovative product development, arts and content creation. 4. 2.5.5. objective 5: A clear plan should be conducted on the allocation of the 3000 AI professionals, starting with a pilot study examining the effect of such a development on the overall workforce of Cyprus. Among other issues, this study should focus on measures to prevent staff shortages in other critical priority sectors and on possible socio-economic effects." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",Kokk1reb,"ΕΙΣΗΓΗΣΕΙΣ ΓΕΝΙΚΟΥ ΧΗΜΕΙΟΥ ΤΟΥ ΚΡΑΤΟΥΣ (ΓΧΚ): PROPOSED COMMENTS BY THE STATE GENERAL LABORATORY (SGL) COMMENT 1 Article / paragraph Section 2.4.1 – Priority Sectors for Leadership: Healthcare and Life Sciences Annex C – Healthcare and Life Sciences Comment / Recommendation The Healthcare and Life Sciences pillar should explicitly recognize the role of Public Health Laboratories and laboratory intelligence as an integral component of AI-enabled healthcare and public health. The Strategy should include: “AI-supported laboratory analytics for food safety, environmental monitoring, toxicology and chemical risk assessment.” Justification The Strategy appropriately identifies Healthcare and Life Sciences as a priority sector and focuses on clinical decision-making, preventive care, health data and healthcare system optimization. However, the laboratory dimension of public health is not sufficiently reflected. The SGL is a key national scientific and laboratory institution supporting public health through laboratory surveillance and analytical activities in areas including food safety, environmental health, drinking water quality, chemical hazards and toxicology. AI-supported laboratory analytics could enhance the interpretation of complex analytical datasets, support early identification of emerging hazards and strengthen evidence-based public health decision-making. PROPOSED COMMENTS BY THE STATE GENERAL LABORATORY (SGL) COMMENT 2 Article / paragraph Section 3.2.1 – Strategic Role of Data Section 3.2.3 – Interoperability and Secure Data Sharing Comment / Recommendation The proposed federated national data architecture should explicitly recognize a: National Laboratory Data Space This should enable secure and governed interoperability between the State General Laboratory, hospitals, Veterinary Services, environmental authorities, water authorities, universities and other relevant public-sector and research institutions. Justification The Strategy correctly recognizes data as a strategic national asset and proposes secure interoperability across ministries, hospitals, universities and regulated sectors. It also identifies health and environment among the potential sectoral data spaces. A dedicated National Laboratory Data Space would complement this architecture by bringing together high-value scientific and analytical laboratory data relevant to public health, food safety, environmental health, chemical safety and toxicology. Such an approach would support secure data sharing, research and innovation, early warning, risk assessment and evidence-based decision-making, while preserving appropriate access controls, data protection and auditability. PROPOSED COMMENTS BY THE STATE GENERAL LABORATORY (SGL) COMMENT 3 Article / paragraph Section 3.4 – AI Adoption Across Government Section 3.4.1 – Priority Areas for Government Adoption Section 3.4.2 – Use Case Driven Approach Comment / Recommendation The Strategy should explicitly include public health laboratory intelligence and national chemical intelligence among the high-value government AI use cases. AI applications should support: • analysis of large-scale laboratory datasets; • detection of emerging trends and anomalies; • identification and forecasting of chemical and biological hazards; • early warning and surveillance; • population exposure assessment; • evidence-based decision-making. Justification The Strategy promotes practical, high-value AI use cases in government, including analytical and forecasting capabilities for evidence-based decision-making. The State General Laboratory generates and interprets large volumes of scientific laboratory data. These data represent an important national asset for public health protection and can provide valuable signals for emerging risks. Explicitly recognizing laboratory intelligence and national chemical intelligence would extend the Strategy beyond administrative and clinical applications and strengthen its public health and prevention dimension. PROPOSED COMMENTS BY THE STATE GENERAL LABORATORY (SGL) COMMENT 4 Article / paragraph Section 3.5 – Priority Sectors Section 3.8 – Research, Innovation and Ecosystem Development Annex D – Research and Innovation, Focus Area 1: Energy, Environment and Resource Management; Focus Area 3: Healthcare Comment / Recommendation The Strategy should adopt a One Health perspective in the development and application of AI for health, environmental and food-safety surveillance. The Strategy should include: “AI should support One Health surveillance through the integrated analysis of laboratory, environmental and food safety data.” Justification The Strategy already identifies Healthcare, Environment and Resource Management as important areas for AI research and highlights the importance of integrated, evidence-based approaches. The One Health approach provides an appropriate framework for connecting human health, animal health, food safety and environmental health. The State General Laboratory contributes through the generation and interpretation of laboratory data across several of these domains. Integrating relevant datasets through AI could improve early detection of emerging hazards and strengthen national preparedness and prevention. PROPOSED COMMENTS BY THE STATE GENERAL LABORATORY (SGL) COMMENT 5 Article / paragraph Section 3.13 – Risk Management, Resilience and Adaptation Section 3.4.2 – Use Case Driven Approach Comment / Recommendation The Strategy should explicitly recognize the use of AI in risk assessment and early warning for chemical and public health hazards, including: • intelligent sample prioritization; • anomaly detection; • contamination prediction; • exposure modelling; • horizon scanning. Justification The Strategy already identifies risk identification and assessment, including ongoing horizon scanning, as an important component of national AI resilience. AI can significantly strengthen scientific risk assessment by identifying patterns and emerging signals across large and heterogeneous datasets. For the State General Laboratory, such applications could support the prioritization of laboratory resources, improve early identification of emerging hazards and strengthen national preparedness for chemical, food and environmental risks. PROPOSED COMMENTS BY THE STATE GENERAL LABORATORY (SGL) COMMENT 6 Article / paragraph Section 3.4.4 – Shared Capabilities and Reuse Section 3.2.3 – Interoperability and Secure Data Sharing Section 3.7 – Infrastructure, Compute and Digital Sovereignty Comment / Recommendation The Strategy should explicitly recognize AI-enabled digital laboratory infrastructure as a component of public-sector AI transformation. This should include: • Laboratory Information Management Systems (LIMS); • digital laboratories; • intelligent laboratory workflows; • AI-enabled analytical and decision-support tools. Justification The Strategy promotes shared platforms, reusable components, interoperability and common capabilities across government. Laboratory systems constitute a specialized but strategically important component of public-sector digital infrastructure. AI-enabled LIMS and intelligent laboratory workflows could improve laboratory efficiency, data quality, traceability, resource allocation and decision support. This would also create a practical pathway for connecting laboratory data with wider national health, environmental and food-safety data infrastructures. PROPOSED COMMENTS BY THE STATE GENERAL LABORATORY (SGL) COMMENT 7 Article / paragraph Section 3.1.2 – Design Principles Section 3.4.3 – Human Oversight and Accountability Section 3.9.3 – Transparency and Explainability Comment / Recommendation The Strategy should explicitly require Explainable AI principles for AI systems supporting laboratory analysis, chemical risk assessment and public health surveillance. The Strategy should emphasize: transparency, auditability, scientific traceability and mandatory human oversight for high-impact decisions. Justification The Strategy already establishes explainability, auditability, human oversight and accountability as fundamental principles of responsible AI. These principles are particularly important in laboratory and scientific applications because analytical results generated by the State General Laboratory may support regulatory, public health, customs, law-enforcement and judicial processes. For such applications, it is essential that AI-supported outputs can be scientifically interpreted, traced and audited, while final high-impact decisions remain subject to appropriate expert human oversight. PROPOSED COMMENTS BY THE STATE GENERAL LABORATORY (SGL) COMMENT 8 – Proposed Pilot Applications Article / paragraph Section 3.4.2 – Use Case Driven Approach Annex C – Priority Sectors for Leadership Annex D – Research and Innovation Comment / Recommendation The State General Laboratory proposes the consideration of the following pilot AI applications in the field of public health laboratory science: 1. Intelligent Food Safety Surveillance 2. AI-supported Drinking Water Quality Monitoring 3. AI-supported Environmental Surveillance and Early Hazard Detection 4. Intelligent Laboratory Sample Prioritization 5. AI-assisted Chemical Risk Assessment 6. Smart Laboratory Information Management Systems (Smart LIMS) 7. National Early Warning System for Chemical Hazards 8. AI-enabled Scientific Assistant for State General Laboratory scientists 9. AI-supported Public Health Crisis Management 10. National AI Platform for Public Health Chemistry 11. AI and Chemoinformatic for the Automated Assessment and Classification of New Psychoactive Substances (NPS) Justification The Strategy explicitly promotes a use-case-driven approach, prioritizing applications that demonstrate measurable public value, feasibility, data readiness and manageable risk. The proposed applications provide concrete examples of how this approach could be implemented within public health laboratory services. They build on SGL’s existing scientific expertise, laboratory infrastructure and analytical data and could provide suitable pilot projects for the responsible application of AI in food safety, environmental health, toxicology, chemical safety and public health surveillance. PROPOSED COMMENTS BY THE STATE GENERAL LABORATORY (SGL) COMMENT 9 – SGL readiness and contribution Article / paragraph Section 3.8 – Research, Innovation and Ecosystem Development Section 3.4 – AI Adoption Across Government Objective 8 – Develop Sovereign Capability through Partnerships Comment / Recommendation The State General Laboratory considers the application of AI to public health, through the processing and utilization of scientific laboratory data for prevention, surveillance and risk assessment, to be an area of high strategic importance. The SGL is ready to contribute, in collaboration with other competent authorities and relevant academic and research institutions, to the further development of relevant AI applications and pilot projects in support of the implementation of the National AI Strategy. Justification The Strategy emphasizes applied, impact-oriented research, collaboration between government, academia and industry, and the development of sovereign national capabilities through trusted partnerships. The SGL can contribute specialized scientific expertise, laboratory infrastructure, analytical data and domain knowledge in areas directly relevant to public health, food safety, environmental health, chemical risk and toxicology. Its participation would therefore support the Strategy's objectives on public-sector AI adoption, applied research, national capability development and responsible AI deployment." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Αρχή Ανάπτυξης Ανθρώπινου Δυναμικού Κύπρου","1. National AI Skills Observatory Αφορά τις σελίδες 24, 36–37 και 78–79 της Στρατηγικής . Να καθοριστούν ο θεσμικός και λειτουργικός ρόλος της ΑνΑΔ στο National AI Skills Observatory (NASO), οι ευθύνες των συνεργαζόμενων φορέων και ο τρόπος αξιοποίησης των αποτελεσμάτων του στον σχεδιασμό πολιτικών και δράσεων κατάρτισης. Να εξειδικευτεί ο μηχανισμός μέσω του οποίου το NASO θα παρακολουθεί τις επιπτώσεις της ΤΝ στα επαγγέλματα, στα εργασιακά καθήκοντα και στις ανάγκες σε δεξιότητες, περιλαμβανομένων της μεθοδολογίας, των βασικών δεικτών, των πηγών δεδομένων και της συχνότητας παρακολούθησης. Να αξιοποιηθούν οι υφιστάμενοι μηχανισμοί των συνεργαζόμενων Φορέων, αποφεύγοντας επικαλύψεις. Η συνεισφορά της ΑνΑΔ να καθοριστεί με βάση τα δεδομένα και τις αναλύσεις που είναι διαθέσιμα στο πλαίσιο των αρμοδιοτήτων της. 2. Παροχή δεδομένων στο NASO Αφορά τις σελίδες 20-21 και 79 της Στρατηγικής. Να καθοριστούν τα δεδομένα που θα απαιτείται να παρέχει η ΑνΑΔ στο NASO, η συχνότητα και η μορφή παροχής τους, τα κοινά πρότυπα ανταλλαγής και οι ευθύνες για την ποιότητα και επικαιροποίησή τους. Να διευκρινιστούν η νόμιμη βάση επεξεργασίας, οι απαιτήσεις ασφάλειας και οι τεχνικές προδιαγραφές διασύνδεσης, καθώς και ο τρόπος αντιμετώπισης περιπτώσεων όπου υφιστάμενα πληροφοριακά συστήματα δεν είναι άμεσα συμβατά. Οι συγκεκριμένες κατηγορίες δεδομένων να καθοριστούν σε συνεργασία με τους εμπλεκόμενους φορείς, με βάση τον σκοπό του NASO, την αναγκαιότητα των δεδομένων και τις υφιστάμενες δυνατότητες των πληροφοριακών συστημάτων. Να προβλεφθούν οι αναγκαίοι πόροι για τυχόν απαιτούμενες προσαρμογές. Να καθοριστούν επίσης σαφείς ευθύνες για την παροχή, επικύρωση, επικαιροποίηση και διόρθωση των δεδομένων, καθώς και για τον υπολογισμό και τη δημοσίευση των σχετικών δεικτών. 3. . Διακυβέρνηση του FutureAI CY Αφορά τις σελίδες 79-80 και 93-94 της Στρατηγικής. Να διευκρινιστεί τι συνεπάγεται για την ΑνΑΔ η συμπροεδρία της AI Upskilling Certification and Quality Committee και να προσδιοριστούν οι αρμοδιότητες της ΑνΑΔ στον σχεδιασμό, στην υλοποίηση, στη διασφάλιση ποιότητας και στην παρακολούθηση του FutureAI CY. Να αποσαφηνιστεί ο μηχανισμός επιλογής, έγκρισης και υλοποίησης των προγραμμάτων κατάρτισης στα οποία θα συμμετέχουν οι δικαιούχοι του FutureAI CY και κατά πόσο θα αξιοποιηθούν υφιστάμενα Σχέδια και διαδικασίες της ΑνΑΔ ή θα εφαρμοστεί διαφορετικός μηχανισμός. Να αποσαφηνιστεί επίσης η σχέση με το Σύστημα Αξιολόγησης και Πιστοποίησης Συντελεστών Παροχής Κατάρτισης, το Συστημα Επαγγελματικών Προσόντων και τις αρμοδιότητες άλλων αρμόδιων φορέων, περιλαμβανομένου του ΔΙΠΑΕ, ώστε να αποφεύγονται παράλληλες διαδικασίες και επικαλύψεις. Στη διακυβέρνηση του FutureAI CY να εξεταστεί η συμμετοχή του Υπουργείου Εργασίας και Κοινωνικών Ασφαλίσεων και αντιπροσωπευτικών οργανώσεων εργοδοτών και εργαζομένων, καθώς και άλλων σχετικών φορέων, με σαφή καθορισμό του ρόλου τους. Επιπρόσθετα, να διευκρινιστεί ο τρόπος λειτουργίας και λήψης αποφάσεων της Επιτροπής. 4. Πιστοποίηση παρόχων και μητρώο διαπιστευτηρίων Αφορά τις σελίδες 79-80 και 93-94 της Στρατηγικής. Να διευκρινιστεί το αντικείμενο των όρων provider accreditation και credentials registry που χρησιμοποιούνται στη Στρατηγική, περιλαμβανομένων των κατηγοριών παρόχων και διαπιστευτηρίων που καλύπτονται. Να καθοριστούν ο αρμόδιος φορέας, τα κριτήρια και οι διαδικασίες για έγκριση, εγγραφή, ανανέωση, αναστολή ή ανάκληση, καθώς και οι διαδικασίες επανεξέτασης ή ένστασης όπου απαιτούνται. Να καθοριστεί, όπου είναι αναγκαίο, ο τρόπος αναγνώρισης ή αντιστοίχισης υφιστάμενων εθνικών και διεθνών πιστοποιήσεων και η σχέση τους με τα σχετικά εθνικά και ευρωπαϊκά πλαίσια προσόντων. Να εξεταστεί κατά προτεραιότητα η αξιοποίηση ή επέκταση υφιστάμενων συστημάτων πιστοποίησης (Σύστημα Αξιολόγησης και Πιστοποίησης Συντελεστών Παροχής Κατάρτισης, το Συστημα Επαγγελματικών Προσόντων) και μητρώων της ΑνΑΔ, όπου αυτά μπορούν να καλύψουν τις νέες απαιτήσεις, αντί της δημιουργίας παράλληλων διαδικασιών και συστημάτων. Να αποσαφηνιστεί επίσης αν το credentials registry θα υλοποιηθεί ως κεντρική εθνική υπηρεσία ή μέσω διασύνδεσης με υφιστάμενα μητρώα και πληροφοριακά συστήματα, καθώς και οι ευθύνες λειτουργίας, ενημέρωσης, τεχνικής υποστήριξης και χρηματοδότησής του. 5. Μικροδιαπιστευτήρια 5–15 ECTS Αφορά τις σελίδες 80-81 της Στρατηγικής . Η Στρατηγική προβλέπει μικροδιαπιστευτήρια 5–15 ECTS, χωρίς να αποσαφηνίζει πλήρως ποιοι φορείς θα τα απονέμουν, πώς θα αναγνωρίζονται και πώς θα συνδέονται με τους μηχανισμούς χρηματοδότησης και πιστοποίησης της κατάρτισης. Η διευκρίνιση είναι αναγκαία, ώστε να διαχωριστούν σαφώς οι ακαδημαϊκές λειτουργίες από τις λειτουργίες χρηματοδότησης και πιστοποίησης της κατάρτισης, δεδομένου ότι δεν εμπίπτουν όλες στις αρμοδιότητες της ΑνΑΔ, όπως, για παράδειγμα, τα ECTS. Υποβάλλεται επίσης εισήγηση να εξεταστεί η συμπερίληψη αναφοράς στο ECVET, το οποίο σχετίζεται με δραστηριότητες της ΑνΑΔ. Η συγκεκριμένη εισήγηση προϋποθέτει την έγκριση του Διοικητικού Συμβουλίου της ΑνΑΔ. 6. Χρηματοδότηση και σύστημα κουπονιών του FutureAI CY Αφορά τις σελίδες 80-81 της Στρατηγικής. Να αποσαφηνιστεί ο μηχανισμός χρηματοδότησης και υλοποίησης του FutureAI CY, περιλαμβανομένου του κατά πόσο θα εφαρμοστεί το προτεινόμενο local voucher scheme ή άλλη κατάλληλη διευθέτηση. Σε περίπτωση εφαρμογής συστήματος κουπονιών, να καθοριστούν οι πηγές χρηματοδότησης ανά κατηγορία δικαιούχου, καθώς και οι φορείς έγκρισης, διαχείρισης, εξαργύρωσης και ελέγχου. Να διευκρινιστεί επίσης αν η τεχνική διαχείριση του συστήματος κουπονιών θα πραγματοποιείται μέσω κεντρικής εθνικής πλατφόρμας ή μέσω διασύνδεσης με υφιστάμενα συστήματα και να καθοριστούν οι σχετικές ευθύνες λειτουργίας, τεχνικής υποστήριξης και χρηματοδότησης. Πρόσθετα να διευκρινιστεί η σχέση του μηχανισμού με τα υφιστάμενα Σχέδια της ΑνΑΔ και η δυνατότητα χρηματοδότησης από άλλες εθνικές ή ευρωπαϊκές πηγές, όπου απαιτείται. Σημειώνεται ότι, η ΑνΑΔ δεν νομιμοποιείται να χρηματοδοτήσει μέσω του συστήματος κουπονιών (voucher scheme) κατηγορίες δικαιούχων για τους οποίους δεν καταβάλλεται Τέλος Ανάπτυξης Ανθρώπινου Δυναμικού, όπως εργοδοτούμενους στον δημόσιο τομέα (public sector officials/servants) και τους συνταξιούχους. Η χρηματοδότηση των ομάδων αυτών θα πρέπει να καλυφθεί από άλλους εθνικούς πόρους ή ευρωπαϊκά κονδύλια.Προτείνεται η ρητή αποσαφήνιση των πηγών χρηματοδότησης ανά κατηγορία δικαιούχου στο κείμενο της Στρατηγικής. 7. Ομάδες στόχου και επιλέξιμοι δικαιούχοι Αφορά τη σελίδα 80 της Στρατηγικής. Να προσδιοριστούν χωριστά οι ομάδες στόχου του εθνικού προγράμματος FutureAI CY και οι κατηγορίες συμμετεχόντων των οποίων η κατάρτιση δύναται να χρηματοδοτείται από την ΑνΑΔ σύμφωνα με το εφαρμοστέο θεσμικό πλαίσιο και τα σχετικά Σχέδιά της. Για κατηγορίες συμμετεχόντων που δεν χρηματοδοτούνται από την ΑνΑΔ να προσδιοριστούν άλλες κατάλληλες εθνικές ή ευρωπαϊκές πηγές χρηματοδότησης. Η ύπαρξη διαφορετικής πηγής χρηματοδότησης δεν θα πρέπει από μόνη της να συνεπάγεται αποκλεισμό μιας ομάδας από το εθνικό πρόγραμμα. 8. Δείκτες απόδοσης και αξιολόγηση αποτελεσμάτων Αφορά τις σελίδες 44-45, 80-81 και 93-94 της Στρατηγικής. Για κάθε βασικό δείκτη απόδοσης (KPI) που θα υιοθετηθεί στο πλαίσιο εφαρμογής της Στρατηγικής να καθορίζονται ποσοτικοποιημένος στόχος, σημείο αναφοράς όπου απαιτείται, πηγή δεδομένων, υπεύθυνος φορέας, συχνότητα μέτρησης και μεθοδολογία υπολογισμού. Για το FutureAI CY να καθοριστούν δείκτες που να επιτρέπουν την αξιολόγηση της επίδρασης της κατάρτισης στην ανάπτυξη δεξιοτήτων, στην παραγωγικότητα, στην απασχολησιμότητα ή απασχόληση και, όπου είναι κατάλληλο, σε άλλα μετρήσιμα εργασιακά αποτελέσματα. Οι δείκτες αυτοί να συνδέονται με την ανεξάρτητη αξιολόγηση της πιλοτικής εφαρμογής πριν από την ευρύτερη ανάπτυξη του προγράμματος. 9. Εφαρμογή των προβλέψεων της Στρατηγικής στην ΑνΑΔ Αφορά τις σελίδες 24-25 της Στρατηγικής. Να διευκρινιστεί αν και σε ποιο βαθμό οι προβλέψεις για public bodies/public sector organisations εφαρμόζονται στην ΑνΑΔ ως νομικό πρόσωπο δημοσίου δικαίου. Να προσδιοριστούν οι υποχρεώσεις διακυβέρνησης, ελέγχων, αξιολόγησης κινδύνων, αναφορών, ανταλλαγής δεδομένων και κατάρτισης, με σαφή κατανομή ευθυνών και απαιτούμενων πόρων. 10. Institutional AI Strategy της ΑνΑΔ Αφορά τις σελίδες 25, 60-61 της Στρατηγικής. Να αποσαφηνιστεί αν η ΑνΑΔ υπάγεται στην υποχρέωση εκπόνησης και δημοσίευσης Institutional AI Strategy. Εφόσον υπάγεται, να καθοριστούν το ελάχιστο περιεχόμενο, η διαδικασία εκπόνησης και έγκρισης, η αρμόδια αρχή, το χρονοδιάγραμμα και η σχέση της στρατηγικής με τον υφιστάμενο στρατηγικό σχεδιασμό και την εταιρική διακυβέρνηση της ΑνΑΔ. Να αποσαφηνιστεί επίσης η διάκριση και η σχέση μεταξύ Institutional AI Strategy, Applied AI Strategy και AI adoption plan, καθώς και η προβλεπόμενη συχνότητα επικαιροποίησης κάθε εγγράφου, δεδομένων των διαφορετικών σχετικών αναφορών στη Στρατηγική. 11. AI Champion και AI Officer Στη σελίδα 22 της Στρατηγικής προβλέπεται ο διορισμός AI Champions από κάθε υπουργείο, ενώ στις σελίδες 26–27 και 91–92 προβλέπεται ο ορισμός AI Officers σε υπουργεία και καθορισμένους οργανισμούς του δημόσιου τομέα. Να επιβεβαιωθεί ότι δεν χρειάζεται ο ορισμός AI Champion από την ΑνΑΔ. Να αποσαφηνιστεί η διαδικασία ορισμού ή παροχής του AI Officer, και να διευκρινιστεί ο ρόλος και η γραμμή αναφοράς των εμπλεκομένων μερών. 12. Συμμετοχή της ΑνΑΔ σε όργανο δεοντολογίας της ΤΝ Αφορά τις σελίδες 22, 24 και 56 της Στρατηγικής. Να αποσαφηνιστεί αν το National Ethics and Values Committee και το council focused on AI ethics στο οποίο προβλέπεται συμμετοχή της ΑνΑΔ αφορούν στο ίδιο όργανο. Σε περίπτωση διαφορετικών οργάνων, να προσδιοριστούν με συνέπεια η ονομασία, η σύνθεση, οι αρμοδιότητες, οι γραμμές αναφοράς και η μεταξύ τους σχέση. Να διευκρινιστεί επίσης ο συγκεκριμένος ρόλος, οι υποχρεώσεις και ο τρόπος εκπροσώπησης της ΑνΑΔ σε οποιοδήποτε από τα όργανα αυτά προβλέπεται να συμμετέχει. Η ΑνΑΔ σημειώνεται ως Human Resources Development Authority. Παρακαλώ να τροποποιηθεί σε Human Resource Development Authority of Cyprus. 13. Εθνική υποδομή ΤΝ και υφιστάμενα συστήματα της ΑνΑΔ Αφορά τις σελίδες 38-39, και 61-62 της Στρατηγικής. Να αποσαφηνιστεί το πεδίο εφαρμογής της προβλεπόμενης εθνικής υποδομής ΤΝ και των κοινών υπηρεσιών φιλοξενίας για δημόσιους οργανισμούς που διαθέτουν υφιστάμενες υποδομές και κρίσιμα πληροφοριακά συστήματα. Να καθοριστούν τα κριτήρια βάσει των οποίων μια υπηρεσία θα εντάσσεται σε κεντρική υποδομή ή θα μπορεί να διατηρείται σε υφιστάμενο περιβάλλον, λαμβάνοντας υπόψη την ασφάλεια, την επιχειρησιακή συνέχεια, την τεχνική συμβατότητα, το κόστος και τις κανονιστικές απαιτήσεις. Για τυχόν μετάβαση να καθοριστούν το χρονοδιάγραμμα, η χρηματοδότηση και οι ευθύνες λειτουργίας, αντιγράφων ασφαλείας, ανάκαμψης, ενημερώσεων, παρακολούθησης και αντιμετώπισης περιστατικών. Να μην θεωρείται δεδομένη η μεταφορά υφιστάμενων συστημάτων χωρίς προηγούμενη τεχνική και οικονομική αξιολόγηση." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",Kokk1reb,"ΕΙΣΗΓΗΣΕΙΣ ΓΕΝΙΚΟΥ ΧΗΜΕΙΟΥ ΤΟΥ ΚΡΑΤΟΥΣ (ΓΧΚ): PROPOSED COMMENTS BY THE STATE GENERAL LABORATORY (SGL) COMMENT 1 Article / paragraph Section 2.4.1 – Priority Sectors for Leadership: Healthcare and Life Sciences Annex C – Healthcare and Life Sciences Comment / Recommendation The Healthcare and Life Sciences pillar should explicitly recognize the role of Public Health Laboratories and laboratory intelligence as an integral component of AI-enabled healthcare and public health. The Strategy should include: “AI-supported laboratory analytics for food safety, environmental monitoring, toxicology and chemical risk assessment.” Justification The Strategy appropriately identifies Healthcare and Life Sciences as a priority sector and focuses on clinical decision-making, preventive care, health data and healthcare system optimization. However, the laboratory dimension of public health is not sufficiently reflected. The SGL is a key national scientific and laboratory institution supporting public health through laboratory surveillance and analytical activities in areas including food safety, environmental health, drinking water quality, chemical hazards and toxicology. AI-supported laboratory analytics could enhance the interpretation of complex analytical datasets, support early identification of emerging hazards and strengthen evidence-based public health decision-making." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","CYPRUS COMPUTER SOCIETY","INTRODUCTION The Cyprus Computer Society (CCS) welcomes the publication of the National AI Strategy 2032 and considers it an important and necessary step for Cyprus to move forward in a coordinated and responsible way in the field of Artificial Intelligence. A clear national strategy is essential for creating a common direction, supporting investment and innovation, strengthening public-sector capabilities, and ensuring that AI developments deliver meaningful benefits for the economy and society. Recognising the strategic importance of Artificial Intelligence for Cyprus, and with full respect for the extensive work undertaken by the competent authorities, and in response to the call for public consultation, we are pleased to contribute the following comments and suggestions, with the aim of further supporting the implementation as well as the practical delivery of the Strategy. The comments below are offered in a constructive spirit and acknowledge that, in most cases, the National AI Strategy already includes the relevant principle or refers to the issue concerned. The National AI Strategy already sets out governance structures, control gates, data governance, infrastructure planning, skills development and measurement arrangements at a strategic level. Therefore, they should be viewed as suggestions for further consideration, rather than observations that these subjects are absent. The purpose of the comments is more specific: to consider how the National AI Strategy can support and ensure effective implementation of the principles it sets out. Hence, rather than proposing new directions or changes to the National AI Strategy’s priorities, our comments focus on the operational detail that can determine whether a strategy is effectively delivered. This is particularly important for AI initiatives, which depend on sustained funding, good data, capable public organisations and effective management of external suppliers. A project may be legally compliant and technically sound, yet still be delayed, exceed its budget or fail to deliver the expected benefits. The comments therefore address areas such as project-delivery assurance, requirements and user acceptance, change control, lifecycle costs, benefits realisation and the organisational capability required to act as effective owners of AI initiatives. The comments are therefore intended as practical refinements to strengthen implementation and help ensure that the National AI Strategy’s principles lead to tangible results for citizens, public administration and the wider economy. STRATEGIC PERSPECTIVE The Cyprus National AI Strategy 2032 provides a strong and ambitious foundation for positioning Cyprus as a trusted and competitive participant in the European AI ecosystem. Its breadth, focus on sovereignty and infrastructure, commitment to responsible AI and alignment with European requirements provide a solid basis for implementation. To maximise its impact, the Strategy could benefit from clear prioritisation and a focused implementation approach, reflecting Cyprus’s particular strengths, capabilities and opportunities. A compelling strategic positioning could be: “Cyprus: Europe’s trusted AI gateway to the Eastern Mediterranean.” This could be supported by focusing on • AI deployment, • AI assurance, • regulated experimentation, • sectoral AI, • European market access and • regional connectivity, while at the same time leveraging European partnerships and infrastructure. The success of the Strategy should ultimately be reflected not only in initiatives established by 2032, but in • measurable productivity gains, • better public services, • a stronger AI workforce, • successful AI companies, • increased AI exports, • recognised research and • trusted AI deployment. In short: Cyprus has an opportunity to build on a strong AI strategy by sharpening its priorities and focusing implementation where the country can create the greatest value. Comments and Suggestions 1. Multi-year and sustainable funding The National AI Strategy could give more detail on the financial arrangements needed to support its implementation over the longer term. In particular, it would be useful to have clearer information on how funding for major initiatives will continue after the initial implementation phase and how this funding will be linked to agreed priorities and delivery milestones. Reference in Strategy: §1.4.9 Sustainability and Economic Model, p.6, where the Strategy refers to “Multi-year investment with clear ROI tracking”; and §3.10.3 Funding and Renewal Model, p.44, which refers to a multi-year renewal cycle and predictable capacity. 2. Project-level milestones and completion criteria In addition to the high-level implementation periods set out in the National AI Strategy, consideration could be given to having more detailed implementation plans for important initiatives. These could include key milestones, expected deliverables, dependencies and target completion dates, together with clear and measurable criteria for deciding whether each stage of a project has been successfully completed. Reference in Strategy: §1.5 Implementation Timeline and Success Metrics, p.6, which sets out the general 0–8 month, 6–12 month, 12–24 month and 2026–2032 periods. Also §3.3.2 Control Framework, p.27, which establishes approval gates throughout the lifecycle. 3. Reporting, coordination, escalation and corrective action The National AI Strategy could further specify the operational mechanism through which progress reporting, cross-government coordination and accountability will function in practice, particularly for significant or cross-government initiatives. This could include defined reporting responsibilities, reporting frequency, escalation thresholds, procedures for resolving implementation bottlenecks, and the circumstances under which corrective action or intervention is required. Reference in Strategy: §3.3.1 Governance Structure, pp.23–25, which establishes the National AI Authority, Interministerial AI Council and related governance bodies; and §3.11.3 Monitoring and Reporting, p.45, which provides for regular KPI monitoring and corrective action. 4. Formal project-delivery assurance For major public-sector AI initiatives, consideration could also be given to having a formal project-delivery assurance process at key stages of implementation. This would complement the National AI Strategy’s existing governance and risk controls and would provide a more specific check that projects remain within their agreed scope, budget and timetable, that key risks and dependencies are being managed, and that they are ready to move to the next stage. This would help ensure that approval gates consider not only AI-related risks, but also the overall progress and viability of the project. Reference in Strategy: §3.3.2 Control Framework, p.27, which establishes lifecycle controls and approval gates; and Annex B, AI Use Case Lifecycle and Control Gates, pp.57–59. 5. Requirements and user acceptance For significant public-sector AI initiatives, it would be useful to ensure that the business and user requirements are clearly defined before procurement or development starts, together with appropriate acceptance criteria. The intended users should also have a meaningful role during design, testing and acceptance, so that the solution being implemented meets the needs for which it was originally intended. Reference in Strategy: §3.4.2 Use Case Driven Approach, p.28, which requires the problem to be defined before selecting a solution; §3.4.5 Capacity Building and Change Management, p.29; and Annex B, Stage 2 and Stage 3, pp.58–59, concerning design, testing and deployment readiness. 6. Formal change-control mechanism The National AI Strategy could give more detail on how significant changes to an AI project should be managed during implementation. Changes affecting the scope, requirements, cost, timetable or expected benefits could be documented and assessed before they are submitted for approval at the appropriate level. Significant changes could also trigger a further review where necessary. Reference in Strategy: §3.3.2 Control Framework, p.27, which requires approval gates before “material modifications” to AI systems; and Annex B, Stage 5, p.59, which provides for adaptation or modification during the lifecycle. 7. Independent assurance at major gates For major or high-value public-sector AI initiatives, consideration could be given to obtaining independent assurance at key stages of the project lifecycle, especially before procurement, major commitments of resources, deployment and later scaling. The level of such assurance could be based on the financial, operational and wider importance of the initiative. Reference in Strategy: §3.3 Governance and Controls, p.21, which refers to internal or external assurance; and Annex B, pp.57–59, which establishes the lifecycle control gates. 8. Strengthening the “intelligent client” capability The National AI Strategy could place more emphasis on the capabilities that public bodies need in order to act as effective and informed owners of AI initiatives. This includes not only understanding the technology, but also being able to define requirements, manage procurement and contracts, oversee suppliers, be actively and effectively involved in testing and acceptance and keep accountability within the public organisation even when implementation is outsourced. Reference in Strategy: §2.2.4 Skills and Organisational Readiness, p.10, which states that some public organisations lack the internal capability to identify, procure and manage AI systems; and §3.6.3 Public-Sector Capability, p.37, which requires public servants to commission, evaluate and manage AI systems, including where outsourced. 9. Procurement and contract-management capability Given the likely use of external technology providers and implementation partners for a significant part of AI adoption, the Strategy could give more attention to the capabilities needed to manage these relationships effectively. This could include preparing suitable technical specifications, setting clear and measurable deliverables, having appropriate acceptance arrangements, monitoring supplier performance, ensuring knowledge transfer and making sure that the public body keeps enough control over the system throughout its lifecycle. Reference in Strategy: §3.4.1 Priority Areas for Government Adoption, p.32, which refers to the transition toward AI-first procurement models; §3.3.2 Control Framework, p.27, concerning procurement and delivery partners; and Objective 8, §2.5.8, pp.17–18, concerning partnerships, knowledge transfer, interoperability and portability. 10. Total lifecycle cost, not only implementation cost The National AI Strategy could place more emphasis on considering the total cost of an AI initiative over its full lifecycle, rather than focusing mainly on the initial investment. This should include, where relevant, the costs of implementation and integration, infrastructure, licences, support and maintenance, future upgrades, skills, and eventual replacement or decommissioning. Reference in Strategy: §3.10 Sustainability and Economic Model, p.44, which addresses financial resilience and multi-year renewal; and Annex B, Stage 5, p.59, which includes adaptation and decommissioning. 11. Explicit benefits-realisation and stop/continue decisions The National AI Strategy could place more emphasis on checking whether the expected benefits of significant AI initiatives are actually being achieved. It would be useful for the expected benefits to be identified at the beginning, with a baseline where possible, so that progress can later be measured. If an initiative is not delivering the expected results, or if its cost, risks or performance have changed significantly, there should be a clear process for deciding whether corrective action is enough or whether the initiative should be modified, reduced or brought to an end. Reference in Strategy: §3.11.1–3.11.4 Outcomes-Focused Measurement, National KPIs, Monitoring and Reporting, Learning and Continuous Development, pp.44–45; and Annex B, Stage 4–5, pp.59–60. 12. Skills and organisational capability The National AI Strategy could provide more detail on the organisational and professional capabilities that public-sector organisations will need for the effective adoption and management of AI. This should go beyond general AI awareness and technical skills and include the ability to define needs and requirements, assess and select solutions, manage procurement and implementation, oversee external providers, and assess the performance and risks of AI systems throughout their lifecycle. Reference in Strategy: §2.2.4 Skills and Organisational Readiness, p.10, which notes that some public-sector organisations lack the internal capability to identify, procure and manage AI systems; and §3.6.3 Public-Sector Capability, p.37, which refers to the ability of public servants to commission, evaluate and manage AI systems, including where these are outsourced. 13. AI infrastructure capacity, scalability and sustainability Given the National AI Strategy’s ambition to develop sovereign and scalable AI capabilities in Cyprus, it could give more attention to the longer-term capacity, scalability, resilience and sustainability of the national AI infrastructure that will be needed. For major initiatives such as G-Cloud and national AI compute and data capabilities, it would be useful to consider from the beginning the expected capacity requirements, the ability to scale, key dependencies, lifecycle and renewal requirements, and how infrastructure investment will remain aligned with future public-sector and national AI needs. Reference in Strategy: §3.7 Infrastructure, Compute and Digital Sovereignty, p.38, which identifies infrastructure as a foundational prerequisite for AI adoption and states that Cyprus currently lacks a National AI Infrastructure capable of supporting its long-term AI ambitions. It also sets out requirements concerning secure storage, processing capacity, connectivity, secure deployment environments and access to advanced computing resources. In addition, §3.3.1.4 National AI Infrastructure Committee, p.24, assigns responsibility for strategic oversight of national AI compute resources, infrastructure sustainability, operational performance and related economic models. The Strategy also specifically states, in its implementation section, p.39, that Cyprus is currently in the procurement process for G-Cloud and identifies concrete early deliverables and milestones for its implementation. 14. Data governance, quality and readiness The National AI Strategy could give more attention to the practical requirements for ensuring that data is ready to support significant AI initiatives. This could include clear responsibility for data ownership and quality, common standards and definitions, interoperability between systems, appropriate arrangements for secure data sharing, and checks that the required data is available and fit for purpose before major AI initiatives move into implementation. Reference in Strategy: §3.2 Data as a Strategic National Asset (p.19); §3.2.2 Data Governance and Stewardship (p.20); §3.2.3 Interoperability and Secure Data Sharing (p.20); §3.2.4 Data by Design in Public Systems (p.20). 15. Prioritisation of AI Adoption in Sectors of Existing National Strength The National AI Strategy appropriately identifies a number of priority sectors in which Cyprus already has established economic activity, institutional capacity and comparative advantages. These include public administration, financial services, healthcare, tourism, legal services, education, shipping and entrepreneurship. This approach is considered appropriate for a small, services-oriented economy. Rather than dispersing limited financial, institutional and human resources across a broad range of sectors, Cyprus should prioritise areas where there is already sufficient sectoral expertise, market demand, data availability and potential for measurable economic or public-sector impact. A comparable approach can be identified in Singapore’s National AI Strategy 2.0. Singapore does not seek to develop leadership across all possible areas of artificial intelligence. Instead, it concentrates national efforts around defined strategic priorities, including government, industry, research, talent and computing infrastructure, while supporting selected areas and centres of excellence. It is therefore recommended that the National AI Strategy retain this sectoral prioritisation and strengthen it through a clear implementation framework. For each priority sector, the Strategy should identify specific AI use cases, measurable objectives, responsible authorities, implementation timelines, required investment and expected outcomes. This would help ensure that sectoral prioritisation moves beyond a general statement of intent and becomes a practical mechanism for allocating resources, coordinating implementation and assessing results. Reference: Singapore National AI Strategy 2.0, Smart Nation Singapore. https://www.smartnation.gov.sg/initiatives/national-ai-strategy/ Reference in strategy: § 1.2 The National Strategic Objectives and Priority Sectors p.2 16. Treat Data Architecture as Core National AI Infrastructure The National AI Strategy correctly identifies data fragmentation as one of the main structural barriers to effective AI adoption in Cyprus. The proposed approach is particularly important. The Strategy refers to federated data architecture, secure APIs, standardised metadata, sectoral data spaces and controlled access mechanisms, rather than relying on unnecessary centralisation of government and sectoral data. This should be considered a core strength of the Strategy. Effective AI systems depend on reliable, interoperable and accessible data. Without common standards, secure data exchange mechanisms and clear governance arrangements, investment in individual AI applications is likely to produce fragmented results and limited scalability. Estonia provides a useful international benchmark. Its AI development builds on an already highly integrated digital-state infrastructure. The Estonian Information System Authority, RIA, operates Bürokratt and continues to develop secure infrastructure that supports AI assistants and digital public services across government. Cyprus should therefore treat data architecture as a strategic infrastructure priority rather than as a supporting technical issue. The implementation of the National AI Strategy should include clear interoperability standards, common metadata requirements, secure API frameworks, data governance responsibilities and measurable targets for connecting priority public-sector datasets and systems. This would create the technical foundation required for AI systems to operate across government and would reduce the risk of developing isolated applications that cannot communicate, share data securely or scale across institutions. Reference: Estonian Information System Authority, Artificial Intelligence. https://ria.ee/en/state-information-system/artificial-intelligence Reference in strategy: § 3.2 Data as a Strategic National Asset p.19 17. Adopt a “Build Once, Reuse Across Government” Approach The National AI Strategy’s proposal to develop shared national AI services and reusable capabilities across ministries is one of its stronger operational elements. Rather than allowing individual ministries and public authorities to procure similar AI tools independently, the Strategy promotes the development of common capabilities that can be deployed and reused across government. This approach can reduce duplication, lower procurement and maintenance costs, improve interoperability and support more consistent standards for security, data governance and system performance. The United Kingdom provides a relevant international comparison. Its AI Opportunities Action Plan includes recommendations for greater infrastructure interoperability, code reusability and the development of a scalable government AI technology stack. These recommendations reflect the broader principle that common digital and AI infrastructure can support faster and more coordinated adoption across the public sector. It is therefore recommended that Cyprus formalise the “build once, reuse across government” principle as a core implementation requirement of the National AI Strategy. Shared components should be developed for capabilities that are common across ministries, including AI assistants, document processing, language technologies, data access services and other horizontal functions. The implementation framework should also define which authority will own and maintain these shared services, how ministries will access them and under what circumstances separate procurement will be permitted. This approach would reduce fragmentation and help ensure that public investment in AI creates reusable national infrastructure rather than a series of isolated departmental systems. Reference: UK Government, AI Opportunities Action Plan: Government Response, Recommendations 41 and 42. https://www.gov.uk/government/publications/ai-opportunities-action-plan-government-response/ai-opportunities-action-plan-government-response Reference in strategy: § 3.5 Priority Sectors p.29 18. Introduce a Consolidated and Costed National AI Implementation Plan The National AI Strategy does not currently provide a consolidated estimate of the financial resources required for implementation. The Strategy states that budget allocations should be aligned with performance objectives, but it does not present an overall national AI budget or a costed implementation framework covering the main programmes, infrastructure investments and institutional responsibilities. This gap is also visible in the section on sovereign AI infrastructure, where the Strategy proposes the development of a roadmap, governance model and funding plan. This indicates that important elements of the financing framework remain to be defined after the Strategy is adopted. International examples show the value of linking strategic ambitions to clearly identified funding commitments. Singapore’s National AI Strategy 2.0 includes concrete programme-level funding, including the S$150 million Enterprise Compute Initiative. France has also linked its AI ambitions to substantial infrastructure investment commitments, including €109 billion announced in 2025. These figures are not directly comparable with Cyprus and should not be treated as benchmarks for the level of expenditure required. The relevant lesson is that a national AI strategy should provide greater clarity on the expected cost of its ambitions and on how those costs will be financed. It is therefore recommended that Cyprus publish a consolidated, costed implementation plan alongside the National AI Strategy. This should include estimated capital and operating expenditure, funding sources, expected EU and national contributions, procurement timelines and indicative expenditure by major programme or strategic pillar. A costed implementation plan would make the Strategy more credible, improve accountability and allow government, Parliament and the public to assess whether the resources committed are proportionate to the stated objectives. References: Singapore, National AI Strategy 2.0, Smart Nation Singapore. https://www.smartnation.gov.sg/initiatives/national-ai-strategy France, AI Action Summit and AI-related investment commitments, Élysée, 2025. https://www.elysee.fr/admin/upload/default/0001/18/6cd9e17ec44a1c92e099626f065781cf69fa394e.pdf Reference in strategy: § 3.3.1 Governance Structure p.22 & 3.7.3 Digital Sovereignty and Strategic Autonomy, p. 39 19. Simplify the Governance Structure and Clarify Accountability The National AI Strategy establishes a broad governance architecture involving several categories of bodies, in addition to ministry-level responsibilities. While the Strategy assigns roles across these structures, the number of institutions and interfaces involved could create overlapping responsibilities and slow implementation. The proposed model gives the central Authority a coordinating and gatekeeping role, while ministries retain operational responsibility. At the same time, the Taskforce has a separate role in monitoring implementation. This creates multiple points of interaction between policy coordination, operational delivery, oversight and performance monitoring. The concern is therefore not that responsibilities are entirely undefined. The main risk is that a complex governance structure may create uncertainty over who is ultimately accountable for decisions, delays, budget execution and delivery outcomes. Singapore provides a useful international comparison. Its national AI governance model has moved toward stronger top-level coordination, including the establishment of a National AI Council chaired by the Prime Minister. This reflects an effort to strengthen strategic direction and decision-making at the highest level. It is therefore recommended that Cyprus review whether all proposed governance bodies are necessary and clearly distinguish between strategic oversight, regulatory functions, implementation responsibility and performance monitoring. The final governance framework should identify one clearly accountable authority for overall delivery, define escalation mechanisms for unresolved issues and minimise duplication between coordinating and monitoring bodies. A simple responsibility matrix should also specify which institution is accountable, responsible, consulted and informed for each major action. This would reduce execution risk and help ensure that governance arrangements support implementation rather than adding further administrative complexity. Some critical unanswered questions are: • Who ultimately owns delivery? • Who controls the implementation budget? • Who can stop an underperforming project? • Who is accountable for missed KPIs? • How are conflicts between ministries resolved? Reference: Singapore, National AI Strategy 2.0, Smart Nation Singapore. https://www.smartnation.gov.sg/initiatives/national-ai-strategy/ Reference in strategy: § 3.3.1 Governance Structure p.22 20. Replace the “Three Unicorns” Target with Broader Economic Impact Indicators The National AI Strategy identifies the creation or attraction of “three unicorns” as one of the objectives associated with the proposed AI Innovation Fund. While this provides a visible ambition for the development of the AI ecosystem, unicorn creation should not be treated as a primary indicator of economic success. A unicorn valuation is primarily the result of private financing rounds and investor expectations. It does not necessarily demonstrate that a company has generated sustainable revenues, created high-productivity employment, developed intellectual property in Cyprus or contributed significantly to exports and the wider economy. For this reason, the Strategy should place greater emphasis on measurable indicators of underlying economic activity and value creation. These could include AI-related exports, revenue generated by supported companies, intellectual property developed and retained in Cyprus, private follow-on investment, the number and quality of high-productivity jobs created, research commercialisation and the proportion of supported companies that successfully scale into international markets. The objective should not necessarily be to remove ambition around developing globally competitive technology companies. Rather, the success of the AI Innovation Fund should be assessed through a broader set of economic indicators that measure whether public support is creating sustainable economic value in Cyprus. It is therefore recommended that the “three unicorns” target be treated as a secondary ambition rather than a core economic KPI and that the Strategy introduce a balanced set of measurable indicators covering company growth, exports, intellectual property, private investment and employment. This would provide a more meaningful basis for evaluating whether public investment in the AI ecosystem is producing sustainable economic outcomes. Reference in strategy: § 5. Immediate Steps for the Strategy Launch p.50 21. Strengthen Demand-Side Support Through Public Procurement The National AI Strategy includes a broad range of measures to support startups and scaleups, including access to funding, computing infrastructure, regulatory sandboxes, testbeds and other support mechanisms. These measures are important, but they remain largely supply-side in nature. They focus on helping companies build products, access infrastructure and navigate regulation. Less emphasis is placed on creating domestic demand for those products and helping innovative companies secure their first significant customers. The United Kingdom’s AI Opportunities Action Plan provides a useful comparison. It places greater emphasis on the role of the state as a customer of AI solutions, including procurement reform and the use of government purchasing power to support innovation and shape emerging AI markets. For Cyprus, this could be particularly relevant. A small domestic market can make it difficult for startups to secure early reference customers, validate products at scale and demonstrate commercial traction before expanding internationally. It is therefore recommended that the National AI Strategy complement existing startup support measures with a stronger demand-side policy. This should include mechanisms that make it easier for ministries and public authorities to procure innovative AI solutions from startups and SMEs, launch challenge-based procurement programmes, conduct structured pilots with clear pathways to production, and create opportunities for successful solutions to scale across government. The objective should not be to add further incubators or support programmes alone, but to create a functioning market in which innovative companies can sell, deploy and scale their solutions. A stronger procurement and demand-side approach would improve the commercial impact of public support and help convert innovation funding into revenues, reference customers, exports and sustainable company growth. References: UK Government, AI Opportunities Action Plan. https://www.gov.uk/government/publications/ai-opportunities-action-plan/ai-opportunities-action-plan UK Government, AI Opportunities Action Plan: Government Response. https://www.gov.uk/government/publications/ai-opportunities-action-plan-government-response/ai-opportunities-action-plan-government-response Reference in strategy: § 3.8 Research, Innovation and Ecosystem Development p.40 22. Differentiate the “3,000 AI Professionals” Target by Skill Category The National AI Strategy sets a target of approximately 3,000 AI professionals and includes within this figure a wide range of occupational categories, such as AI engineers, data scientists, no-code developers, prompt engineers and certified specialists. While the ambition to expand Cyprus’ AI talent base is positive, a single headline target risks combining substantially different levels and types of capability. Frontier technical skills, applied AI engineering, data science, no-code development and general AI proficiency serve different economic and institutional needs and should not be treated as equivalent. The United Kingdom’s AI Opportunities Action Plan places emphasis on first developing an accurate assessment of the national AI skills gap before designing interventions. This reflects the importance of understanding which specific skills are scarce, in which sectors, and at what level of technical depth. Finland also provides a useful reference through an approach that links skills development with industrial adoption and measurable implementation indicators. This allows talent policy to be connected more directly to the needs of the economy rather than being assessed only through aggregate participation numbers. It is therefore recommended that Cyprus replace or supplement the headline target of 3,000 AI professionals with a more detailed skills framework. This should distinguish between advanced AI researchers, machine learning and AI engineers, data professionals, applied AI specialists, sector-specific practitioners and broader AI-literate professionals. The Strategy should also define how each category will be measured, the expected demand from the public and private sectors, and the education, reskilling or talent-attraction mechanisms required to address identified shortages. This would provide a more accurate picture of Cyprus’ AI capacity and reduce the risk that a quantitative target is achieved without addressing the most important technical and sectoral skills gaps. References: UK Government, AI Opportunities Action Plan. https://www.gov.uk/government/publications/ai-opportunities-action-plan/ai-opportunities-action-plan Finland, national AI and digital policy programme. https://julkaisut.valtioneuvosto.fi/items/24932639-b776-45a1-85ad-9c084726b0d9/full Reference in strategy: § 2.5.2 Objective 2: Increase national productivity through responsible AI adoption p.16 23. Measurement and Benefits-Realisation Gap The CNAI Strategy contains ambitious targets, including AI adoption, productivity, GDP impact, skills and citizen-service improvements. The challenge is attribution. For example, productivity improvements cannot automatically be attributed to AI. The CNAI Strategy therefore needs a stronger distinction between: Inputs → Activities → Outputs → Outcomes → Economic/Societal Impact. Every major AI programme should have: • baseline; • quantified target; • responsible owner; • deadline; • data source; • evaluation methodology; • benefits-realisation plan. Cyprus needs an independent National AI Observatory and Impact Dashboard. Reference in strategy: § 3.11.1 Outcomes-Focused Measurement) (Annex F – National KPIs and Measurement Framework (sample) 24. AI Adoption Versus Transformation The CNAI Strategy correctly recognises the danger of fragmented pilots and emphasises scaling proven use cases. Nevertheless, the number of proposed initiatives is substantial. Cyprus should avoid measuring success by: • number of pilots + number of programmes + number of trained people. The real measurement should be: • economic value + public-service improvement + productivity + exports + research commercialisation + citizen benefit. Every major project should therefore pass through a common: • Business Case → Risk Assessment → Pilot → Independent Evaluation → Scale / Stop process. 25. Public Procurement and Vendor Dependency The CNAI Strategy appropriately promotes common platforms and reusable AI services. It also envisages shared government AI capabilities and a G-Cloud foundation. However, procurement needs to become an explicit AI industrial-policy instrument. Cyprus should use government demand to: • stimulate local AI companies; • create first customers; • encourage European solutions; • avoid vendor lock-in; • require interoperability and portability. The Strategy should therefore establish a National AI Procurement Framework covering model portability, data portability, open standards, cybersecurity, auditability and supplier exit strategies. Reference in strategy: § 3.7.3 Digital Sovereignty and Strategic Autonomy p.39 & 3.4.1 Priority Areas for Government Adoption p.28 26. Foundation Models, Generative AI and AI Agents The Strategy recognises generative and agentic AI, but these technologies deserve a dedicated governance framework rather than scattered references throughout the document (indicatively in sections: Tourism and Hospitality Pillar - What this pillar is expected to deliver, 5. Legal Services, Legal Services Pillar - What this pillar is expected to deliver) Cyprus needs clear national policies for: • government use of LLMs; • confidential government information; • AI agents capable of taking actions; • hallucination and reliability; • model evaluation; • open-source versus commercial models; • copyright; • synthetic content; • deepfakes; • human oversight. This is particularly urgent because Article 50 transparency requirements are now applicable from 2 August 2026. Providers and deployers must meet specified transparency requirements concerning AI interaction and AI-generated or manipulated content. Reference: https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content 27. EU AI Act: Alignment Versus Operational Readiness The CNAI Strategy explicitly commits Cyprus to EU AI Act compliance and proposes a National AI Compliance Framework. This is a significant strength. However, there is an important distinction between: • strategic alignment and operational regulatory readiness. Cyprus must ensure that its national framework can actually support: • market surveillance; • conformity assessment; • regulatory sandboxes; • incident reporting; • AI literacy; • fundamental-rights safeguards; • high-risk AI governance; • transparency obligations; • GPAI coordination; • enforcement. The EU framework is now moving from preparation to implementation, with governance and GPAI requirements already applicable and transparency obligations commencing in August 2026. Cyprus should establish a dedicated AI Act Implementation Programme rather than treating compliance primarily as a strategic principle. Reference in strategy: § 2.3.3 Alignment with European Frameworks p.12 28. Human-Centred AI: Equality, Literacy and Skills for All Enforce Algorithmic Gender-Bias Auditing: Require all state-deployed or state-procured AI systems to undergo a mandatory ""Gender Equality Impact Assessment"" to ensure public algorithms do not perpetuate systemic demographic bias. Users – citizens can have an involvement into this by reporting potential biased behavior of in use AI systems. Launch ""AI Literacy for All"" Community Workshops: Partner with local municipalities and community centers to run free, non-technical evening/hybrid workshops explaining how everyday AI tools work, data privacy rights, and how to spot AI-generated deepfakes. Integrate AI Literacy into the elderly Program: Expand existing state programs for senior citizens to include accessible modules on navigating AI-driven public services (e.g., Cyprus Government Gateway /gov.cy) to prevent the digital exclusion of the elderly. Incorporate AI Ethics into School Curriculums: Mandate the Ministry of Education to introduce basic AI literacy, algorithmic bias awareness, and prompt engineering into the standard public school curriculum starting from Primary school. This can also be used for encouraging the involvement of female students and students coming from vulnerable backgrounds in tech fields. Fund ""AI Transition Scholarships"" for At-Risk Workers: Direct specific funding from the EU Just Transition Fund to create fast-track technical and semi-technical AI training paths for workers in retail, tourism, and hospitality sectors with high female and youth employment that face imminent automation. Provide ""Return-to-Work"" AI Bootcamps: Create fully subsidized, flexible AI data annotation, project management, and basic programming bootcamps specifically designed for parents returning to the workforce after long-term parental leave. 29. Integration of Gender-Disaggregated Data Collection and Bias Auditing in AI Governance The National AI Strategy places appropriate emphasis on fairness, non-discrimination and compliance with the EU AI Act. It also assigns an important role to the National Ethics and Values Committee and the wider governance and control framework. However, the Strategy does not define sufficiently specific operational mechanisms for identifying and mitigating gender and demographic bias in AI systems. This is particularly relevant where training datasets may reflect historical inequalities, occupational segregation or the under-representation of specific population groups. It is therefore recommended that the National Ethics and Values Committee, in coordination with the National AI Authority, establish a standardised Algorithmic Impact Assessment framework for AI systems developed, deployed or procured by the public sector. These assessments should explicitly examine gender and demographic bias before deployment and, where appropriate, throughout the lifecycle of the system. They should include reviews of training data, model outputs, error rates and differential impacts across relevant population groups. The Strategy should also require the systematic collection and reporting of gender-disaggregated indicators in publicly funded AI research, development and deployment. This would align implementation with Action 10.2 of the National Strategy for Gender Equality 2024–2026 and provide measurable evidence on whether AI policies are contributing to, or potentially reinforcing, existing inequalities. This would strengthen the Strategy’s existing commitments on fairness by translating high-level ethical principles into clear and auditable implementation requirements. References: Cyprus National Strategy for Gender Equality 2024–2026, Action 10.2. Reference in strategy: § 3.3, “Governance and Controls”, including Section 3.3.1.5, “National Ethics and Values Committee”, and Section 3.3.2, “Control Framework”. p.21-27 & 3.9.4, “Fairness and Non-Discrimination” p. 42-43 30. Gender-Responsive Target Setting and Intersectional Inclusion in Workforce Transformation (FutureAI CY) The National AI Strategy places significant emphasis on talent development, workforce transformation and the creation of approximately 3,000 AI professionals. The FutureAI CY flagship programme is intended to support this objective through stackable micro-credentials and structured upskilling pathways. However, the current framework does not appear to include specific gender or inclusion targets for participation. This creates a risk that existing inequalities in STEM education and employment could be reproduced within the emerging AI workforce, particularly if participation is measured only through aggregate training numbers. It is therefore recommended that the FutureAI CY programme introduce clear participation targets for women across its six priority tiers. A minimum participation threshold, for example 40–50%, could be considered, with particular emphasis on women returning to the labour market and female graduates from non-technical disciplines who could transition into applied AI roles. The National AI Strategy should also provide dedicated and fully or partially subsidised training pathways for groups that may face additional barriers to participation, including women in rural areas, single mothers and women with disabilities. Flexible delivery models, including evening, hybrid and remote learning options, should form part of this approach. These measures would be consistent with Actions 2.6 and 10.1 of the National Strategy for Gender Equality and with the Second Pillar of the national Disability Strategy. The objective should be to ensure that the expansion of Cyprus’ AI talent base does not simply increase the overall number of trained professionals, but also broadens participation in the digital economy and reduces existing gender and accessibility gaps. References: Cyprus National Strategy for Gender Equality, Actions 2.6 and 10.1. Cyprus National Disability Strategy, Second Pillar. References in strategy: § 3.6, “Talent, Skills and Workforce Transformation” p 36-37, including § 3.6.4, “Workforce Augmentation and Transition”, and § 3.6.5, “Attracting and Retaining AI-related Talent” & Annex C, Flagship Programme: “FutureAI CY” p.80. 31. Digital Accessibility and Universal Design Compliance for Citizen-Facing AI Portals The National AI Strategy places significant emphasis on the use of AI across government, including conversational agents, multilingual access points and the development of the “Digital Citizen 2.0” model. However, the National AI Strategy does not appear to explicitly require that these citizen-facing AI systems comply with accessibility obligations under the European Accessibility Act and relevant national legislation. This creates a risk that new AI-enabled public services could improve efficiency while still leaving barriers for citizens with disabilities. It is therefore recommended that all generative AI tools, automated public-service portals and conversational agents deployed by the public sector be required to follow Universal Design principles and comply with the Accessibility of Products and Services Law implementing Directive (EU) 2019/882. Accessibility requirements should be incorporated from the design and procurement stage rather than treated as an additional feature after deployment. This should include multimodal functionality such as text-to-speech, speech-to-text, high-contrast and keyboard-accessible interfaces, and other assistive technologies appropriate to the needs of citizens with visual, auditory, motor or cognitive impairments. Where technically feasible and validated for accuracy, the National AI Strategy should also support the development of Cyprus Sign Language-enabled interfaces and other language and accessibility technologies relevant to the local population. These requirements should be incorporated into public-sector AI procurement standards, technical specifications and acceptance testing, with accessibility performance assessed before systems are made available to the public. This would ensure that the digital transformation envisioned under “Digital Citizen 2.0” is inclusive by design and consistent with Cyprus’ wider obligations and policies on disability and equal access to public services. References: Directive (EU) 2019/882, European Accessibility Act. Accessibility of Products and Services Law. Cyprus National Action Plan on Disability, Third Pillar, Action 16. References in strategy: § 3.4, “AI Adoption Across Government”, including § 3.4.1, “Priority Areas for Government Adoption” p.28-29, Annex C, “Personalised Citizen Journey – Digital Citizen 2.0” p. 61-62. 32. Gender Mainstreaming in Priority Vertical Sectors (Shipping, FinTech, and Healthcare) The National AI Strategy identifies financial services, healthcare, shipping and maritime among the priority sectors for AI leadership and proposes a range of sector-specific initiatives to accelerate adoption. However, the current sectoral approach could place greater emphasis on how AI adoption may interact with existing gender disparities. This is particularly relevant in traditionally male-dominated sectors such as shipping and FinTech, as well as in healthcare, where historical data gaps may affect the performance of AI-supported diagnosis, triage and treatment. For shipping and financial services, it is recommended that sectoral AI initiatives incorporate measurable gender inclusion indicators alongside technological and productivity objectives. AI Industrial Centres of Excellence could be used not only to develop technical capabilities, but also to support more inclusive talent pipelines, monitor participation by gender and track career progression in AI-augmented maritime and financial technology roles. This approach would be consistent with Actions 14.1 and 14.2 of the National Strategy for Gender Equality and would help ensure that technological transformation does not reinforce existing occupational imbalances. In healthcare and life sciences, the Strategy should explicitly require that national health data infrastructure and AI-supported clinical systems account for sex- and gender-related differences in health outcomes, biomarkers, symptoms and clinical presentation. In particular, the proposed Secure National Health Data Repository and Socratic Scaffolding Diagnostic AI framework should include requirements for representative datasets, disaggregated performance testing and ongoing monitoring for differences in diagnostic accuracy and treatment recommendations across relevant population groups. This would reduce the risk that historical gaps in clinical data are reproduced in AI systems and would strengthen the Strategy’s broader commitments to fairness, safety and non-discrimination. References: Cyprus National Strategy for Gender Equality, Actions 14.1 and 14.2. References in strategy: § 3.5, “Priority Sectors for Leadership” p. 33-36 & Annex C, including initiatives related to Financial Services, Healthcare, Shipping and Maritime p. 64-71 and 82-85. 33. Institutional Representation and Gender Budgeting in National AI Governance The National AI Strategy establishes a multi-layered governance structure through the National AI Authority, the Interministerial AI Council and the National AI Taskforce, alongside a funding and renewal model for implementation. However, the current governance framework does not appear to provide formal representation for national gender equality and disability inclusion mechanisms. The funding model also does not explicitly incorporate gender-responsive budgeting or broader demographic impact assessment. It is therefore recommended that the governance structure include formal representation from the Office of the Commissioner for Gender Equality and the Department for Social Inclusion of Persons with Disabilities, particularly within the Interministerial AI Council and the National AI Taskforce. This would help ensure that equality, accessibility and inclusion considerations are incorporated at the policy-design and implementation stages, rather than being assessed only after AI systems and programmes have already been developed. The Strategy should also apply Gender-Responsive Budgeting principles to multi-year national AI expenditure. Major allocations for AI infrastructure, testbeds, innovation programmes, skills initiatives and public-sector deployment should be assessed not only against technological and economic objectives, but also against their distributional impact across different demographic groups. This approach would be consistent with Actions 1.1 and 1.2 of the National Strategy for Gender Equality and would strengthen accountability over how public AI investment contributes to broader social and economic inclusion. The objective should be to ensure that AI governance and funding decisions reflect both technological priorities and measurable equality outcomes. Reference: Cyprus National Strategy for Gender Equality, Actions 1.1 and 1.2. References in strategy: § 3.3.1, “Governance Structure”, including § 3.3.1.1, “National AI Authority”, § 3.3.1.2, “Interministerial AI Council”, and § 3.3.1.3, “National AI Taskforce” p. 22-26 & § 3.10.3, “Funding and Renewal Model” p.44." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",angus@rexe.ai,"SUBMISSION TO THE PUBLIC CONSULTATION ON THE NATIONAL AI STRATEGY 2032 Submitted by: REXE Technologies Ltd, trading as REXE (Real Estate Exchange Europe), Nicosia Contact: Angus Archer Mason, Founder and Managing Director Date: 31 August 2026 ABOUT THE SUBMITTER REXE Technologies Ltd is building a regulated digital escrow and settlement platform in Cyprus, to be licensed as an Administrative Service Provider regulated by the Cyprus Bar Association and/or CySEC, with client funds held at a systemic Cypriot credit institution as depository of record. The platform is built for property transfers in the first instance and extends to corporate, marine, aviation and other legal settlements. The model is not speculative. REXE is built on the architecture of Property Exchange Australia (PEXA), which carries close to 90 per cent of Australian property settlements, has processed more than twenty million settlements, and in the 2025 financial year settled over one trillion Australian dollars, connecting more than ten thousand legal practitioners with some 160 financial, government and statutory bodies. Australia moved from paper settlement rooms to a national digital rail in roughly a decade. No equivalent rail exists in Cyprus, Greece or most of the European Union. Our positioning is deliberately narrow: infrastructure behind the notary and the advocate. REXE does not practise law and does not hold itself out as a professional adviser. It operates the money rail and the document rail beneath the regulated professional, who retains the legal act and the responsibility for it. Every action with legal or financial effect passes a human approval gate against an append-only approvals ledger. Production infrastructure is hosted in Germany under EU data protection law, while the entity, its licence, its governance and its records remain Cypriot. DECLARATION OF INTEREST The comments below concern the Legal Services pillar, in which we would be a market participant. Comment 1, if adopted, would create opportunities for which we and others would be candidates. We make the comments because we consider the underlying gap material, and we would participate in delivering any of them. COMMENT 1 — ADD TRANSACTIONAL LEGAL SERVICES AND SETTLEMENT TO THE LEGAL SERVICES PILLAR Strategy reference: Section 3.5, Priority Sector (Legal Services), pp. 34 and 74-76; Annex C, Legal Services. Comment / Suggestion: The Legal Services pillar addresses legal information (the Cyprus case-law model, court transcription), legal adjudication (the AI Judge capability) and legal compliance (AIREG, the Digital AML Certification Scheme, NAICF). It does not address legal transactions: conveyancing, property transfer, corporate transactions, and the settlement of funds and title. We recommend that transactional legal services and settlement be added as a named component of the pillar, with its own use case, deliverables and KPIs, and that the pillar's measurable targets include time-to-settlement, registry rejection and rework rates, and cost per transaction. Justification: Property transfer is the highest-volume, most document-bound and most citizen-facing legal process in the Republic. It is also the process in which the largest sums of consumer money move, the process most dependent on multi-registry coordination between the Department of Lands and Surveys, the Tax Department and DRCOR, and the process where administrative error and delay are most visible to the public. It is therefore the strongest candidate in the entire pillar for measurable productivity gain, and the pillar currently omits it. The omission also weakens two of the Strategy's own commitments. Section 3.4.1 commits the government to AI-first procurement principles by 2032 and Section 3.2.5 proposes a National Intelligent Digital API Fabric, but neither is connected to the transaction that would exercise them at volume. And the pillar's flagship proposals — an AI Judge for claims under 5,000 euro, a case-law language model, a blockchain registry — are all downstream of, or adjacent to, disputes. A settlement rail acts upstream, on the transactions that generate disputes when they go wrong. Australia is the available evidence. It did not begin by automating adjudication. It built a settlement rail, and the productivity, fraud-reduction and registry-throughput gains followed from the transaction layer rather than from the courtroom. COMMENT 2 — RECAST THE DIGITAL AML CERTIFICATION SCHEME AROUND THE POINT OF SETTLEMENT Strategy reference: Legal Services pillar, pp. 74-76 (Digital AML Certification Scheme); Financial Services and Financial Technology pillar. Comment / Suggestion: We support the objective behind the Scheme and share the concerns already raised on this consultation that a certificate cannot discharge an obliged entity's own customer due diligence, monitoring, sanctions and reporting duties. We recommend that the Scheme be reframed so that its primary control point is the movement of funds rather than the issuance of a certificate: that is, AML evidence generated, verified and retained at the moment of settlement by a regulated operator that sees both sides of the transaction, rather than a portable credential asserted in advance and relied upon afterwards. Justification: A certificate is a point-in-time assertion that begins going stale the moment it is issued. It creates exactly the reliance risk that other contributors have identified, and it concentrates systemic dependence on whoever issues it. Settlement is a different control point and a better one. At settlement, the source of funds, the destination account, both parties' identities, the consideration and the registry effect are all present simultaneously and are all verifiable. A regulated escrow operator holding client funds at a supervised credit institution sees both sides of every transaction, which is a materially stronger position than dispersed practitioner client accounts, and it produces a contemporaneous, auditable record available to supervisors without a new certification regime. This also addresses a consumer harm the pillar does not currently name. Diverted settlement funds are among the most damaging frauds in any property market: the sums are large, the transfers are irreversible, and they arrive at a moment of trust. A controlled rail with verified account details removes the attack surface that email-based settlement instructions create. No certificate does that. COMMENT 3 — ESTABLISH A LICENSED-ACCESS FRAMEWORK FOR NATIONAL LEGAL AND REGISTRY DATA Strategy reference: Section 3.2 (Data as a Strategic National Asset); Section 3.2.3; Legal Services pillar (Cyprus case-law model; AIREG). Comment / Suggestion: The objective of secure, sovereign and interoperable data will not be achieved by infrastructure alone. It requires a legal framework governing who may train on Cypriot legal and registry corpora, and on what terms. We recommend the Strategy commit to: (a) a national position on text-and-data-mining reservation over public legal and registry data; (b) a licensing regime permitting use by accountable, regulated parties, with verifiable access control and provenance logging; (c) a requirement that outputs derived from such data be attributable and auditable. Justification: Cypriot case law, legislation, professional databases and registry records are a national data asset. At present there is no clear national position on their use as AI training data. Under the EU sui generis database right and the text-and-data-mining reservation available under Directive (EU) 2019/790, Cyprus can assert control over these corpora rather than allow them to be absorbed, unlicensed, into models built elsewhere and sold back into the Cypriot market. This is a data sovereignty measure and a consumer protection one: it ensures legal outputs originate from accountable professionals rather than unlicensed automated substitutes. We note that other contributors have questioned whether AIREG's proposed ledger can establish the ownership and provenance effects claimed for it. We agree, and we would add that the underlying objective is better served here than there. Provenance in legal AI depends on licensed, access-controlled, logged source data — a question of rights and governance — rather than on the architecture of the register that records it. COMMENT 4 — MAKE REGISTRY INTEROPERABILITY OUTWARD-FACING, NOT ONLY INTER-MINISTERIAL Strategy reference: Section 3.2.5 (National Intelligent Digital API Fabric); Section 3.4 (AI Adoption Across Government); Annex C, Government and Public Sector. Comment / Suggestion: We recommend that registry and agency interfaces be specified from the outset as accessible to licensed private operators under defined conditions, not solely to other government departments. Justification: Most transactional value is created at the boundary between the citizen, the regulated professional and the registry. If the Department of Lands and Surveys, the Tax Department and DRCOR expose interoperable, machine-readable interfaces to accountable licensed operators, the private sector will build the citizen-facing productivity layer at no capital cost to the state, and the state retains the standard-setting and supervisory role. If interoperability stops at the ministry wall, the state will be asked to build and maintain that layer itself, on public budget, in competition with private capital that is willing to carry the delivery risk. Two further public benefits follow. Lodgements arriving complete, validated and machine-readable address registry rejection and rework at source, which is the principal cause of registry backlog. And transfer fees, capital gains withholding and stamp duty can be computed on statutory methodology and remitted at the moment funds move, rather than assessed and pursued afterwards. We have mapped the multi-registry lodgement dependencies in the Cypriot property transfer process in detail and would make that analysis available to the Taskforce. COMMENT 5 — DEFINE AN ACCOUNTABILITY STANDARD CYPRUS CAN CERTIFY Strategy reference: Section 1.1 (Fundamental Principles); Section 3.3.2 (Control Framework); Section 3.9.6; Annex B (AI Use Case Lifecycle and Control Gates). Comment / Suggestion: The principle that people must remain in control is correct but is currently expressed as a value rather than a testable standard. We recommend Cyprus develop a certifiable accountability standard for AI used in regulated legal and financial workflows, covering at minimum: (a) mandatory human approval gates for actions with legal or financial effect; (b) separation of the approving and compliance functions (dual control), with self-review expressly excluded; (c) immutable, append-only approval and provenance records available to regulators; (d) disclosure of the trust boundary beyond which a system may not act autonomously. Justification: We are building to substantially this specification, and we would submit that it is achievable for operators of ordinary size rather than only for large institutions. Point (b) deserves emphasis because it is the requirement most often omitted. A human approval gate provides no assurance if the same identity can hold both the approving and the compliance role on the same record. The control must be enforced at the point of write, not in the interface. Point (d) matters for agentic systems specifically, an issue other contributors have raised. The governance question for an agentic system is not only what it produces but what it is permitted to do, and the answer should be a declared, auditable boundary rather than an implicit one. Codifying this would give the phrase ""trusted jurisdiction"" in Objective 1 an audit trail behind it, and would be an exportable Cypriot standard rather than an imported one. ENDORSEMENTS We support, without repeating, the following positions already on this consultation record: 1. That the Strategy be conformed to the enacted national law implementing Regulation (EU) 2024/1689, and that the respective competences of the National AI Authority and the existing competent authorities be stated explicitly to avoid overlap. As a prospective regulated operator we would answer to several supervisors under the current drafting, with no stated coordination mechanism between them. 2. That EU-resident cloud infrastructure be recognised as satisfying sovereignty and residency requirements in the interim, and that sovereignty be defined by lawful control, portability and exit rather than by physical location. 3. That the treatment of ISO/IEC 42001 be corrected, and that management-system certification not be presented as conformity of an AI system. Angus Archer Mason Founder and Managing Director REXE Technologies Ltd KEMA BLDG, 5th Floor East, 21 Akademias Avenue, Nicosia, CYPRUS 2107" "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",ETEK1,"Σχόλια και Εισηγήσεις ΕΤΕΚ επί της Εθνικής Στρατηγικής για την Τεχνητή Νοημοσύνη – Κύπρος 2032 Εισαγωγή Σε σχέση με τη Δημόσια Διαβούλευση της Εθνικής Στρατηγικής για την Τεχνητή Νοημοσύνη (ΤΝ), η οποία εκπονήθηκε από την Εθνική Εξειδικευμένη Επιτροπή για την Τεχνητή Νοημοσύνη (National AI Taskforce), που συστάθηκε με την Απόφαση του Υπουργικού Συμβουλίου αρ. 97.538, ημερομηνίας 22.1.2025, υπό την προεδρία του Επικεφαλής Επιστήμονα για Έρευνα, Καινοτομία και Τεχνολογία και με τη συμμετοχή έντεκα μελών από τον δημόσιο και ιδιωτικό τομέα, την ακαδημαϊκή και ερευνητική κοινότητα, το ΕΤΕΚ χαιρετίζει την εκπόνηση της Στρατηγικής και συμφωνεί με τη γενική κατεύθυνση, το όραμα και τις βασικές αρχές της. Ιδιαίτερα θετικά αξιολογούνται η ανθρωποκεντρική προσέγγιση, η έμφαση στην ασφάλεια, στη διαφάνεια, στη διαλειτουργικότητα, στην ανάπτυξη δεξιοτήτων και στη συμμόρφωση με το ευρωπαϊκό κανονιστικό πλαίσιο. Για να καταστεί, ωστόσο, η Στρατηγική πρακτικά εφαρμόσιμη και να αποφευχθεί ο κατακερματισμός δράσεων και πόρων, απαιτείται περαιτέρω εξειδίκευση ως προς την προτεραιοποίηση, την κοστολόγηση, τις θεσμικές αρμοδιότητες, την τεχνική αρχιτεκτονική, τη διαχείριση των υφιστάμενων συστημάτων και τη μέτρηση των αποτελεσμάτων. Το ΕΤΕΚ προτείνει όπως η Εθνική Στρατηγική δεν περιοριστεί σε γενικές κατευθύνσεις, αλλά συνοδευτεί από δεσμευτικό, κυλιόμενο, συγκεκριμένο, κοστολογημένο και ιεραρχημένο Σχέδιο Εφαρμογής ΤΝ μέχρι το 2032, με σαφή χρονοδιαγράμματα, υπεύθυνους φορείς και μετρήσιμα παραδοτέα, και αναμενόμενα οφέλη ανά δράση. Παράλληλα, θα πρέπει να προβλέπεται υποχρεωτική Εθνική Αρχιτεκτονική Αναφοράς ΤΝ και Δεδομένων η οποία να καθορίζει ενιαίους τεχνικούς κανόνες για τη διαλειτουργικότητα, τις διεπαφές και τα APIs, τα κοινά πρότυπα δεδομένων και μεταδεδομένων, την ταυτοποίηση και τον έλεγχο πρόσβασης, τη διαχείριση μοντέλων και εκδόσεων, τη φορητότητα και τη δυνατότητα αλλαγής προμηθευτή, σχέδιο επικαιροποίησης των διοικητικών διαδικασιών, των υφιστάμενων πληροφοριακών συστημάτων και της αναγκαίας νομικής βάσης, καθώς και ανεξάρτητος μηχανισμός τεχνικής διασφάλισης και ελέγχου για έργα ΤΝ μεγάλης αξίας, υψηλού κινδύνου ή σημαντικού δημόσιου αντικτύπου. Ακολουθούν τα σχόλια και οι εισηγήσεις του ΕΤΕΚ, σύμφωνα με τη δομή που καθορίζεται στη Δημόσια Διαβούλευση: 1. Αρ. Άρθρου και εδαφίου: Ενότητες 1.4, 1.5, 3, 4 και 5. Σχόλιο / Εισήγηση: Να εκπονηθεί, εντός καθορισμένου χρονικού διαστήματος, δεσμευτικό και κυλιόμενο Εθνικό Σχέδιο Εφαρμογής ΤΝ μέχρι το 2032. Για κάθε δράση να καθορίζονται τα παραδοτέα και το χρονοδιάγραμμα, η κεφαλαιουχική και λειτουργική δαπάνη και τα αναμενόμενα οφέλη. Παράλληλα, οι δράσεις να καταταχθούν, κατά σειρά προτεραιότητας, σε θεμελιώδεις εθνικές υποδομές, παραγωγικές εφαρμογές πρώτου κύματος και μακροπρόθεσμες ή ερευνητικές πρωτοβουλίες. Αιτιολόγηση: Η Στρατηγική περιλαμβάνει γενικό ορίζοντα και ενδεικτικές φάσεις εφαρμογής, χωρίς όμως ενιαίο και επαρκώς εξειδικευμένο σχέδιο ανά δράση, με σαφή ιεράρχηση, κοστολόγηση, συγκεκριμένα παραδοτέα και αναμενόμενα οφέλη. Χωρίς κοστολογημένο σχέδιο εφαρμογής, δεν μπορεί να αξιολογηθεί ούτε η βιωσιμότητα ούτε η δυνατότητα παράλληλης υλοποίησης των προτεινόμενων δράσεων. Η ταυτόχρονη προώθηση μεγάλου αριθμού αρχών, συμβουλίων, κέντρων αριστείας, sandboxes, τομεακών πλατφορμών, υποδομών και μεγάλων έργων δημιουργεί κίνδυνο διασποράς των περιορισμένων ανθρώπινων και οικονομικών πόρων. Για επενδύσεις μεγάλης κλίμακας σε υπολογιστικές υποδομές ΤΝ να προηγείται τεχνοοικονομική μελέτη σκοπιμότητας, η οποία να εξετάζει το συνολικό κόστος ιδιοκτησίας, τις ενεργειακές και περιβαλλοντικές απαιτήσεις, καθώς και την επιλογή μεταξύ ανάπτυξης εθνικής υποδομής και αξιοποίησης υφιστάμενων ευρωπαϊκών υποδομών. 2. Αρ. Άρθρου και εδαφίου: Ενότητες 2.5, 3.3, 3.9, 5 και Παραρτήματα Α και Γ. Σχόλιο / Εισήγηση: Να εκπονηθεί Οδικός Χάρτης Νομικής και Κανονιστικής Εφαρμογής, στον οποίο να προσδιορίζεται για κάθε μέτρο κατά πόσο αποτελεί υφιστάμενη νομική υποχρέωση, υποχρέωση ευρωπαϊκού δικαίου ή μέτρο που απαιτεί νέα νομοθεσία, αποσαφηνίζοντας τη σχετική νομική βάση για μητρώα, πιστοποιήσεις, άδειες και πρόσβαση σε δημόσιες υποδομές. Αιτιολόγηση: Το κείμενο χρησιμοποιεί σε ορισμένα σημεία δεσμευτική διατύπωση για θεσμικές στρατηγικές ΤΝ, μητρώα, πιστοποιήσεις, άδειες και πρόσβαση σε δημόσιες υποδομές, χωρίς να αποσαφηνίζεται πάντοτε η σχετική νομική βάση. Παράλληλα, στο πλαίσιο του Οδικού Χάρτη να αποσαφηνιστούν η νομική βάση και τα όρια αρμοδιοτήτων της Εθνικής Αρχής ΤΝ σε σχέση με τις υφιστάμενες αρμόδιες εποπτικές αρχές, καθώς και να ενοποιηθεί η ονοματολογία και ο ρόλος όλων των προβλεπόμενων οργάνων. Να αποσαφηνιστεί επίσης η αναφορά σε «AI Judge Capability», ώστε να είναι σαφές ότι τα σχετικά συστήματα έχουν αποκλειστικά υποβοηθητικό χαρακτήρα, με διατήρηση της ανθρώπινης εποπτείας και με σαφή διατήρηση της ανθρώπινης εποπτείας και της δικαιοδοτικής αρμοδιότητας του φυσικού δικαστή. 3. Αρ. Άρθρου και εδαφίου: Ενότητες 3.2, 3.4.4, 3.7, 4.2 και Παράρτημα Β. Σχόλιο / Εισήγηση: Οι αρχές και τεχνικές κατευθύνσεις που ήδη περιλαμβάνονται στη Στρατηγική να εξειδικευτούν και να ενοποιηθούν σε υποχρεωτική Εθνική Αρχιτεκτονική Αναφοράς ΤΝ και Δεδομένων για όλα τα δημόσια έργα ΤΝ. Η Αρχιτεκτονική να καθορίζει ελάχιστες απαιτήσεις για τη διαλειτουργικότητα, τις διεπαφές και τα APIs, τα κοινά πρότυπα δεδομένων και μεταδεδομένων, την ταυτοποίηση και τον έλεγχο πρόσβασης, τη διαχείριση μοντέλων και εκδόσεων, την παρακολούθηση απόδοσης, τη φορητότητα και τη δυνατότητα αλλαγής προμηθευτή. Η συμμόρφωση με την Αρχιτεκτονική να ελέγχεται πριν από την προκήρυξη και πριν από την παραγωγική λειτουργία κάθε έργου. Αιτιολόγηση: Η Στρατηγική αναγνωρίζει την ανάγκη κοινών προτύπων, επαναχρησιμοποίησης, διαλειτουργικότητας και φορητότητας. Για να εφαρμοστεί, όμως, στην πράξη η αρχή «build once, reuse everywhere», οι σχετικές πρόνοιες πρέπει να μετατραπούν σε ενιαίες, δεσμευτικές και ελέγξιμες τεχνικές απαιτήσεις. Διαφορετικά, υπάρχει κίνδυνος διαφορετικών ερμηνειών από τους φορείς υλοποίησης, δημιουργίας νέων απομονωμένων συστημάτων, μη συμβατών διεπαφών και εξάρτησης από συγκεκριμένους προμηθευτές. 4. Αρ. Άρθρου και εδαφίου: Ενότητες 2.2.2, 3.2, 3.4, 3.7 και Παράρτημα Γ. Σχόλιο / Εισήγηση: Κάθε έργο ΤΝ στον δημόσιο τομέα να περιλαμβάνει κοστολογημένο σχέδιο ενσωμάτωσης με υφιστάμενα συστήματα και ανασχεδιασμού διαδικασιών (Legacy Integration and Process Redesign Plan), με συγκεκριμένο χρονοδιάγραμμα για τον καθαρισμό και τον μετασχηματισμό δεδομένων, τη δημιουργία διεπαφών και APIs, τον ανασχεδιασμό διοικητικών διαδικασιών, την εξάλειψη διπλών καταχωρίσεων, την ενοποίηση ή αντιστοίχιση μητρώων, ώστε να αποτραπεί η ενίσχυση υφιστάμενων αδυναμιών από τη χρήση ΤΝ σε παρωχημένα συστήματα. Αιτιολόγηση: Οι περισσότερες εφαρμογές ΤΝ εξαρτώνται από υφιστάμενα συστήματα διαχείρισης εγγράφων, υποθέσεων, πληρωμών, ταυτοποίησης υγείας και διοικητικών μητρώων. Η εισαγωγή ΤΝ πάνω σε παρωχημένα, μη διαλειτουργικά ή προβληματικά συστήματα δεν αντιμετωπίζει τις βασικές αδυναμίες και ενδέχεται να τις ενισχύσει. 5. Αρ. Άρθρου και εδαφίου: Ενότητες 3.3.2, 3.9, 3.11, 3.13 και Παράρτημα Β. Σχόλιο / Εισήγηση: Το προβλεπόμενο πλαίσιο πυλών ελέγχου να εξειδικευτεί με υποχρεωτική ανεξάρτητη τεχνική διασφάλιση από φορέα ανεξάρτητο από τον ανάδοχο και την ομάδα υλοποίησης για έργα ΤΝ υψηλού κινδύνου, μεγάλης αξίας ή σημαντικού δημόσιου αντικτύπου. Η διασφάλιση να πραγματοποιείται υποχρεωτικά πριν από την προκήρυξη, πριν από την παραγωγική λειτουργία και πριν από ουσιώδη αλλαγή του μοντέλου, του σκοπού ή του πεδίου χρήσης. Να βασίζεται σε προκαθορισμένα και δημοσιευμένα κριτήρια για την αρχιτεκτονική, τα δεδομένα, την ασφάλεια, τη διαλειτουργικότητα, την ανθρώπινη εποπτεία, την προσβασιμότητα, την απόδοση, τη μεροληψία, την επιχειρησιακή ετοιμότητα και το συνολικό κόστος ιδιοκτησίας. Αιτιολόγηση: Οι πύλες ελέγχου και η δυνατότητα εσωτερικής ή εξωτερικής διασφάλισης που προβλέπει η Στρατηγική αποτελούν θετική βάση. Για έργα, όμως, με αυξημένο κίνδυνο, κόστος ή επίδραση στους πολίτες, η τεχνική αξιολόγηση πρέπει να είναι υποχρεωτική, να διενεργείται από φορέα ανεξάρτητο από τον ανάδοχο και την ομάδα υλοποίησης και να βασίζεται σε ενιαία κριτήρια αποδοχής. Η προσέγγιση αυτή μειώνει τον κίνδυνο τεχνικής αστοχίας, υπέρβασης κόστους, σύγκρουσης συμφερόντων και λειτουργίας συστημάτων χωρίς επαρκή τεκμηρίωση. 6. Αρ. Άρθρου και εδαφίου: Ενότητες 1.5, 3.5, 5 και Παραρτήματα Γ και ΣΤ. Σχόλιο / Εισήγηση: Να ενοποιηθούν και να τεκμηριωθούν οι ποσοτικοί στόχοι υιοθέτησης ΤΝ, με σαφή ορισμό του δείκτη, ενιαία βάση αναφοράς, ημερομηνία-στόχο και πηγή δεδομένων. Ειδικότερα, να αποσαφηνιστεί η αναφορά στον στόχο 75% της Ψηφιακής Δεκαετίας, ο οποίος αφορά συνδυαστικά υπολογιστικό νέφος, ανάλυση μεγάλων δεδομένων ή/και ΤΝ και όχι αποκλειστικά υιοθέτηση ΤΝ. Αιτιολόγηση: Η Στρατηγική χρησιμοποιεί διαφορετικές βάσεις αναφοράς και ημερομηνίες για τον στόχο υιοθέτησης ΤΝ και παραπέμπει στον στόχο της Ψηφιακής Δεκαετίας χωρίς να αποσαφηνίζεται η αντιστοίχιση των δεικτών. Για να είναι οι στόχοι ελέγξιμοι και μετρήσιμοι, απαιτείται ενιαία μεθοδολογία, σαφής πηγή δεδομένων και συνεπής χρονικός ορίζοντας. Να εξεταστεί επίσης η μετατροπή του Παραρτήματος ΣΤ σε πλήρη πίνακα παρακολούθησης, με ορισμό δείκτη, βάση αναφοράς, πηγή, ενδιάμεσο και τελικό στόχο, αρμόδιο φορέα και συχνότητα μέτρησης." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Vassilis Vassiliades","The Strategy is ambitious and contains many strong elements, particularly in relation to public-sector adoption, data and compute infrastructure, responsible AI, skills, governance and sectoral transformation. The comments below focus on a small number of areas where the Strategy could be strengthened further, especially to ensure that Cyprus builds not only capacity to adopt AI, but also long-term capacity to create AI knowledge, technologies and future industries. A national AI research strategy should support both research serving today's economy and research capable of creating tomorrow's economy. 1. Distinguish AI-adoption priorities from scientific and technological leadership The eight ""Priority Sectors for Leadership"" are selected largely on the basis of GDP contribution and exposure to AI-driven productivity gains. These are appropriate criteria for identifying sectors where AI adoption should be accelerated, but they are not necessarily the same criteria that should determine where Cyprus can achieve international scientific or technological leadership. For example, tourism is clearly an important AI-adoption priority: AI can improve demand forecasting, personalisation, resource management and SME productivity. This does not necessarily imply that Cyprus should concentrate frontier-research resources on becoming a world leader in tourism AI. By contrast, an area such as maritime autonomy could potentially combine an existing Cypriot industrial ecosystem, real test environments, frontier research and exportable technology. Suggestion: distinguish explicitly between Priority Sectors for AI Adoption and Transformation and a smaller number of Scientific and Technological Leadership Missions. Leadership missions should be selected through a transparent critical-mass and comparative-advantage assessment, considering existing excellence, talent, unique national assets/testbeds, European leverage, global market potential, cross-sector spillovers and long-term sustainability. 2. Elevate Frontier & Foundational AI and introduce AI for Science and Engineering Section 3.8 and Annex D appropriately recognise foundational AI, but the research architecture remains predominantly applied and sector-oriented. Foundational AI would be better treated as a horizontal national scientific capability, rather than one vertical focus area alongside healthcare, telecommunications or energy. The Strategy should also explicitly recognise AI for Science and Engineering: the use of AI to generate scientific discoveries and new engineering solutions, rather than only to improve existing services and processes. Suggestion: organise national AI research around three complementary modes: • Frontier and Foundational AI (""Science for AI"") - investigator-led research advancing AI itself; • AI for Science and Engineering - AI-enabled scientific discovery and engineering design; and • Mission-driven AI R&D - translation of AI into strategic national challenges. Frontier research should retain a sufficiently bottom-up, excellence-based component so that promising future directions are not limited to a static list of technologies chosen in 2026. 3. Define the National AI Research Fund, AI ERC Bridge and research-talent pipeline more concretely The proposed National AI Research Fund and AI ERC Bridge could become major instruments for building long-term national AI capability, but their design is currently under-specified. Suggestion: structure the Research Fund as a portfolio with separate instruments for frontier AI, AI for Science, strategic missions, research translation/proof-of-concept, shared research infrastructure and international research talent. Different instruments should use different evaluation criteria. The AI ERC Bridge should also be clarified as part of a complete excellence pipeline: prepare -> bridge/resubmit -> attract -> establish -> retain In addition to proposal and attraction support, the national framework should address long-term retention and career stability, so that internationally excellent researchers and the teams they build are not lost when externally funded projects end. This issue extends beyond AI and should ideally connect to broader national research-career policy. 4. Strengthen Autonomous Systems into Embodied AI, Robotics and Autonomous Systems, including physical research infrastructure Annex D already identifies Autonomous Systems and the Strategy proposes an Autonomous Systems Park. This could be strengthened into a more ambitious frontier programme in Embodied AI, Robotics and Autonomous Systems. Relevant research includes robot learning, manipulation and loco-manipulation, multimodal/tactile perception, learning reusable skills, planning, continual adaptation, safe autonomy, sim-to-real, human-robot collaboration and multi-agent systems. These capabilities have strong spillovers across several existing priorities: maritime inspection and autonomy; energy/water infrastructure; environmental monitoring; agri-food and field robotics; rehabilitation and assistive healthcare; and security/emergency-response systems. Suggestion: recognise that AI research infrastructure is not limited to GPUs and data. Frontier robotics also requires shared physical experimental infrastructure - robotic platforms, sensors, laboratories, field/marine systems, instrumented test environments, research engineers, maintenance and technology-renewal budgets. A federated national infrastructure based on existing capability may be more efficient than duplicating expensive equipment. 5. Strengthen the Energy-Environment focus into AI for Climate, Energy, Water and Sustainable Island Systems, and explicitly consider Agri-food Focus Area 1 already addresses water scarcity, renewable energy, climate impacts, smart grids, irrigation and resource optimisation. The current emphasis is mainly on prediction, monitoring and optimisation. Cyprus could also exploit AI for scientific and engineering discovery. For example, using AI to optimise an existing desalination plant can provide important near-term value; using AI-assisted discovery to develop better desalination membranes, energy-storage materials, photovoltaic materials or anti-fouling technologies could generate exportable IP and future industries. Suggestion: consider a mission such as AI for Climate, Energy, Water and Sustainable Island Systems, combining AI-enabled prediction/control with scientific discovery and engineering design. Agri-food should also be explicitly reconsidered. Although agriculture may contribute less to current GDP than major service sectors, it is strategically important for food security, water demand, climate resilience, rural development and high-value local production. Rather than simply adding a ninth equal ""pillar"", Agri-food could be recognised as an important AI-adoption and innovation domain linked strongly to the energy-water-climate and robotics missions. 6. Use existing capability first and define selective strategic autonomy The Strategy proposes several new national bodies, hubs, committees and Centres of Excellence. Many of the functions are important, but creating new entities can duplicate existing capability and fragment a limited national pool of specialised talent. Suggestion: adopt an existing-capability-first principle. Before establishing a new institution or Centre of Excellence, map the relevant capability already present in universities, existing Centres of Excellence, research organisations, regulators and European infrastructures. Use federated structures, competitive designation and shared infrastructure where these can deliver the function effectively. Similarly, ""AI sovereignty"" should be operationalised as selective strategic autonomy. Cyprus should define what it must own, control, understand, keep portable/interoperable, access through European infrastructure, or procure commercially. National compute investments should follow demonstrated workloads and include utilisation, lifecycle cost, energy and renewal considerations, while leveraging EuroHPC and the European AI Factory ecosystem where scale is more efficiently obtained at European level. 7. Strengthen research-to-innovation pathways, implementation and measurable KPIs The Entrepreneurship and Innovation pillar contains promising measures, but the complete pathway from frontier research to scalable deep-tech companies should be made more explicit: discovery -> proof of concept -> IP -> spin-off/startup -> first customer -> follow-on investment -> international scale-up Possible instruments include proof-of-concept grants, researcher-entrepreneurship mechanisms, predictable IP arrangements, public-sector first-customer/testbed opportunities and strong links to European scale-up instruments. Implementation should also be more auditable. Annex F is explicitly indicative, while the Strategy contains precise headline targets. Some targets/timelines also require reconciliation - for example, the Strategy refers in different places to 50% and 75% AI-adoption targets by 2032, and to ministerial AI strategies being updated every three years versus annually. Suggestion: for each major objective define: baseline -> 2028 milestone -> 2030 milestone -> 2032 target -> methodology -> data source -> accountable owner -> corrective trigger Separate KPI families should cover adoption/productivity, scientific excellence, research talent, innovation/commercialisation, infrastructure, trust/compliance and strategic missions. Finally, the 2032 Strategy should remain technology-neutral at the strategic level, with specific bets such as particular model architectures or platforms handled through shorter rolling implementation roadmaps. Concluding comment The Strategy is already strong in describing how Cyprus can become a responsible and productive user of AI. Its long-term impact could be increased further by answering equally clearly: In which areas will Cyprus create internationally significant AI knowledge and technologies, rather than primarily adopt technologies created elsewhere? A strong model for Cyprus would combine broad AI adoption, open excellence-based frontier research, and concentrated investment in a small number of evidence-based scientific and technological missions with sufficient critical mass to become internationally distinctive." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Panayiotis Andreou","The release of the Cyprus National AI Strategy for public consultation represents, in our view, an important step forward for Cyprus. Moving beyond individual applications of artificial intelligence toward a coordinated national framework matters if Cyprus is to approach one of the most significant technological transformations of our time in a systematic, deliberate and economically meaningful way. The importance of such a strategy should not be judged solely by whether every target can already be predicted with precision. Artificial intelligence is developing rapidly, its applications are spreading unevenly across sectors and firms, and our understanding of its full macroeconomic effects remains incomplete. A national strategy must therefore perform a more fundamental function: establish a credible direction, build the capabilities needed for adoption, provide an institutional framework within which experimentation can occur, and create mechanisms through which implementation can be measured and progressively improved. Read through an economic and academic lens, several features of the Cyprus Strategy are particularly important. ------A strategy of focus rather than technological breadth------- First, the broad architecture of the Strategy is economically sound. Cyprus does not attempt to compete across every dimension of artificial intelligence. Such an objective would be neither realistic nor economically efficient for a small economy. Instead, the Strategy follows a logic of focus and differentiation, concentrating attention on sectors in which Cyprus already possesses significant economic weight, institutional capabilities or established sectoral strengths. These include financial and professional services, shipping, tourism, healthcare, education and government. At the same time, the Strategy treats data, infrastructure, skills, research, governance and trusted AI as shared enabling capabilities that can support adoption across these sectors. This distinction is important. The economic value of AI for Cyprus will not necessarily arise from attempting to reproduce the complete global AI value chain domestically. It is more likely to arise from becoming exceptionally capable at adopting, adapting and deploying AI in areas in which Cyprus already possesses economic, institutional or sector-specific advantages. The Strategy's architecture is therefore consistent with the broader logic appropriate to small European economies: coordinated adoption, shared infrastructure, human-capital development, public-sector transformation and credible governance. The associated concept of sovereign capability through partnerships is particularly relevant. Strategic autonomy should not be interpreted as requiring Cyprus to develop every AI model, semiconductor, cloud platform or technological capability domestically. For a small economy, this would be neither feasible nor desirable. A more useful interpretation of strategic autonomy is the capacity to maintain sufficient knowledge, control, resilience and freedom of action while drawing on European and international partnerships to obtain technological capabilities and scale that cannot efficiently be produced domestically. This also places institutional capability at the center of the economic discussion. Data governance, interoperability, procurement capability, technological assurance, cybersecurity and regulatory certainty are sometimes treated mainly as constraints surrounding innovation. Properly designed, however, they are also part of the infrastructure through which innovation can spread and scale. If public institutions cannot procure AI effectively, if organizations cannot access appropriate data, if systems cannot communicate with one another, if firms remain uncertain about regulatory requirements, or if the workforce lacks the capabilities required to use new technologies productively, technological availability alone will not generate economic transformation. The institutional foundations of adoption are therefore not peripheral to the Strategy. They are part of its economic mechanism. -------The economic evidence for AI is becoming stronger------ Second, the microeconomic and firm-level evidence supporting the proposition behind strategies of this kind has strengthened substantially. AI can raise productivity and support innovation at the level of workers and firms and, through these and other channels, may eventually expand the productive capacity of the wider economy. What remains considerably less certain is the magnitude, timing and distribution of those effects at the aggregate level. Three recent studies illustrate different links in a possible transmission chain running from individual productivity through firm growth to entrepreneurship and the creation of new economic activity. Brynjolfsson, Li and Raymond (2025), examining the introduction of generative AI in a real workplace, find meaningful productivity gains associated with the technology. Babina, Fedyk, He and Hodson (2024) move the analysis to the firm level. They show that firms investing in AI subsequently experience stronger growth in sales, employment and market value, with product innovation representing an important channel. Gofman and Jin (2024) highlight another mechanism with particular relevance for national policy. Their evidence indicates that the loss of AI professors reduces AI startup formation among affected students, consistent with the proposition that university-based AI knowledge can support entrepreneurship and the creation of new firms. These studies should not be interpreted as establishing a mechanical sequence through which every AI investment eventually generates economic growth. Rather, they illustrate different links in a possible transmission chain: improved capabilities at the individual level can affect organizations; organizational capabilities can contribute to innovation and growth; and knowledge creation and human capital can contribute to entrepreneurship and new economic activity. This evidence sits alongside a growing body of work from institutions such as the OECD and IMF examining the potential aggregate productivity implications of artificial intelligence. The direction of the evidence is increasingly important. The difficult question is no longer simply whether AI can affect productivity or innovation. There is now substantial evidence that, under appropriate circumstances, it can. The more difficult economic question is how those gains propagate across an entire economy. -----From individual productivity to national economic performance------ This distinction is central to evaluating any national AI strategy. We are becoming considerably better at measuring what artificial intelligence can achieve at the level of particular tasks, workers and firms. We know much less about how these effects ultimately aggregate into economy-wide productivity, output and welfare. Adoption is only the beginning of the transmission mechanism. A worker becoming more productive through AI does not automatically make the entire firm proportionately more productive. Task-level productivity gains need to be accompanied by organizational redesign, complementary investments in technology and infrastructure, changes in workflows, new managerial practices and investment in human capital. Those firm-level changes must then become sufficiently widespread to matter at the aggregate level. Successful firms may innovate, develop new products, enter new markets and generate new forms of activity. New firms may emerge. Knowledge and technologies may spill over across sectors. Workers may move between organizations and transfer expertise. Public-sector applications may improve the quality or efficiency of services. New capabilities may reduce costs, improve decision-making and allow existing resources to be deployed more effectively. Only as these different mechanisms accumulate does AI have the potential to produce a substantial effect on aggregate productivity and potential output. The transmission is therefore neither instantaneous nor automatic. It depends on skills. It depends on data readiness. It depends on organizational redesign and capital investment. It depends on how broadly adoption spreads across firms rather than remaining concentrated among a small number of leading organizations. It depends on institutional capability. And ultimately, it depends on execution. This is where the history of previous general-purpose technologies becomes instructive. Their largest economic effects were often realized only after significant complementary investments in new processes, organizational structures, skills and intangible capital. Brynjolfsson, Rock and Syverson (2021) describe this phenomenon through the concept of the productivity J-curve: transformative technologies may require substantial complementary investment before their full productivity effects become visible in measured economic statistics. AI may follow a similar logic. The economic model of AI, in other words, is still being written. That observation should not be interpreted as an argument for inaction. Rather, it helps explain why a national strategy should combine ambition with experimentation, investment, measurement and continuous learning. -------Economic value will not necessarily appear in a single statistic----- A further complication is that the economic effects of AI are unlikely to appear through one channel or in one indicator. Some benefits may eventually register clearly in measured productivity and output. Others may emerge through the creation of new firms, intellectual property, human capital, technological capabilities, knowledge spillovers, improved public services or greater economic and institutional resilience. Some effects may be relatively easy to quantify. Others may be difficult to anticipate before the relevant applications emerge. The economic impact of AI may therefore become multidimensional before it becomes fully measurable. This point is important when considering the headline macroeconomic ambitions contained in the Strategy. The Strategy refers to ambitions of up to 15% improvement in productivity relative to the baseline trajectory and 12% expansion in GDP associated with AI-enabled transformation. The scale of these eventual gains clearly matters. It matters for economic analysis, but it also matters for determining the appropriate scale, sequencing and allocation of investment. At the present stage, however, we believe these figures are more appropriately interpreted as strategic scenarios or targets rather than empirically established forecasts. This distinction strengthens rather than weakens the economic case for the Strategy. A forecast implies a particular baseline, transmission mechanism, time horizon and set of behavioral and economic assumptions. Given how rapidly AI technology and adoption are evolving, considerable uncertainty surrounds each of these elements. An appropriate next step would therefore be to progressively underpin these headline ambitions with a Cyprus-specific scenario and impact-assessment framework. Such a framework could make explicit the assumptions underlying different scenarios, the baseline trajectory against which improvements are measured, the mechanisms through which AI is expected to affect different parts of the economy and the time horizon over which those effects could reasonably emerge. Importantly, this need not involve pretending that the economic effects of AI can already be estimated with false precision. Instead, the framework could initially operate through scenarios, sensitivity analysis and ranges of possible outcomes. As implementation advances and Cyprus-specific evidence becomes available, it could then be progressively calibrated and refined. This would create a feedback mechanism between strategy, implementation and evidence. ------Uncertainty does not invalidate the strategic direction------- Uncertainty over magnitude does not invalidate the direction of the Strategy. It does mean that the scale, sequencing and prioritization of investment should evolve with the available evidence. Even more moderate but sustained improvements in productivity, innovation, public-sector efficiency, human capital and the creation of new economic activity can accumulate into substantial economic and social value over time. The strategic case for AI therefore does not need to depend on achieving one particular GDP number or one particular productivity estimate. The more fundamental question is whether AI can materially strengthen productivity, innovation and economic capability. The available evidence increasingly suggests that it can. The Strategy provides Cyprus with a framework within which it can build capabilities, accelerate adoption, strengthen institutions, experiment, learn and gradually identify the applications that produce the greatest economic and societal value. Implementation itself can also generate another important asset: Cyprus-specific evidence. If appropriately accompanied by rigorous evaluation, implementation will allow policymakers and institutions to observe where adoption succeeds, where it fails, which complementary investments matter, which sectors respond most strongly, and which interventions generate the highest economic and social returns. That evidence can then be used to improve assumptions, refine priorities and redirect resources toward interventions that work. The Strategy should therefore be viewed not simply as a fixed plan extending to 2032, but as a framework within which learning and economic calibration can occur continuously. -----Why the opportunity is particularly relevant for Cyprus------- This consideration is especially important because of the structure of the Cypriot economy. Cyprus is a small, highly service-oriented and internationally connected economy. Financial services, professional services, shipping, tourism, healthcare, education and public administration are all activities in which information, expertise, judgment and knowledge play central roles. These are precisely the types of activities in which artificial intelligence can potentially alter how work is performed, how information is processed, how decisions are made and how services are delivered. This does not mean that every occupation or organization will be transformed in the same way. Nor does it mean that technological adoption alone guarantees productivity gains. It does, however, mean that Cyprus has a direct economic interest in developing the capabilities required to participate effectively in this transformation. Standing still while the transformation unfolds would itself constitute a strategic choice. The available evidence is sufficiently strong to justify action. At the same time, considerable uncertainty remains regarding the magnitude, timing and distribution of the eventual gains. These two conclusions are not contradictory. Taken together, they make the case for combining strategic ambition with implementation, measurement, learning and continuous economic calibration. The Strategy provides a structure through which Cyprus can do precisely that. ------From strategic architecture to implementation discipline------ Setting the direction is therefore an important first step. The next challenge is to translate that direction into measurable economic and societal value. The Strategy already provides a credible foundation. Its emphasis on selected sectors, trusted AI, human capital, shared infrastructure and sovereign capability through European partnerships aligns well with Cyprus's economic structure and strategic position.The next stage can build on this foundation by further strengthening the connection between strategic architecture and implementation discipline. One dimension is regulatory readiness. With the European Union's AI regulatory framework becoming operational, implementation of the Strategy can be aligned with the evolving requirements of Regulation (EU) 2024/1689. Connecting governance, procurement, risk classification, transparency, human oversight, AI literacy, regulatory sandboxes and post-market monitoring with the European regulatory framework can reinforce the Strategy's existing emphasis on trusted and responsible AI. Regulatory readiness should not be viewed solely as a compliance exercise. For firms considering investment and for public organizations deploying AI, legal and regulatory certainty can itself form part of the institutional infrastructure supporting adoption. Keeping the implementation roadmap aligned with the evolving European regulatory timetable can therefore support more consistent implementation across the public and private sectors while reinforcing institutional credibility and investor confidence. In this sense, trusted AI and economic development should not be regarded as competing objectives. Proper governance can contribute to the conditions under which adoption becomes sustainable and scalable. ------Building a measurable implementation framework------ A useful next step would consequently be the progressive translation of the Strategy's high-level objectives into an increasingly measurable investment and delivery framework. Several elements will be particularly important. First, institutional responsibilities need to be clearly allocated. AI policy cuts across digital government, education, research, regulation, public administration, industrial policy and sector-specific responsibilities. Effective implementation therefore requires clarity regarding who is responsible for delivery and accountability. Second, implementation should be supported by a multiannual and prioritized funding framework. The economic logic of AI investment depends not only on how much is spent, but also on sequencing and complementarity. Infrastructure without skills, skills without adoption, or isolated projects without scalable data and governance arrangements may generate limited returns. Third, Cyprus will need appropriate common data and computing infrastructure. These are enabling capabilities rather than ends in themselves, and investment should be assessed according to how effectively it supports high-value applications. Fourth, public-sector implementation requires an AI-ready procurement framework capable of acquiring technologies while managing technological, financial, operational and regulatory risks. Fifth, the country should progressively establish measurable sector-level indicators of adoption, productivity and outcomes. National indicators are useful, but sectoral measurement will be required to understand where value is actually being created. Sixth, particular attention should be paid to diffusion toward small and medium-sized enterprises. Aggregate productivity effects will depend not only on what the largest or technologically most advanced organizations can achieve, but also on how widely useful applications diffuse throughout the economy. Finally, implementation should incorporate evaluation of economic and societal outcomes. The purpose of evaluation should not merely be to determine whether projects were completed or funds were spent. It should establish whether interventions changed adoption, productivity, service quality, innovation, human capital or other relevant outcomes, and whether the value generated justified the resources deployed. This is the point at which strategy becomes economic policy. ------Direction, evidence and learning------ The case for action is therefore strong, but it does not rest on a single headline GDP or productivity figure. The Strategy gives Cyprus a framework for progressively translating artificial intelligence into higher productivity, stronger firms, improved public services, new knowledge-intensive economic activity, better human capital and greater institutional capability. Not all of these benefits will materialize immediately. Not all will be easily measurable. And not every AI investment will succeed. That is precisely why implementation should be accompanied by measurement, experimentation and evidence-based prioritization. The objective should be to discover where AI produces genuine value for Cyprus and then create the conditions for those gains to diffuse throughout the economy. There is an important balance to maintain. Excessive certainty about the eventual macroeconomic effects would not be justified by the evidence available today. But excessive caution would carry its own costs if it prevented Cyprus from building capabilities while the technological environment continues to evolve. A more appropriate approach is disciplined ambition: establish the direction, invest in the enabling capabilities, implement, measure the results, learn from them and continuously recalibrate. Seen from this perspective, the Cyprus National AI Strategy 2032 should not be assessed solely as a prediction of what the Cypriot economy will look like in 2032. Its deeper value lies in providing a framework through which Cyprus can prepare for, participate in and progressively shape a major technological transformation. The direction has now been set. The challenge is to convert that direction into measurable economic and societal value—and to allow evidence generated along the way to determine how Cyprus proceeds. --------Sources------- [1] Brynjolfsson, E., Li, D. & Raymond, L. (2025). “Generative AI at Work.” Quarterly Journal of Economics, 140(2), 889–942. [2] Babina, T., Fedyk, A., He, A. & Hodson, J. (2024). “Artificial Intelligence, Firm Growth, and Product Innovation.” Journal of Financial Economics, 151, 103745. [3] Gofman, M. & Jin, Z. (2024). “Artificial Intelligence, Education, and Entrepreneurship.” Journal of Finance, 79(1), 631–667. [4] Brynjolfsson, E., Rock, D. & Syverson, C. (2021). “The Productivity J-Curve: How Intangibles Complement General Purpose Technologies.” American Economic Journal: Macroeconomics, 13(1), 333–372. [5] Filippucci, F., Gal, P. & Schief, M. (2024). “Miracle or Myth? Assessing the Macroeconomic Productivity Gains from Artificial Intelligence.” OECD Artificial Intelligence Papers, No. 29. [6] Misch, F., Park, B., Pizzinelli, C. & Sher, G. (2025). “Artificial Intelligence and Productivity in Europe.” IMF Working Paper WP/25/67. [7] Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), as amended. Dr Panayiotis C. Andreou and Dr Costas Tziouvas (Cyprus University of Technology)" "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",arkaita,"Amazon Web Services (AWS) appreciates the opportunity to comment on the draft Cyprus National AI Strategy 2032. AWS welcomes the Strategy's ambitious, adoption-led, and execution-focused approach. Its emphasis on cloud-first adoption, responsible public-sector use cases, SME participation, applied skills, trusted public-private and international partnerships, interoperability, portability, vendor diversity, risk-based governance, and regulatory sandboxes provides a strong foundation for responsible AI adoption, innovation, competitiveness, and broad-based productivity growth. The recommendations below focus on implementation choices that can help translate this ambition into sustained deployment while preserving customer choice, legal certainty, open and fair competition, and consistency with the harmonized European framework. AWS understands that the consultation document is a strategic policy framework rather than implementing legislation. Measures expressed in mandatory terms should therefore be clarified as policy proposals. Any future binding obligations should be established through an appropriate legal basis, with defined scope, proportionality, procedural safeguards, and consultation with affected stakeholders. 1. Private-sector obligations and conditional access Article/paragraph reference: Section 3.5, Priority Sectors (pp. 29-30); Annex C, introductory provisions for the Regulated Private Sector and Private Companies/Organisations (p. 60). Comment/recommendation: Clarify which provisions are non-binding policy guidance and which may be proposed for future legal effect. The Strategy should clarify that disclosing an enterprise AI strategy or acceptable-use policy will not constitute an additional condition for granting or renewing an operating license beyond requirements established under applicable sectoral law. Any eligibility conditions for public funding, national compute, or datasets should be transparent, objectively justified, risk-based, proportionate, and non-discriminatory. They should be limited to information necessary for participation in the relevant resource or program and should include robust protection for trade secrets, confidential business information, and security-sensitive information. Any future binding requirements should have a clear legal basis, use terms aligned with the EU AI Act and applicable sectoral law, distinguish the responsibilities of different actors in the AI value chain, and be developed in consultation with the competent regulators and affected stakeholders. Rationale: The Strategy states that industry adoption is not mandatory, but it also provides that every sizable organization must formalize an AI adoption plan. Annex C would give Institutional AI Strategies in regulated sectors the same legal weight as risk-management frameworks and would require certain private enterprises to share AI policies to obtain or renew operating licenses or access public AI resources. Key terms, including ""sizable organization,"" ""critical and high-risk systems,"" ""strategic sectors,"" and ""basic compliance,"" are not defined. This creates legal uncertainty and may duplicate obligations under the EU AI Act or existing sectoral supervision. Conditioning the right to operate on disclosure of a forward-looking AI strategy would be disproportionate to the policy objective and could discourage responsible adoption. Proportionate program-specific conditions can support accountability without creating a broader market-access requirement. 2. EU AI Act alignment and a complementary national compliance proposition Article/paragraph reference: Section 3.9.6, AI Social Contract Principles (pp. 43-44); Section 4.3, AI Governance Enablers (pp. 49-50); Section 5, Immediate Steps, item 4 (p. 51); Annex A (pp. 53-55); Annex C, Government and Public Sector (p. 63) and Legal Services (pp. 74-76). Comment/recommendation: Implement the Strategy through risk-based and proportionate measures that remain fully aligned with the EU AI Act and preserve Single Market consistency. Registration in the EU database should apply only where the AI Act requires it. Any national registry should have a clearly defined purpose, avoid duplicative reporting, collect only necessary information, and protect confidential business and security-sensitive information. A general annual audit requirement should not extend beyond applicable EU or sectoral obligations. The National AI Compliance Framework should operate as a voluntary, outcome-based, technology-neutral, and interoperable support framework. Regulatory sandboxes and related assurance services should remain voluntary and should support, not replace or add to, the AI Act conformity-assessment framework. References to ""foundation models"" should be aligned with the AI Act term ""general-purpose AI models."" Any national pre-certification service for such models should not become an additional condition for offering or deploying AI products and services, participating in public procurement, or accessing the Cyprus market. The Strategy should also distinguish the AI Act's general August 2, 2026 application date from the amended application dates established by Regulation (EU) 2026/1744 (Digital Omnibus on AI) for Chapter III, Sections 1-3: December 2, 2027 for systems classified as high-risk under Article 6(2) and Annex III, and August 2, 2028 for systems classified as high-risk under Article 6(1) and Annex I. Rationale: Cyprus's ambition to become a compliance and testing hub can help innovators and SMEs if it provides practical, voluntary support. Universal registration, annual national audits, or pre-certification requirements would instead create a Cyprus-specific layer on top of harmonized EU rules, increasing cost, complexity, and uncertainty for organizations operating across the Single Market. The AI Act uses targeted registration and conformity-assessment obligations. General-purpose AI models are governed through a distinct EU-level regime, supported by the voluntary GPAI Code of Practice and supervision by the AI Office. National implementation should reinforce those common EU routes and avoid creating parallel market-access conditions. The extended application timeline for high-risk AI systems creates a preparation window that Cyprus can use to strengthen compliance readiness, expand its capacity to operate regulatory sandboxes, and develop assurance expertise, helping position the country as an early-mover jurisdiction for responsible AI deployment. 3. Digital sovereignty, infrastructure, procurement, and incentives Article/paragraph reference: Section 1.1, The Vision (pp. 1-2); Section 3.3.1, Government Innovation Hub (pp. 25-26); Section 3.3.2, Controls (p. 27); Section 3.7, Infrastructure, Compute and Digital Sovereignty (pp. 38-39); Section 4.2.1, AI Infrastructure Enablers (p. 49); Section 5, Immediate Steps, items 2-4 (pp. 50-51). Comment/recommendation: Retain and strengthen the Strategy's recognition that sovereignty can be achieved through trusted partnerships, interoperability, portability, vendor diversity, and European integration. Interoperability and portability requirements should be proportionate to the relevant service layer and workload and should focus on outcomes such as commonly used data formats, documented interfaces, and practical data and workload migration capabilities. They should not prescribe specific orchestration architectures, internal implementation methods, or technical equivalence across distinct services. Operationalize sovereignty as customer agency and control, including the ability to choose and switch providers and to apply verifiable, auditable technical and operational controls over who can access data, where data is stored, how it is encrypted, and how services remain resilient. Sovereignty requirements should not be based on provider nationality, country of origin, mandatory localization, prescribed architectures, or ownership tests. Public procurement, grants, and incentive programs should remain open, competitive, non-discriminatory, outcome-based, and technology-neutral. Solutions should be assessed against objective workload requirements, including security, functionality, performance, resilience, sustainability, and total cost of ownership. National compute should complement broad and portable access to commercial cloud and AI services, enterprise applications, managed tooling, and European infrastructure. Industrial policy should support economy-wide AI diffusion by combining demand-side measures, including outcome-based public procurement, with well-designed incentives and access to finance for adopters. Support should enable firms, particularly SMEs, to invest in the full set of capabilities required for adoption, including eligible consumption-based cloud services, applications, implementation, skills, and organizational change, without favoring infrastructure ownership or capital expenditure where different delivery models meet objective program requirements. Qualification of delivery and implementation partners should use transparent, objective, proportionate, and non-discriminatory criteria open to qualified local and international providers and partners. RISC-V initiatives can advance Cyprus’s research and innovation ambitions. Public procurement should nevertheless remain outcome-based and technology-neutral and should not prescribe hardware origin, a specific architecture, or a particular technical solution. Rationale: Access to compute is necessary but not sufficient for economy-wide AI adoption. Most firms, particularly SMEs, will adopt AI through commercially available applications, managed tooling, enterprise software, and implementation services rather than by interacting directly with raw GPU infrastructure or developing models in-house. A policy that concentrates support on infrastructure ownership or capital acquisition can underinvest in the application, tooling, organizational, and skills layers that enable production deployment. Empirical research by DeStefano, Johnstone, Kneller, and Timmis found that capital incentives favoring hardware could slow the diffusion of cloud, big data, and AI, with particularly pronounced effects for SMEs. National infrastructure and research can strengthen resilience and domestic capability, but they should expand the range of trusted options available to users rather than displace commercial or European capabilities. 4. Governance, industry engagement, and institutional coordination Article/paragraph reference: Section 3.3, Governance and Controls, including Section 3.3.1 (pp. 21-24); Annex A, EU AI Act (p. 53); Annex C, Government and Public Sector (p. 63). Comment/recommendation: AWS welcomes the Strategy’s emphasis on multi-stakeholder engagement, including its recognition of the National AI Taskforce as an independent advisory body, and supports the establishment of an Industry Advisory Board as a standing, non-binding channel for structured public-private dialogue. Broad and balanced representation across technology providers of different sizes, local innovators, SMEs, and businesses from priority sectors can provide practical implementation expertise, identify adoption barriers early, and help keep delivery responsive to technological and market developments. The Board should operate transparently and complement, rather than replace, wider stakeholder consultation and the statutory responsibilities of public authorities. More broadly, Cyprus should publish a clear and accessible allocation of policy, advisory, enablement, platform-operation, supervisory, and enforcement responsibilities across the proposed bodies. The framework should define decision rights, statutory powers, accountability, coordination procedures, conflict-resolution and escalation mechanisms, and predictable decision timelines. Implementation should preserve the independent exercise of the statutory powers of authorities designated under the EU AI Act, data-protection law, and applicable sectoral legislation. Regulated entities should have a clear point of contact and protection against duplicative information requests or conflicting guidance. Rationale: The Strategy's distributed model can bring valuable technical, legal, sectoral, and ethical expertise into decision-making. An Industry Advisory Board would complement the proposed public governance bodies with direct feedback from businesses that develop, deploy, and use AI. It can help translate strategic ambition into scalable implementation and allow practical barriers to be identified before they become entrenched. Clear allocation and coordination of institutional responsibilities would further strengthen the model. The Strategy names the Communications Commissioner and the Commissioner for Personal Data Protection as competent authorities without fully explaining their relationship with the National AI Authority and other proposed bodies. Greater clarity can reduce multiple supervisory interfaces, duplicative requests, and inconsistent guidance while preserving effective national coordination and respecting the statutory responsibilities of the relevant authorities. 5. Adoption delivery, SME enablement, workforce capability, and transition Article/paragraph reference: Sections 3.5 and 3.6 (pp. 29-38); Sections 4.1-4.4 (pp. 47-50); Section 5 (pp. 50-52); Section 3.11, Measuring Impact and National KPIs (pp. 44-45); Annex C, Education and Human Capital Development (pp. 77-81). Comment/recommendation: Operationalize the Strategy's adoption initiatives through a clear and accessible firm-level pathway, particularly for SMEs. This should include sector-specific adoption roadmaps, practical support to identify viable use cases, access to commercially available AI applications and managed tooling, a diverse pool of qualified implementation partners, workflow-redesign and change-management support, and mechanisms for scaling proven deployments. Public-sector AI adoption should also serve as a demand-side catalyst. Open, competitive, and outcome-based procurement, combined with responsible and measurable deployments, can improve public services, demonstrate tangible benefits to citizens, create reference use cases, build public trust, and help strengthen Cyprus’s market for AI applications and implementation services. Where appropriate, contracting authorities should consider dividing flagship AI initiatives into proportionately sized lots that enable specialist firms of different sizes, including Cypriot SMEs and local integrators, to compete for suitable workstreams while preserving clear accountability, security, interoperability, and end-to-end delivery. Singapore's SMEs Go Digital program, including sector-specific guidance and hands-on advisory support, provides a useful model. Workforce policy should take a full-stack approach covering innovators, facilitators, and users. It should pay particular attention to data architects, systems integrators, cloud engineers, sector specialists, middle managers, governance and assurance professionals, trainers, and change leaders. Progress should be measured not only through training participation and talent totals, but also through production deployments, SME participation, time from pilot to scale, workforce adoption, and measurable productivity gains. Workforce-related conditions attached to public funding should remain proportionate, outcomes-based, and consistent with applicable employment law. References to avoiding ""headcount arbitrage"" should not become general restrictions on legitimate business organization. At the same time, workers whose tasks or roles change should have access to modular retraining, career-transition assistance, active labor-market programs, and appropriate social dialogue. Rationale: The Strategy provides strong foundations through ApplyAI, FutureAI CY, AI Officers, the AI Industrial Centre of Excellence, the National AI Skills Observatory, and stackable microcredentials. The remaining challenge is the end-to-end pathway through which firms move from awareness and experimentation to production deployment and measurable gains. Public-sector leadership can help activate this pathway. Unlocking Europe’s AI Potential 2026, research conducted by Strand Partners for AWS, found that 68% of businesses said they were most likely to increase their AI adoption when the public sector leads. The report also identifies streamlined, open, and competitive public procurement as a means of creating early demand and real-world validation for innovators. For Cyprus, these findings support using responsible public-sector adoption to build trust, stimulate market demand, and strengthen the AI ecosystem. Infrastructure, tools, and training do not generate impact automatically. Businesses also need implementation capacity, domain knowledge, management support, workflow redesign, and change leadership. The AI Labor Stack framework describes these facilitator roles as the connective layer between technical innovation and productive use. Building this layer, while supporting inclusive workforce transitions, will help Cyprus translate its adoption targets into broad-based and resilient productivity growth. 6. Human oversight, transparency, and explanations Article/paragraph reference: Section 1.1, Fundamental Principles (pp. 1-2); Section 3.1.2, Design Principles (p. 19); Sections 3.9.2-3.9.6 (pp. 42-44); Annex A, Human-centred values and Transparency and explainability (pp. 54-55). Comment/recommendation: Retain meaningful transparency, contestability, and human oversight, but align each requirement with the risk, autonomy, context of use, and role of each actor in the AI value chain. Avoid universal human-in-the-loop or model-level explainability requirements. For systems that affect rights or access to essential services, safeguards should include clear accountability, appropriate human review or escalation, and understandable information about the role of AI in the decision. The Strategy should align its references to a right to explainability with Article 86 of the EU AI Act, which concerns explanations of the role of a specified high-risk AI system and the main elements of certain individual decisions. It does not establish a general right to disclosure of how an underlying model functions. Transparency obligations should protect intellectual property, trade secrets, confidential business information, and security-sensitive information. Rationale: Risk-appropriate human oversight and meaningful explanations support trust and accountability. A universal human-in-the-loop requirement, however, would not reflect the AI Act's differentiated framework and may be unnecessary or impractical for low-risk and assistive uses. Similarly, requiring access to model internals may not produce a useful explanation for an affected person and could expose proprietary or security-sensitive information. Focusing on the system's role, the relevant decision factors, available review mechanisms, and the responsibilities of the deployer provides more useful protection while preserving innovation and security. 7. Copyright, AI-generated works, and AIREG Article/paragraph reference: Annex C, Legal Services, Implementation and flagship programs (pp. 74-76). Comment/recommendation: Clarify the scope, purpose, governance, disclosure requirements, and intended legal effect of AIREG, including the definition of an ""AI asset."" Any registry should be voluntary, technology-neutral, and evidentiary. It should not purport to create an EU-wide presumption of ownership or alter applicable rules on authorship, ownership, exceptions, or enforcement without an appropriate legal basis. Registration should not require disclosure of model weights, training data, source code, trade secrets, confidential business information, or security-sensitive information. The use of blockchain should not be prescribed where other technologies can meet the same objective. Rationale: A registry can provide a timestamped record of a claim or support evidence management, but it cannot by itself establish authorship, ownership, validity, or enforceability across the European Union. Prescribing a specific technology or attaching an overly broad legal presumption could create uncertainty and conflict with existing national and EU intellectual-property frameworks. A voluntary, narrowly scoped approach can support innovators without creating a new mandatory disclosure or market-access mechanism. 8. AI-assisted judicial administration and adjudication Article/paragraph reference: Annex C, Legal Services, Implementation and flagship programs (pp. 74-76). Comment/recommendation: Support appropriate administrative applications, such as transcription, subject to accuracy, security, privacy, and data-protection safeguards. Reframe the proposed ""AI judge capability"" as AI-assisted judicial decision support. AI should not determine or issue judicial decisions; a judge should retain decisional authority, responsibility, and accountability. Any system materially assisting adjudication should be assessed under the applicable EU AI Act high-risk framework and should include safeguards for due process, data quality, auditability, transparency, contestability, human review, cybersecurity, and operational resilience. The framework should also distinguish purely ancillary administrative tools from systems used to research or interpret facts or law or to apply the law to a concrete case. Rationale: Judicial decisions can significantly affect fundamental rights, even where the financial value is low or facts are described as uncontested. Errors, changing circumstances, procedural issues, or power imbalances may still require judicial judgment and an effective route to challenge. AI can improve court administration and help judges work more efficiently, but final legal authority and accountability should remain with the judiciary. This distinction is consistent with the Strategy's broader commitment that technology should augment rather than replace professional judgment." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","CYPRUS ORGANISATION FOR STANDARDISATION","ΝΑΤΙΟNAL AI STRATEGY COMMENTING 31.08.2026 Strategy reference: Section 1.1, 1.4.3-1.4.10; and cross-cutting references to 'European standards'. Comment type: General / technical CYS comment: The Strategy refers broadly to European and international standards but does not define the categories concerned, their different legal effects, or how standards will support implementation across the Strategy. The expression 'European standards' may be interpreted differently by ministries, authorities and market actors. Standardisation should be expressly integrated across the objectives in Sections 1.4.3-1.4.10 rather than confined to isolated references. Proposed text for insertion or replacement Standardisation as implementation infrastructure. Cyprus shall use voluntary European, harmonised, International and National standards, together with open specifications, as practical instruments for AI governance, design, procurement, testing, assurance, deployment, monitoring, resilience and interoperability. For the purposes of this Strategy, ""European standards"" means standards adopted by CEN, CENELEC or ETSI under Regulation (EU) No 1025/2012; ""harmonised standards"" means European standards adopted in response to a Commission standardisation request in support of Union harmonisation legislation; ""international standards"" means those adopted by ISO, IEC or ITU; ""national standards"" means those adopted by the Cyprus Organisation for Standardisation (CYS); and ""open specifications"" means publicly available technical specifications developed through an open and consensus-based process by a body other than a recognised standardisation organisation. Only a harmonised standard whose reference has been cited in the Official Journal of the European Union may confer a presumption of conformity, and only for the requirements and conditions covered by that citation, in accordance with Article 40 of Regulation (EU) 2024/1689. Where harmonised standards are not available or are insufficient, common specifications adopted under Article 41 of that Regulation may confer an equivalent presumption. Other standards and specifications may support good practice and global interoperability but do not in themselves confer that effect. CY-02. Replace Section 1.4.10 with an international cooperation, standardisation and EU-alignment commitment Strategy reference: Section 1.4.10, International Cooperation and EU Alignment. Comment type: General / policy CYS comment: The current provision lists EU legislation and programmes but does not identify formal AI standardisation, participation routes, or the connection between the AI Act, international interoperability and related digital legislation. Proposed text for insertion or replacement - International Cooperation, Standardisation and EU Alignment The Strategy shall: (a) implement Regulation (EU) 2024/1689 (the AI Act) and prepare for the application of the European harmonised standards being developed by CEN-CENELEC JTC 21 in response to the Commission's standardisation request; (b) align, where appropriate, with the work of ISO/IEC JTC 1/SC 42 and with relevant ITU-T, ETSI and sector-specific standards, in order to support global interoperability and international trade; (c) support the active participation of Cypriot experts — from government, industry, SMEs, academia, research, professional bodies, workers, consumers and civil society — in CEN-CENELEC JTC 21, ISO/IEC JTC 1/SC 42, ETSI and other competent technical bodies, through CYS and the national mirror committee system; (d) use standardisation as a strategic policy instrument for innovation, interoperability, market access, procurement and conformity readiness throughout the AI lifecycle; (e) ensure coherence between AI implementation and Regulation (EU) 2016/679 (GDPR), Directive (EU) 2022/2555 (NIS2), Regulation (EU) 2019/881 (Cybersecurity Act), Regulation (EU) 2022/2554 (DORA), Regulation (EU) 2024/2847 (Cyber Resilience Act), Regulation (EU) 2023/2854 (Data Act), Regulation (EU) 2022/868 (Data Governance Act), Regulation (EU) 2024/1183 (European Digital Identity Framework) and other applicable legislation, and monitor pending instruments, including the proposed revision of the Cybersecurity Act and the proposed amendments to NIS2, as they are adopted; (f) strengthen participation in Digital Europe, Horizon Europe, EuroHPC, AI Factories, European Digital Innovation Hubs, Testing and Experimentation Facilities and initiatives of the European AI Office; and (g) foster bilateral and multilateral cooperation for knowledge exchange, responsible innovation and globally compatible governance. CY-03. Use European and international standards to establish Cyprus as a trusted AI jurisdiction Strategy reference: Section 2.5.1, Objective 1: Establish Cyprus as a trusted jurisdiction for AI. Comment type: General / policy CYS comment: The objective relies on governance, regulatory clarity and assurance but does not explain how organisations will demonstrate these qualities in a consistent and internationally recognisable way. Requested amendment: Extend Objective 1 to identify recognised European and international standards as part of Cyprus's trust and investment proposition Proposed text for insertion or replacement - Cyprus will position itself as a jurisdiction where AI is developed and deployed in a predictable, transparent, accountable and internationally interoperable manner. Trust will be built through strong governance, regulatory clarity, full alignment with European law, and the risk-based use of applicable European harmonised standards, other European standards adopted by CEN, CENELEC or ETSI, and internationally recognised standards from ISO/IEC, ITU-T and relevant sector bodies. The Cyprus Organisation for Standardisation (CYS), as the national standardisation body and in cooperation with the National AI Authority, will coordinate national participation in standardisation and the monitoring of relevant developments, so that Cypriot organisations can demonstrate recognised governance, risk-management, data-quality, security, lifecycle and assurance practices. Standards will be selected according to their legal role, system risk, sector and intended use, and do not replace compliance with applicable law. CY-04. Integrate data-quality and data-governance standards Strategy reference: Section 3.2, Data as a Strategic National Asset, and related sector data provisions. Comment type: Technical CYS comment: The Strategy correctly treats data quality, availability, interoperability and governance as prerequisites for trustworthy AI, but it does not establish a standards-based method for evaluating those qualities across the data lifecycle. Requested amendment: Require cross-sector and sector-specific data standards profiles, measurable quality criteria and reusable evidence. Proposed text for insertion or replacement - 3.2.6 Data Standards and Quality Assurance Data quality and governance must be demonstrable rather than merely asserted. This Strategy therefore establishes a standards-based method for defining, evidencing and assuring data quality across the AI lifecycle, building on the interoperability commitments set out in Section 3.2.3. The National AI Authority, in cooperation with the Cyprus Organisation for Standardisation (CYS) as the national standardisation body, together with data owners, competent authorities and sector stakeholders, will develop and maintain national data standards profiles. Each profile will specify, for each of the following dimensions, the applicable requirements or an express statement that none apply. Data quality dimensions will follow the data quality model and characteristics established in ISO/IEC 5259-2, selecting those relevant to the intended use, and for high-risk AI systems will address as a minimum the relevance, representativeness, completeness and freedom from errors required by Article 10 of Regulation (EU) 2024/1689, together with the balance and diversity characteristics relevant to bias examination. Governance dimensions will address terminology and shared semantics, metadata and documentation, provenance and traceability, access control, privacy and security, retention, and technical interoperability with the National Intelligent Digital API Fabric. Profiles select from and constrain the underlying standards; they do not modify or relax their requirements. Profiles will be developed at two levels: a cross-sector baseline applicable to all public-sector data, and sector-specific profiles for the priority sectors identified in Section 3.5, reflecting established health, financial, geospatial, public-sector and maritime data standards. For AI systems classified as high-risk under Regulation (EU) 2024/1689, profiles will be based on the European harmonised standards developed by CEN-CENELEC JTC 21 in support of Article 10 of that Regulation, in particular the standards on the quality and governance of datasets and on bias management, once those standards are published and their references cited in the Official Journal of the European Union.¹ For other systems, and for general data-quality modelling, profiles will draw on the ISO/IEC 5259 series developed by ISO/IEC JTC 1/SC 42, together with relevant ETSI and sector-specific standards. Conformity with a standard does not replace compliance with applicable law. Each AI use case will identify the applicable data-quality criteria, test methods, thresholds, responsible owners and retained evidence across training, validation, testing, deployment and monitoring, proportionate to its risk classification. This evidence forms part of the documentation required at the control gates set out in Annex B, and is reusable across subsequent use cases drawing on the same datasets, reducing duplication of assurance effort. The relevant standards are EN 18284 (Quality and governance of datasets) and EN 18283 (Bias management), currently in development by CEN-CENELEC JTC 21. CY-05. Define CYS's role in the governance architecture and prevent institutional overlap Strategy reference: Section 3.3.1; Section 3.3.1.1, paragraph 1; line 1283; line 1357; Section 4.3, NAICF; Annex C Government and Public Sector, lines 3585-3586; and the governance diagram. Comment type: General / governance CYS comment: CYS and the national Standardization system are absent from the governance architecture, although the Strategy proposes common frameworks and standards, certification and compliance mechanisms, and a National AI Authority mandate to 'provide standards'. The wording may create overlap with the statutory National Standardisation Body and with accreditation, conformity-assessment and regulatory functions. Proposed text for insertion or replacement Relationship with the national standardisation system The Cyprus Organization for Standardization (CYS) is the National Standardization Body of Cyprus, since January 1, 2005, and is responsible for all Standardization activities based on Law 156 (I)/2002. Within the national standardisation system, CYS is responsible for the adoption and publication of standards at national level, for managing the National Standardisation System and establishing National Technical Standardisation Committees for all domains of the Industry. CYS actively participates in International and European Standardization as a full member of the International Standardization Organizations ISO and ITU, as well as the European Standardization Organizations CEN, CENELEC and ETSI. CYS represents Cyprus in European and International Technical Standardization Committees for Artificial Intelligence as an equal member, always aiming to safeguard the national interests. CYS shall develop and maintain a National AI Standards Roadmap Report, published annually in coordination with the National AI Authority, mapping European and international standards to the objectives, implementation domains and priority use cases of this Strategy. The Roadmap Report shall be revised as necessary to reflect technological developments, new legislation and emerging standards, and shall inform the work of the National AI Authority in developing policy and governance frameworks and implementation guidance under Section 3.3.1. The National AI Authority is responsible for policy, governance frameworks, regulatory guidance, implementation mechanisms and oversight within its legal mandate. It does not adopt, publish or develop standards. Where implementation of this Strategy requires the use of standards, the National AI Authority will identify the requirement and CYS will act within its statutory remit. Competent authorities exercise statutory supervision and enforcement. The national accreditation body accredits conformity assessment bodies. Conformity assessment bodies perform assessment and certification under recognised schemes. National frameworks, registries and certification mechanisms established under this Strategy, including the National AI Compliance Framework, shall be designed to operate consistently with this division of functions and shall not duplicate accreditation or conformity assessment. References in this Strategy to the National AI Authority ""establishing common frameworks and standards"" or ""providing standards"" shall be read as ""developing policy and governance frameworks, implementation guidance and tools, in coordination with CYS where standards are implicated."" CY-06. Recognise and fund national delegates and participation in standards development Strategy reference: Section 3.12.2, Participation in European Initiatives; Section 3.3.1; Section 5 Immediate Steps; and Annex F. Comment type: General / implementation CYS comment: The Strategy does not recognise the work of CYS national delegates and experts or establish a mechanism for Cyprus to contribute to the European and international standards that will shape AI implementation and conformity assessment. Requested amendment: Add national standards participation to the Strategy and provide an accountable participation mechanism. Proposed text for insertion or replacement Cyprus will participate actively in the development of European and international AI standards through CYS as the national standardisation body. Active participation ensures that national interests and priorities are reflected in the standards Cyprus will subsequently adopt. At national level, CYS establishes and manages the National Mirror Committees, which bring together the national stakeholders concerned with a given field of standardisation, examine draft standards, form the national consensus position, and nominate the delegates and experts who represent Cyprus. This Strategy recognises the status of those delegates and experts and reinforces the existing subsidy scheme supporting their participation, extending it to the AI standardisation priorities identified under this Strategy. At European and international level, delegates act on the basis of the national consensus positions so formed. The priority bodies are the European technical committee CEN-CENELEC JTC 21 on artificial intelligence, the international subcommittee ISO/IEC JTC 1/SC 42 on artificial intelligence, the European technical committee ETSI TC SAI on securing artificial intelligence, and relevant sector committees, with participation open to public authorities, industry, SMEs, academia, research organisations, professional bodies, workers, consumers and civil society. CYS will coordinate national comments, delegate nominations, stakeholder consultation and periodic briefings. Participation priorities and expected outcomes will be set out in the National AI Standards Roadmap Report referred to in Section 3.3.1 and reviewed annually. CY-07. Mandate a living National AI Standards Roadmap Strategy reference: Sections 3.3, 3.11, 3.12.2 and 3.13; Section 5 Immediate Steps; and Annex F. Comment type: General / implementation CYS comment: The Strategy does not assign an owner, process, update cycle or implementation map for standards. A static list in the Strategy would also become obsolete as legislation, harmonised standards and international standards develop. Requested amendment: Require a CYS-coordinated National AI Standards Roadmap within six months of the Strategy's adoption and annual review thereafter. Proposed text for insertion or replacement - The National AI Standards Roadmap Report referred to in Section 3.3.1 shall be first published within six months of the adoption of this Strategy and reviewed at least annually thereafter. It shall be prepared by CYS in cooperation with the National AI Authority. The Roadmap Report shall: (a) map applicable legal requirements and the relevant standards, controls, tests and evidence artefacts; (b) identify each reference by category, distinguishing European harmonised standards, other European standards, international standards, national standards and open specifications as defined in Section 3.14; (c) state the current development status and legal effect of each reference, including whether a harmonised standard has been cited in the Official Journal of the European Union; (d) identify where sector, procurement, security and assurance profiles are required, for development in accordance with Section 3.2.6; (e) identify gaps in the standards landscape and priorities for national participation; and (f) be updated to reflect developments in legislation, standards and technology. Competent authorities, regulators, the national accreditation body, public procurement authorities and the Digital Security Authority will provide the information necessary for the preparation of the Roadmap Report within their respective remits. Wider stakeholder input, including from academia, industry, SMEs, workers, consumers and civil society, is secured through the National Mirror Committees. CY-08. Correct the treatment of AI management systems and AI risk management Strategy reference: Section 3.13.1, Identification and Assessment of Risks; and Section 3.11.2. Comment type: Technical CYS comment: The Strategy describes ISO/IEC 42001 as a risk-management standard. ISO/IEC 42001 specifies requirements for an organisational AI management system; ISO/IEC 23894 is the dedicated international guidance on AI risk management. ISO/IEC 27001 addresses information-security management and should not be presented as establishing AI governance or complete legal compliance. Requested amendment: Correct the standard references and require applicability to be determined by legal role, risk, sector and lifecycle stage. Proposed text for insertion or replacement - A common methodology will be applied across implementing bodies, provided by ISO/IEC 23894 (Guidance on risk management for AI) and applied within the organisational governance framework of ISO/IEC 42001 (AI management system), supported by ISO/IEC 42005 for AI system impact assessment. For AI systems classified as high-risk under Regulation (EU) 2024/1689, the European harmonised standards developed by CEN-CENELEC JTC 21 in response to the Commission's standardisation request are the standards intended to support conformity assessment.¹ Once published and cited in the Official Journal of the European Union, they confer a presumption of conformity with the requirements they cover. The applicability of any standard is determined by legal role, risk classification, sector and lifecycle stage, and is set out in the National AI Standards Roadmap Report. Implementation or certification of a management system does not by itself certify an AI system or establish compliance with all applicable legal requirements. The relevant standard is EN 18228 (AI Risk Management), currently in development by CEN-CENELEC JTC 21. CY-09. Strengthen operational resilience through continuous evidence and lifecycle assurance Strategy reference: Section 3.13.2, Operational and Institutional Resilience; Sections 3.4 and 3.8.5; and Annex B. Comment type: Technical / implementation CYS comment: The Strategy lists redundancy, fail-safe mechanisms, human override and contingency procedures but does not require continuous operational evidence for learning or dynamic AI systems whose performance and risk may change after deployment. Requested amendment: Add continuous monitoring, traceable evidence and standards-based lifecycle assurance, including consideration of ETSI TS 104 008 where applicable. Proposed text for insertion or replacement: Operational resilience will be supported by documented service objectives, redundancy, fail-safe and fallback arrangements, human-oversight and override mechanisms, incident response, recovery, change control and post-market monitoring. For learning, adaptive or otherwise dynamic AI-enabled systems, assurance plans will define measurable requirements, monitoring metrics, evidence sources, thresholds, escalation rules and responsibilities throughout operation. Where appropriate, organisations should consider ETSI TS 104 008, Continuous Auditing-Based Conformity Assessment for AI-enabled systems, or successor standards as a methodology for continuous evidence gathering and conformity-status review. Use of continuous or automated assessment will not remove requirements for competent human judgement, independence, legal accountability or formal conformity assessment where required. CY-10. Define the basis and institutional boundaries of AI audit and certification Strategy reference: Section 3.9.6, proposed Cyprus AI Security & Certification Authority; Section 4.3, NAICF; and related annual-audit references. Comment type: Legal / technical CYS comment: The proposed annual audit does not identify the object of assessment, applicable standards, conformity-assessment scheme, assessor competence, accreditation basis, evidence, legal effect or relationship with AI Act conformity assessment. A separate national certification label could create duplication or misleading claims of EU recognition. Requested amendment: Require recognised standards and schemes, define institutional roles and avoid creating an unsupported national AI-system certification regime. Proposed text for insertion or replacement: Any national AI audit, security or certification activity will be based on a published scheme identifying the object of assessment, the applicable legal requirements and standards, the scope of assessment, the evidence required, the frequency of assessment, requirements for independence and assessor competence, accreditation requirements, the decision process, surveillance arrangements, complaints and appeals procedures, conditions for suspension and withdrawal, and the legal effect of the outcome. ISO/IEC 42001 certification applies to the organisation, not to its AI systems. It confirms that governance, roles, processes and controls for AI are in place and maintained. Each AI system remains subject to the requirements applicable to it, including conformity assessment where the system is classified as high-risk. Harmonised standards are the standards developed to support the requirements of Regulation (EU) 2024/1689. Conformity with a harmonised standard confers a presumption of conformity with the requirements it covers, provided its reference has been cited in the Official Journal of the European Union. Within the national framework, CYS coordinates standards and national technical input. The national accreditation body accredits conformity assessment bodies. Conformity assessment bodies perform audits and certification under recognised schemes. Competent authorities retain supervision and enforcement. The National AI Compliance Framework, and any national body performing audit or certification functions, will not represent their outputs as conferring EU-wide recognition or certification of an AI system unless that effect follows from applicable Union law and an authorised conformity assessment route. CY-11. Reframe AIREG and the role of blockchain or DLT Strategy reference: Legal Services pillar, including the AIREG proposal on strategy pages 34 and 75-76. Comment type: Legal / technical CYS comment: The Strategy confines DLT largely to AIREG while using language such as 'immutable certification' and a strong presumption of ownership that may overstate the legal and evidentiary effect of a blockchain entry. Requested amendment: Require a technology-neutral feasibility and legal-design phase and define DLT as one possible evidence architecture rather than automatic proof or certification. Proposed text for insertion or replacement: AIREG will be subject to legal, evidentiary, data-protection, cybersecurity, identity, interoperability, governance and cost-benefit assessment before implementation. The assessment will compare centralised and distributed architectures and identify the authoritative source, validation rules, governance, correction and appeal mechanisms, retention, cross-border recognition, liability, off-chain data and exit arrangements. Where DLT is justified, it may support tamper-evident timestamping, provenance, integrity and multi-party evidence records. A register entry will not by itself validate the truth or lawfulness of submitted information, create intellectual-property rights, establish authorship, certify AI Act compliance or displace the powers of courts, registries, regulators and competent authorities. The selected architecture will align with relevant CEN/CLC JTC 19 and ISO/TC 307 standards and with AI, cybersecurity, identity, privacy and digital-evidence requirements. CY-12. Create a funded CYS-led AI standards uptake and conformity-readiness programme Strategy reference: Section 3.3.1; Sections 3.6 and 4.2-4.4; Section 5 Immediate Steps; and Annex F. Comment type: General / implementation CYS comment: The Strategy proposes training and funding but does not assign responsibility for standards literacy, standards implementation, procurement support or national expert participation, and does not define measurable outputs. Requested amendment: Establish a funded programme coordinated by CYS with the National AI Authority, Digital Security Authority and relevant sector bodies. Proposed text for insertion or replacement - Standards uptake and conformity readiness. The National AI Standards Roadmap Report referred to in Section 3.3.1 will be accompanied by a national standards uptake programme, coordinated by CYS in cooperation with the National AI Authority. The programme will provide standards guidance and training for public sector and industry users, standards support for public procurement, reusable assurance and evidence templates aligned with the national data standards profiles, and support for national expert participation in European and international standardisation. Standards uptake will be delivered through existing national training, SME support and innovation instruments established under Sections 3.6 and 4.4 of this Strategy, rather than through a separate delivery structure. Resourcing will be provided through existing mechanisms, including the national subsidy scheme for participation in standardisation. CY-13. Add definitions and standards profiles for every priority sector Strategy reference: Annex G Glossary and each Annex C priority-sector pillar. Comment type: Technical / editorial CYS comment: The glossary defines interoperability but not the principal standardisation and conformity-assessment concepts. Health is the clearest sector example, while other pillars lack an equivalent standards profile. Requested amendment: Add legal and technical definitions and require an annually updated standards profile for every priority sector. Proposed text for insertion or replacement - Annex G will define the following terms: standard; European standard; European harmonised standard; international standard; national standard; open specification; common specification; profile; conformity assessment; certification; accreditation; assurance; audit; validation; verification; and presumption of conformity. The definitions of the standards categories are those set out in Section 3.14. Each priority sector pillar in Annex C will include a standards profile, maintained by CYS in cooperation with the competent sector regulator or authority and with input from industry, SMEs, professional bodies, academia, workers, consumers and users, and updated annually as part of the National AI Standards Roadmap Report. Each profile will identify, for the sector concerned, the applicable cross-sector AI standards and domain-specific standards, organised according to the categories of the European standardisation request supporting Regulation (EU) 2024/1689: (a) risk management for AI systems (Article 9); (b) governance and quality of datasets used to build AI systems (Article 10); (c) record keeping through built-in logging capabilities (Article 12); (d) transparency and information to users of AI systems (Article 13); (e) human oversight of AI systems (Article 14); (f) accuracy specifications for AI systems (Article 15); (g) robustness specifications for AI systems (Article 15); (h) cybersecurity specifications for AI systems (Article 15); (i) quality management systems for providers of AI systems, including post-market monitoring (Article 17); (j) conformity assessment for AI systems (Article 43); and (k) supporting standards, including terminology. For each standard identified, the profile will record its designation and edition, its development status, its legal effect, its intended users, the criteria determining its applicability, and the owner responsible for updating the entry. CY-14. Add standards and standardisation sources to Annex H Strategy reference: Annex H Bibliography. Comment type: Editorial / technical CYS comment: The bibliography contains strategy and policy documents but no ISO/IEC, CEN-CENELEC or ETSI standards documents, despite the Strategy relying on standards for risk, security, governance and compliance. Requested amendment: Add authoritative standards references and maintain the detailed list through the National AI Standards Roadmap. Proposed text for insertion or replacement - Annex H will include, as sources for the standards relied on by this Strategy, CEN-CENELEC JTC 21, Artificial Intelligence — work programme and published deliverables, available at https://jtc21.eu, and ISO/IEC JTC 1/SC 42, Artificial Intelligence, available at https://www.iso.org/committee/6794475.html. Standards are available at national level through the Cyprus Organisation for Standardisation (CYS). Individual standards, their editions, status and legal effect are recorded in the National AI Standards Roadmap Report, which is maintained and updated as standards are published and revised. CY-15. Recognise Cyprus standards leadership in distributed-systems engineering and forensics and evidence Strategy reference: Section 3.12.2; Annex D Research and Innovation; Section 5 Immediate Steps; and relevant AI, DLT, finance, legal-services and public-sector pillars. Comment type: General / strategic CYS comment: The Strategy focuses on adopting technology and complying with external frameworks but does not identify credible routes through which Cyprus can contribute to the engineering foundations of emerging technologies. CYS identifies two distinct opportunities: a common methodology for describing distributed systems and the Cyprus-initiated ISO/TC 307/WG 10 work on forensics and evidence. Requested amendment: Include both opportunities as separate but complementary national standards-leadership workstreams, subject to the governance of the competent committees. Proposed text for insertion or replacement - Focus Area 7: Standards Engineering and Digital Evidence This area translates national research capability into contributions to the engineering foundations of AI and distributed systems, positioning Cyprus as a contributor to international standards rather than solely an adopter of them. It links directly to the governance, assurance and conformity readiness priorities of the Strategy. Priorities include: • A common, adaptable engineering methodology for describing distributed systems, covering stakeholders, components, data flows, governance, provenance and dependencies • Forensics and digital evidence for distributed systems, including chain of custody, admissibility, and the limits of what tamper-evident records demonstrate⁹⁹ • Development of national use cases from justice, financial services, public accountability and AI incident assurance to support committee work • Coordination of Cypriot expert participation, through CYS, in ISO/IEC JTC 1/SC 42, ISO/TC 307, ISO/TC 308, CEN-CENELEC JTC 21, CEN/CLC JTC 19 and relevant sector committees Work in this area is subject to the governance and approval procedures of the competent committees, and no deliverable will be presented as an adopted standard before committee approval. Expected outcomes include contribution to international standards deliverables, exportable national expertise in digital evidence, and earlier national readiness for conformity assessment in AI and distributed systems. ISO/TC 307/WG 10, Forensics and evidence, a working group of ISO/TC 307 Blockchain and distributed ledger technologies, established at the initiative of Cyprus. ISO/TC 307 holds liaisons with ISO/IEC JTC 1/SC 42 (Artificial intelligence), ISO/IEC JTC 1/SC 27 (Information security, cybersecurity and privacy protection) CY-16. Recognise the role of CYS and national delegates in Annex A (DSA) Strategy reference: Annex A, line 3058, sub-section ""Harnessing the EU AI Act to Accelerate National Innovation"". Comment type: General / policy CYS comment: Throughout the Strategy there is no real mention of the work and role of CYS and its national delegates within the AI sector in Cyprus. There need to be mentions of the work done by CYS and the Cyprus delegation, and its importance regarding the future of AI in Cyprus. Requested amendment: Under the sub-section ""Harnessing the EU AI Act to Accelerate National Innovation"", add a new section titled ""AI Standardisation"". Proposed text for insertion or replacement: AI Standardisation Standardisation will help Cyprus develop a trusted, interoperable and competitive AI ecosystem. European and international standards provide practical, technical and organisational requirements for the quality, safety, security, interoperability and responsible development and use of AI systems. The Cyprus Organisation for Standardisation (CYS), as the National Standardisation Body of Cyprus, plays a central role in managing the national standardisation system and in facilitating Cyprus's participation in European and international standardisation. CYS represents Cyprus in the relevant European and international technical standardisation committees, facilitates the participation of national experts and stakeholders in standardisation activities, and adopts relevant European standards as Cyprus Standards. CY-17. Recognise CYS's role in monitoring EU-level developments and standards Strategy reference: Annex A, paragraph 7, point 5, ""Monitor EU-Level Developments and Standards"". Comment type: General / policy CYS comment: Throughout the Strategy there is no real mention of the work and role of CYS and its national delegates within the AI sector in Cyprus. There need to be mentions of the work done by CYS and the Cyprus delegation, and its importance regarding the future of AI in Cyprus. Requested amendment: Add a sentence recognising the role of CYS in point 5 of the sub-section ""Harnessing the EU AI Act to Accelerate National Innovation"". Proposed text for insertion or replacement: After ""Monitor EU-Level Developments and Standards: To stay informed of evolving legislation, technical standards, and best practices, Cyprus will continue to maintain active engagement with EU institutions"", add: CYS supports Cyprus's engagement with relevant European standardisation activities through participation in Εuropean Standardization Technical Commitee CEN-CENELEC JTC 21 and through the dissemination and uptake of relevant standards at national level. CY-18. Clarify the National AI Authority's mandate in relation to standards Strategy reference: Annex C, Government and Public Sector, ""National AI Authority establishment"" row. Comment type: General / governance CYS comment: The reference to the National AI Authority's mandate to ""provide standards"" would benefit from further clarification. If the term refers to technical standards, harmonised standards, or standards supporting compliance with the AI Act, consideration should be given to the existing role of the Cyprus Organisation for Standardisation (CYS) as the National Standards Body and Cyprus's representative within CEN, CENELEC, ISO and IEC. To avoid potential overlaps of responsibility, the Strategy may distinguish between standards development and adoption, which fall within the remit of CYS, and the development of AI policies, guidance, governance frameworks and implementation mechanisms, which fall within the remit of the National AI Authority. Requested amendment: Amend the description of the National AI Authority's mandate so that it does not extend to the development or adoption of standards. Proposed text for insertion or replacement: Replace ""Authority with executive mandate to provide standards, enablement, compliance oversight, and platform operations"" with: Authority with executive mandate to provide governance frameworks and implementation guidance, enablement, compliance oversight, and platform operations, in cooperation with CYS as the National Standardisation Body where standards are implicated. CY-19. Strengthen Cyprus's international position through active contribution to standards development Strategy reference: Section 2.3.4, Strengthening the International Position, paragraph beginning ""The Strategy situates Cyprus…"". Comment type: General CYS comment: The Strategy appropriately identifies cooperation, interoperability and shared standards as important to Cyprus's international AI position. However, the current wording principally describes Cyprus as a participant in European and international initiatives. Given the existing and developing CYS programme of work in AI standardisation, Cyprus has an opportunity to contribute actively to the development of international standards and methodologies, rather than primarily adopting standards developed elsewhere. This would provide a concrete means of supporting the Strategy's stated ambition for Cyprus to become a trusted European AI hub and contributor to global norms. Requested amendment: Add a bullet recognising Cyprus's active contribution to international standards development. Proposed text for insertion or replacement: After the existing bullet ""Contribute to the development of global norms for responsible AI"", add: Contribute actively to the development of international AI standards, methodologies and guidance through CYS participation in European and international standardisation activities, with particular emphasis on areas where Cyprus can provide distinctive expertise and leadership. CY-20. Recognise standards and methodological leadership in the Vision Strategy reference: Section 2.4, The Vision: Where Cyprus Will Lead, key ideas. Comment type: General CYS comment: The Vision recognises that Cyprus should focus on areas where it can achieve leadership and differentiation rather than compete on scale. Standards development is an area in which a smaller Member State can exercise disproportionate influence through expertise, methodology and international collaboration. Explicitly recognising standards leadership would provide a realistic and distinctive route to European influence. Requested amendment: Add a sixth key idea to the Vision. Proposed text for insertion or replacement: Add following the existing five key ideas: 6.Standards and methodological leadership: Cyprus will seek to contribute to the development of international standards, methodologies and governance approaches in strategically important areas of AI, using its participation in European and international standardisation to create influence beyond the scale of its domestic market. CY-21. Extend the reuse and interoperability principle to use case description Strategy reference: Section 3.1.2, Design Principles, ""Reuse and interoperability"". Comment type: Technical CYS comment: The Strategy appropriately identifies common components and interoperable standards as a means of reducing duplication. The same principle could be extended to the description and analysis of AI use cases themselves. A common, structured methodology for describing use cases would improve consistency between institutions and sectors and enable systematic comparison and reuse. Inclusion of structured data-flow representations would additionally improve understanding of how data moves between actors, systems and governance boundaries. Requested amendment: Amend the ""Reuse and interoperability"" design principle to include common methodologies for describing and analysing AI use cases. Proposed text for insertion or replacement: Reuse and interoperability – Shared platforms, common components, interoperable standards, and common methodologies for describing and analysing AI use cases will be prioritised to reduce duplication, improve comparability, and increase efficiency across organisations and sectors. CY-22. Include structured data-flow representations in use case descriptions Strategy reference: Section 3.2.3, Interoperability and Secure Data Sharing, paragraph beginning ""AI requires…"". Comment type: General CYS comment: The Strategy identifies common data standards, shared definitions and interoperable architectures as strategic priorities. For AI governance, however, understanding the movement of data between actors, systems and organisational boundaries is also important for assessing privacy, security, accountability, provenance and risk. Structured representation of data flows within AI use cases would therefore complement the Strategy's data-governance objectives and improve the accessibility and auditability of use case descriptions. The ability to analyse different distributed systems, including AI, IoT and blockchain and distributed ledger technologies, using common metrics has the potential to provide an important governance dimension to the resulting engineering descriptions of apparently disparate systems. It also provides a basis for testing whether meaningful empirical comparisons can be made across different distributed system domains. Requested amendment: Add a sentence requiring structured representation of data flows in use case descriptions. Proposed text for insertion or replacement: Add at the end of the first paragraph: Use case descriptions should, where appropriate, include structured representations of relevant data flows, actors, system interactions and governance boundaries, supporting interoperability, risk assessment, accountability and auditability. CY-23. Establish a common methodology for describing and assessing AI use cases Strategy reference: Section 3.4.2, Use Case Driven Approach, and Section 4.4, AI Adoption Enablers. Comment type: Technical CYS comment: The Strategy places considerable emphasis on a use case driven approach and on reusable methodologies. This provides an opportunity to establish a common methodology for describing, assessing and comparing AI use cases across government and sectors. Such a methodology could be aligned with relevant international standards work and subsequently contribute to international standardisation. It would improve consistency, accessibility and comparability of use cases while supporting governance and reuse. The ability to compare AI systems with other distributed technologies using a common descriptive and analytical framework could provide a powerful governance mechanism, benefiting the assessment and development of all the systems being compared. This is particularly relevant as AI increasingly converges with other distributed technologies and infrastructure, making cross-domain understanding and comparison increasingly important for governance, assurance and standards development. Requested amendment: Require the development and maintenance of a common methodology for describing and assessing AI use cases. Proposed text for insertion or replacement: Add after the first paragraph of Section 3.4.2: A common methodology for describing and assessing AI use cases will be developed and maintained for application across government. The methodology will support structured description of actors, objectives, data flows, system interactions, governance considerations, risks and expected outcomes, enabling consistent assessment, comparison and reuse across sectors. CY-24. Support structured comparison of AI use cases in national evaluation Strategy reference: Section 3.11, Measuring Impact and National KPIs; Section 3.11.2, National Key Performance Indicators. Comment type: Technical CYS comment: The Strategy identifies comparability and actionability as important characteristics of national KPIs. A common structured methodology for AI use cases would provide a complementary basis for comparing use cases themselves, both within and across sectors. This could support more systematic evidence-based assessment of AI adoption, including identification of recurring patterns, outcomes, risks and implementation approaches. Requested amendment: Add a provision supporting structured comparison of AI use cases in national evaluation. Proposed text for insertion or replacement: Add after the KPI list: Where appropriate, national evaluation will also support structured comparison of AI use cases using the common methodology referred to in Section 3.4.2, enabling evidence and lessons from individual deployments to be compared and reused across sectors. CY-25. Define a common structure for use case description in Annex B Strategy reference: Annex B, AI Use Case Lifecycle and Control Gates, Purpose of the Lifecycle Approach and Stage 1. Comment type: Technical CYS comment: The Annex establishes a common lifecycle for AI use cases and explicitly seeks consistency across institutions. The methodology would be strengthened by defining a common structure for the description of use cases themselves, in addition to the lifecycle and control gates. In particular, structured data-flow representations can make use cases more accessible to different stakeholder groups and provide a basis for systematic comparison of AI use cases across institutions and sectors. This would also support governance by making data movement, system interactions and relevant accountability boundaries explicit. Requested amendment: Add a common structured methodology for the description of use cases. Proposed text for insertion or replacement: Add following the paragraph ""The use case lifecycle provides a common structure…"": Use cases will be described using the common structured methodology referred to in Section 3.4.2, which, where applicable, identifies the problem and objectives, stakeholders and roles, system interactions, data and data flows, governance and accountability boundaries, risks, controls, expected outcomes and relevant standards. The methodology supports comparison and reuse of use cases across institutions and sectors. CY-26. Proportionate guidance for smaller organisations and standards-based AI procurement Strategy reference: Section 3.4.1, Priority Areas for Government Adoption; Section 4.4, AI Adoption Enablers. Comment type: General / implementation CYS comment: Section 3.4.1 commits the government to establishing principles and prerequisites for AI-first procurement models by 2032, but does not identify what those principles and prerequisites will be. As the largest buyer of AI systems in Cyprus, what the state requires in tender documentation will shape supplier capability across the market. Separately, most Cypriot organisations will engage with Regulation (EU) 2024/1689 as deployers rather than providers, and the Regulation does not specify what level of documentation is sufficient for them. The Strategy does not address this gap. Proposed text for insertion or replacement: The principles and prerequisites for AI procurement will make use of European and international standards, applied according to their function. Technical requirements will be specified by reference to applicable standards, with equivalent means of demonstration permitted in accordance with public procurement law. Supplier capability will be assessed separately from the AI system being procured, and certification against a management system standard will not be treated as evidence of conformity of a system. Tender documentation will specify the documentation and artefacts to be transferred to the contracting authority, including the evidence a public body requires to meet its own obligations under Regulation (EU) 2024/1689, and the obligations applying during contract performance in relation to model update, monitoring and incident reporting. The applicable standards for each category of procurement will be identified in the National AI Standards Roadmap Report and in the relevant sector standards profiles. Requirements will be proportionate to the risk of the system and to the size of the supplier, so that participation by SMEs is not restricted." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","ΕΠΙΤΡΟΠΟΣ ΕΠΙΚΟΙΝΩΝΙΩΝ","Χαιρετίζουμε την ετοιμασία της Εθνικής Στρατηγικής Τεχνητής Νοημοσύνης (ΤΝ) και τη θέση της σε δημόσια διαβούλευση. Θεωρούμε ιδιαίτερα σημαντική τη σύνδεση της Στρατηγικής με το ευρωπαϊκό κανονιστικό πλαίσιο και ειδικότερα με τον Κανονισμό για την Τεχνητή Νοημοσύνη (AI Act). Οι Εθνικές Αρμόδιες Αρχές μπορούν να συμβάλουν όχι μόνο στην εφαρμογή και εποπτεία του πλαισίου αυτού, αλλά και στην παροχή κανονιστικής σαφήνειας και στην ενίσχυση της εμπιστοσύνης διευκολύνοντας έτσι την ασφαλή και υπεύθυνη αξιοποίηση της ΤΝ. Τα σχόλια που ακολουθούν υποβάλλονται λαμβάνοντας υπόψη το σύνολο των αρμοδιοτήτων του Γραφείου μας, περιλαμβανομένων των αρμοδιοτήτων του στο πλαίσιο του AI Act, της κυβερνοασφάλειας και των ηλεκτρονικών επικοινωνιών: 1. Πλαίσιο διακυβέρνησης και National AI Authority Στην ενότητα 3.3.1 η Στρατηγική προτείνει ένα ευρύ πλαίσιο διακυβέρνησης, το οποίο περιλαμβάνει διάφορα σώματα/δομές για την υποστήριξη και υλοποίησή της. Η «National AI Authority» περιγράφεται ως φορέας στρατηγικού συντονισμού και υλοποίησης αλλά και ως “governance and control gatekeeper” με αρμοδιότητα μεταξύ άλλων, για την ανάπτυξη κοινών πλαισίων και προτύπων και τη διασφάλιση ευθυγράμμισης με τον Ευρωπαϊκό Κανονισμό και τους εθνικούς στόχους πολιτικής. Θεωρούμε ότι θα ήταν χρήσιμο να αποσαφηνιστεί περαιτέρω ο ρόλος και οι αρμοδιότητες της National AI Authority καθώς και ο τρόπος αλληλεπίδρασής της με τις υφιστάμενες Εθνικές Αρμόδιες και Ρυθμιστικές Αρχές ιδιαίτερα σε θέματα που σχετίζονται με την εφαρμογή του AI Act. Παράλληλα προτείνεται να προστεθεί συγκεκριμένη αναφορά/παράγραφος στις υφιστάμενες εθνικές αρμόδιες αρχές και στις προβλεπόμενες αρμοδιότητές τους, ώστε να αποφεύγονται επικαλύψεις και να διασφαλίζεται η σαφής διάκριση μεταξύ στρατηγικού συντονισμού και πολιτικής και των εποπτικών ή ρυθμιστικών αρμοδιοτήτων των Εθνικών Αρμόδιων Αρχών. 2. National AI Compliance Framework (NAICF) Η Στρατηγική προτείνει τη δημιουργία ενός «National AI Compliance Framework (NAICF)», ευθυγραμμισμένου με το AI Act και με αξιοποίηση του ISO 42001 και του AIGP. Σύμφωνα με το κείμενο, το NAICF θα καθορίζει “standardised compliance protocols for developers and deployers”, θα υποστηρίζει κεντρικό εθνικό μητρώο AI systems certified under EU rules και θα συντονίζεται με το Research and Innovation Foundation (RIF) και το Office of the Chief Scientist για compliance readiness και auditing innovation. Σε άλλο σημείο της Στρατηγικής αναφέρεται επίσης ότι το NAICF θα έχει ρόλο “support certification, auditing, and regulatory oversight”. Η δημιουργία του National AI Compliance Framework (NAICF) μπορεί να αποτελέσει σημαντικό εργαλείο για την υποστήριξη της αγοράς, παρέχοντας πρακτική καθοδήγηση και κοινές μεθοδολογίες που θα διευκολύνουν developers και deployers στην κατανόηση και εφαρμογή των απαιτήσεων του AI Act. Στο πλαίσιο αυτό θα ήταν χρήσιμο να αποσαφηνιστεί περαιτέρω ο χαρακτήρας και η λειτουργία του NAICF, ιδιαίτερα σε σχέση με τις αναφορές της Στρατηγικής σε “standardised compliance protocols” και σε υποστήριξη “certification, auditing and regulatory oversight”. Η αποσαφήνιση αυτή θα βοηθήσει ώστε να διακρίνονται σαφώς τα εργαλεία και οι μηχανισμοί υποστήριξης της αγοράς που θα παρέχονται μέσω του NAICF από τις ρυθμιστικές υποχρεώσεις και τις επίσημες διαδικασίες συμμόρφωσης που προβλέπονται από το AI Act (π.χ. διαδικασία conformity assessment που διενεργείται από conformity assessment body ή διαδικασίες και εξουσίες των Εθνικών Αρμόδιων Αρχών βάσει του άρθρου 74). Σε σχέση με την πρόταση για δημιουργία κεντρικού εθνικού μητρώου AI systems certified under EU rules, θα ήταν χρήσιμο να διευκρινιστεί ο σκοπός και η προστιθέμενη αξία του μητρώου ώστε να αποφεύγεται η επικάλυψη με τα υφιστάμενα ενωσιακά εργαλεία και κυρίως η δημιουργία σύγχυσης ως προς τον επίσημο χαρακτήρα και τη νομική σημασία της εθνικής καταχώρισης. Θα μπορούσε να εξεταστεί ένα μητρώο με σαφώς προσδιορισμένο σκοπό, π.χ. ως χαρτογράφηση συστημάτων ΤΝ που δραστηριοποιούνται στην Κύπρο, χωρίς η καταχώριση να υποδηλώνει ή να συνεπάγεται επίσημη διαπίστωση συμμόρφωσης με το AI Act. 3. AI Industrial Centre of Excellence και AI Act compliance Στον πυλώνα Financial Services and Financial Technology αναφέρεται ότι το AI Industrial Centre of Excellence θα λειτουργεί ως “sandbox of sandboxes” και σε συνεργασία με το CySEC Innovation Hub και το Regulatory Sandbox θα κάνει “validate models against EU AI Act requirements before commercial deployment”. Σε άλλο σημείο το Industrial Centre of Excellence περιγράφεται ως φορέας που θα παρέχει resources, development and engineering και governance guidance, με στόχο μεταξύ άλλων, την επιτάχυνση της προετοιμασίας για συμμόρφωση με το AI Act. Θεωρούμε ότι θα ήταν χρήσιμο να αποσαφηνιστεί τι περιλαμβάνει στην πράξη η αναφορά σε “validation against EU AI Act requirements” και ποια είναι η σχέση αυτής της δραστηριότητας με το AI Regulatory Sandbox που προβλέπεται από το AI Act. Επίσης στην ενότητα 3.8.5 προβλέπεται η δημιουργία National AI Testbeds για real-world experimentation and validation, τα οποία θα μπορούν να επεκτείνονται μέσω sectoral sandboxes. Παράλληλα η Στρατηγική αναγνωρίζει ότι regulatory sandbox mechanisms(σελ. 32) μπορούν να χρησιμοποιούνται όπου ενδείκνυται για ελεγχόμενο πειραματισμό. Θεωρούμε ότι και σε αυτή την περίπτωση θα ήταν χρήσιμο να αποσαφηνιστεί περαιτέρω η διάκριση και η σχέση μεταξύ των διαφορετικών αυτών μηχανισμών και ειδικότερά, η θέση του AI Regulatory Sandbox που προβλέπεται από το AI Act στο ευρύτερο οικοσύστημα δοκιμών και καινοτομίας. 4. Control Framework – Incident Reporting Στην ενότητα 3.3.2 προβλέπεται η καθιέρωση διαδικασιών για incident reporting, escalation και remediation. Θα ήταν χρήσιμο να αποσαφηνιστεί η σχέση των διαδικασιών αυτών με τις υποχρεώσεις αναφοράς περιστατικών που προβλέπονται ήδη από το AI Act και άλλα εφαρμοστέα ευρωπαϊκά πλαίσια, ώστε να αποφεύγονται όπου είναι δυνατό παράλληλες διαδικασίες και πρόσθετο διοικητικό βάρος για τους επηρεαζόμενους φορείς. Η Στρατηγική θα πρέπει, ως εκ τούτου, να διατυπώνεται κατά τρόπο που να μην προδικάζει ή δημιουργεί de facto αρμοδιότητες για φορείς πέραν εκείνων που προβλέπονται από το εφαρμοστέο θεσμικό και νομοθετικό πλαίσιο. Στο πλαίσιο αυτό θα μπορούσε να εξεταστεί η δυνατότητα ενός ενιαίου σημείου υποβολής αναφορών και διαβίβασής τους στις κατά περίπτωση αρμόδιες αρχές. Για τα AI-related incidents που έχουν διάσταση κυβερνοασφάλειας, βλ. επίσης σχετικό σχόλιο στο σημείο 8 πιο κάτω. 5. Small and Medium-sized Enterprises and Small Mid-Cap Enterprises Η Στρατηγική προβλέπει σειρά μέτρων για την υποστήριξη των SMEs. Δεδομένου ότι το αναθεωρημένο AI Act, μετά τις τροποποιήσεις του Digital Omnibus on AI αναγνωρίζει πλέον ρητά και τις small mid-cap enterprises (SMCs) σε σειρά μέτρων υποστήριξης της καινοτομίας και απλούστευσης(simplification), θα μπορούσε να εξεταστεί κατά πόσο ορισμένες από τις σχετικές δράσεις της Στρατηγικής θα ήταν σκόπιμο να καλύπτουν και τις SMCs όπου αυτό κρίνεται κατάλληλο. 6. Annex D – Focus Area 5: Next-Generation Wireless Telecommunications Any deployment of AI-integrated network management, dynamic traffic routing, or network slicing (5G/6G) mentioned in the Strategy must operate in full compliance with Regulation (EU) 2015/2120 (Open Internet Regulation) and the relevant BEREC Guidelines. The application of AI for traffic optimization must not compromise the fundamental principle of net neutrality or lead to arbitrary traffic degradation. 7. Σχόλια στο Executive Summary i. Σε σχέση με την αναφορά «Security and Resilience: AI systems are designed to be robust against misuse, failure, and cyber threats. Protection against adversarial AI attacks, establishing operational redundancy, and secure operational guardrails are key priorities» Particular attention should be given to threats such as prompt injection, data poisoning, model poisoning, model manipulation, model inversion, model extraction and other adversarial machine learning attacks. Operational redundancy, continuous monitoring, secure operational guardrails and comprehensive incident response mechanisms should constitute key priorities. ii. Σε σχέση με την αναφορά «Embed ethical governance, transparency, and trust in the AI systems through EU AI Act alignment and robust national safeguards.» The explicit reference only to the EU AI Act not fully reflect the broader legal, regulatory and cybersecurity framework governing the development, deployment and operation of AI systems. To enhance clarity, legal certainty and implementation consistency, it would be beneficial to explicitly refer to the legislative, regulatory and standards framework upon which the national strategy is based. ie NIS2 Directive etc iii. Σε σχέση με την αναφορά «Transform public services through AI-enabled delivery, improving efficiency, accessibility and citizen experience while maintaining human oversight.» the wording could be changed as follows: ""Transform public services through AI-enabled delivery, improving efficiency, accessibility and citizen experience while ensuring meaningful human oversight, intervention, accountability, control, review and final decision-making authority whenever required."", since limiting human involvement solely to oversight may not be sufficient, particularly in the context of high-risk or safety-critical AI systems.Human involvement should extend beyond passive supervision and should include the authority and responsibility to intervene, challenge, override, suspend or terminate the operation of AI systems whenever necessary. iv. Σε σχέση με την αναφορά «Ensure secure, sovereign, and interoperable data and infrastructure foundations, and policies supporting resilience, security and strategic autonomy.» Μπορεί να συμπληρωθεί με την αναφορά By adopting robust cybersecurity, resilience and digital sovereignty principles, including encryption, zero-trust architecture, secure data-sharing mechanisms, secure MLOps practices, model protection controls and continuous monitoring capabilities. v. Σε σχέση με την αναφορά «Financial Services and Financial Technology: Anti Money Laundering (AML), compliance, intelligent insurance, AI-augmented CFO capabilities.» it is suggested to define the Terrorist Financing, transaction monitoring, sanctions screening, fraud detection. 8. Infrastructure, Compute and Digital Sovereignty Σε σχέση με την αναφορά «The National AI Infrastructure should serve as the shared computational and data backbone of Cyprus’s AI ecosystem, providing secure, scalable, and interoperable capabilities that support the full AI lifecycle, including model development, fine-tuning, inference, AI testing and validation, advanced scientific computing, and the deployment of AI solutions across priority sectors.» Σημειώνουμε «The European Union, in its Action Plan on Cybersecurity and Artificial Intelligence (07 July 2026), has highlighted that most advanced frontier AI systems are currently being developed outside the European Union, creating significant strategic dependencies. These dependencies may affect national resilience and cybersecurity. In this context, it would be beneficial to emphasise the importance of strengthening sovereign national capabilities, promoting trusted partnerships and reducing critical external dependencies while maintaining alignment with European values, security requirements and strategic interests» 9. Responsible Deployment and Monitoring Ιt would be beneficial to explicitly define the responsibilities of the relevant stakeholders in cases where an AI system causes operational disruption, compromises data integrity or becomes involved in a cybersecurity incident. 10. Εισήγηση: Στα Priority Sectors στης Εθνικής Στρατηγικής ΤΝ, να περιλαμβάνονται όλες οι κατηγορίες(sectors) οντοτήτων που εμπίπτουν στο πεδίο εφαρμογής της NIS2(κυρίως των sectors του παραρτήματος Ι της οδηγίας), δεδομένου ότι η ασφαλής και ανθεκτική υιοθέτηση της ΤΝ στις οντότητες αυτές έχει ιδιαίτερη σημασία για τη λειτουργία κρίσιμων και σημαντικών υπηρεσιών. Να σημειωθεί ότι οι οντότητες που εμπίπτουν στο σχετικό πλαίσιο οφείλουν να εφαρμόζουν κατάλληλα μέτρα για τη διασφάλιση της ασφάλειας, ανθεκτικότητας και ομαλής λειτουργίας δικτύων και πληροφοριακών τους συστημάτων, έναντι βλαβών, διαταραχών και κακόβουλων ενεργειών (Κ.Δ.Π. 389/2020). Ιδιαίτερα σημαντικό είναι ότι η σχετική απόφαση (Κ.Δ.Π. 389/2020) αναμένεται να τροποποιηθεί και να ενισχυθεί πολύ σύντομα (αναμένεται να εξαγγελθεί πολύ σύντομα δημόσια διαβούλευση) με επιπρόσθετες απαιτήσεις για την ασφάλεια των συστημάτων που σχετίζονται με τη Τεχνητή Νοημοσύνη. Επιπλέον, θα τροποποιηθεί η Απόφαση Κ.Δ.Π. 245/2024, με στόχο την ενίσχυση των Ελέγχων Ωριμότητας Κυβερνοασφάλειας μέσω της εισαγωγής πρόσθετων απαιτήσεων για την ασφάλεια των συστημάτων, συμπεριλαμβανομένων ειδικότερων απαιτήσεων που αφορούν την Τεχνητή Νοημοσύνη. Θα ήταν επομένως χρήσιμο, η AI Strategy να συνδέει την υιοθέτηση της ΤΝ από τις οντότητες της Οδηγίας NIS2 με την κυβερνοασφάλεια, την κυβερνοανθεκτικότητα και τη λειτουργική συνέχεια, αλλά και να αναδεικνύει ότι η ΤΝ μπορεί να αποτελέσει εργαλείο ενίσχυσης της ανίχνευσης απειλών, της διαχείρισης κινδύνων, της αντιμετώπισης περιστατικών και γενικότερα της επιχειρησιακής ανθεκτικότητας. 11. Ποιος θα είναι υπεύθυνος για τη διακυβέρνηση και την εποπτεία της ΤΝ στην Κύπρο και πώς θα διαχωρίζονται στην πράξη οι αρμοδιότητες των αρμόδιων Αρχών, όπως της National AI Authority και της ΑΨΑ, ιδιαίτερα σε περίπτωση που ένα AI σύστημα προκαλέσει ή εμπλακεί σε περιστατικό κυβερνοασφάλειας; Εισήγηση: Θα ήταν χρήσιμο η Στρατηγική να καθορίζει με μεγαλύτερη σαφήνεια τη σχέση και τα όρια αρμοδιότητας μεταξύ των αρμόδιων Αρχών, ώστε να αποφεύγονται επικαλύψεις ή κενά ευθύνης. Επιπλέον, θα ήταν σκόπιμο να προβλεφθεί ένας συντονισμένος μηχανισμός διαχείρισης AI-related cybersecurity incidents, ο οποίος θα αξιοποιεί το υφιστάμενο εθνικό πλαίσιο διαχείρισης περιστατικών κυβερνοασφάλειας. Θα πρέπει να αποφεύγεται η δημιουργία ενός παράλληλου και απομονωμένου “AI incident management system” που θα λειτουργεί ανεξάρτητα από το υφιστάμενο cyber incident-response framework. Αντίθετα, τα AI-related incidents θα πρέπει να εντάσσονται στο υφιστάμενο πλαίσιο, με τις απαραίτητες πρόσθετες διαδικασίες για τους ειδικούς κινδύνους της ΤΝ. 12. Πώς θα διαχωρίζονται στην πράξη οι αρμοδιότητες του AI Officer από αυτές του CISO και του DPO; Ποιος θα έχει την κύρια ευθύνη όταν ένα AI σύστημα παραβιαστεί, δεχθεί κυβερνοεπίθεση, υποστεί αλλοίωση του μοντέλου ή των δεδομένων του, προκαλέσει διαρροή προσωπικών δεδομένων ή επηρεάσει τη λειτουργία μιας κρίσιμης υπηρεσίας; Εισήγηση: Θα ήταν χρήσιμο να καθοριστούν με σαφήνεια οι ρόλοι και οι ευθύνες των εμπλεκόμενων λειτουργών, ώστε ο AI Officer να μην υποκαθιστά τον CISO ή τον DPO. Για AI-specific cybersecurity risks θα πρέπει να προβλέπεται υποχρεωτική συνεργασία AI Officer–CISO–DPO, ανάλογα με τη φύση του περιστατικού. 13. Ποιος θα έχει την εξουσία να αναστείλει ή να τερματίσει τη λειτουργία ενός AI συστήματος όταν διαπιστωθεί σοβαρός κίνδυνος για την κυβερνοασφάλεια, την προστασία δεδομένων, την ασφάλεια των πολιτών ή τη λειτουργία μιας κρίσιμης υπηρεσίας;" "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Ιατρικες Υπηρεσίες Και Υπηρεσίες Δημόσιας Υγείας","H Εθνικής Στρατηγικής για την Τεχνητή Νοημοσύνη (ΤΝ) αναγνωρίζει ως τομέα προτεραιότητας την θεματική «Healthcare and Life Sciences» και περιλαμβάνει σημαντικές αναφορές σε κλινικές εφαρμογές, δεδομένα υγείας, διαλειτουργικότητα και εκπαίδευση. Ειδικότερα το θέμα της Δημόσιας Υγείας πιστεύουμε ότι θα μπορούσε να αναδειχθεί ρητά ως διακριτό πεδίο εφαρμογής της ΤΝ, καθώς έχει διαφορετικές ανάγκες από την κλινική φροντίδα και σημαντικές δυνατότητες αξιοποίησης μεγάλων και ετερογενών συνόλων δεδομένων σε πληθυσμιακό επίπεδο. Ιδιαίτερα από την οπτική της Δημόσιας Υγείας, θα μπορούσε να δοθεί μεγαλύτερη έμφαση στην επιδημιολογική επιτήρηση, την έγκαιρη ανίχνευση και εκτίμηση κινδύνου, την προσέγγιση “One Health”, την υποστήριξη της λήψης αποφάσεων και την αξιοποίηση δεδομένων σε επίπεδο πληθυσμού. Προτείνεται να εξεταστούν προσθήκες, όπως: 1. “Artificial Intelligence for Public Health” AI should be leveraged to strengthen public health surveillance, early detection and risk assessment, outbreak preparedness and response, and evidence-informed public health decision-making. Priority should be given to applications supporting the analysis of population-level, epidemiological, laboratory, environmental and other relevant data in a timely and integrated manner. Specific use cases could include: • Epidemiological surveillance and early detection of threats, through real-time data analysis, predictive analytics and early warning systems. • One Health, through the integration of human health, animal health and environmental data, combined with GIS, environmental indicators, sensors and other surveillance systems. • Support for evidence-informed decision-making, through predictive modelling, risk assessment and simulation tools to assess the potential impact of different public health interventions. • Addressing misinformation and infodemics, particularly during public health emergencies. • AI copilots for public health professionals, to support information retrieval and synthesis, data analysis, risk assessment and report generation, while maintaining appropriate human oversight. • Smart and dynamic electronic forms and processes, which adapt to the information entered during inspections, assessments or investigations, reducing administrative burden and improving data quality. 2. Health-specific assessment of real-world impact and added value The Strategy already recognises the importance of measuring the added value and impact of AI solutions in healthcare, including through measuring their contribution for wait time reduction, time to assessment, triage accuracy etc. It would nevertheless be useful to further specify a framework for public health which could include indicators such as: Positive predictive value and timeliness of alerts, forecast accuracy (Accuracy of predicted cases, hospitalisations, outbreaks, etc.), Outbreak impact (Reduction in outbreak size/duration where AI contributes to intervention), Health outcomes (Change in relevant morbidity, mortality or other outcomes), Workload reduction of Public Health personnel 3. Specialised AI Training for Healthcare and Public Health “In addition to general AI literacy, specialised training should be developed for healthcare and public health professionals, covering the interpretation and appropriate use of AI outputs, model limitations, human oversight, data protection, bias, uncertainty and responsible use of AI in professional decision-making.” Furthermore, in the Page 70 table (under the column “Expectation for 2026-2032” and for the strategic direction “Workforce upskilling and Socratic learning”), the expectation is Socratic AI-driven learning pathways and national capability building, aiming for 50% of the medical workforce trained in AI-enabled practices by 2032. We suggest that capacity building should not be restricted to the medical workforce, but should extend to healthcare and public health professionals, recognising that the responsible and effective use of AI requires relevant competencies across the wider health and public health workforce. 4. Public Health Data, Interoperability and One Health Under chapters “National frameworks and governance” (page 68) and “Implementation, evidence and compliance” (page 69) for Healthcare and Life Sciences we consider it important that the reference to health data be expanded to more explicitly include public health data. The strategy could include: “The development of AI in health should be supported by high-quality, interoperable and securely governed datasets, including clinical, public health, epidemiological, laboratory, and, where feasible environmental and animal health data, in line with a One Health approach.” 5. European Union document reference for AI in healthcare Under chapter “International alignment” (page 68) for Healthcare and Life Sciences we suggest to add reference after the sentence “Cyprus will align implementation to WHO guidance and to European principles for trustworthy, human-centred AI in health.” Reference to add: European Commission: Directorate-General for Health and Food Safety, PwC, EEIG and Open Evidence, [Directorate-General for Health and Food Safety, PwC, EEIG, Open Evidence], Study on the deployment of AI in healthcare – Final report, Publications Office of the European Union, 2025, https://data.europa.eu/doi/10.2875/2169577 6. Applications of AI in public health (Oleribe et al., 2026 – table 1) - Component: Assessment and Monitoring of Health; Predicted Roles: Use AI-powered “digital twins” of populations to simulate community health trends in real time; Expected Outcomes: Provide predictive analytics and preventive interventions enabling early detection of health risks and proactive interventions in populations, not just retrospective analysis. - Component: Surveillance and Disease Control; Predicted Roles: Automated global surveillance networks integrating health, climate, and travel data; Expected Outcomes: Detect outbreaks before the first local report. - Component: Health Promotion and Education; Predicted Roles: Immersive AI-driven personalized health coaching (VR-ECAs); Expected Outcomes: Adapt to cultural context and personal motivation dynamically. - Component: Policy Development and Planning; Predicted Roles: Co-designing policy with AI by simulating economic, social, and health trade-offs instantly; Expected Outcomes: Predict long-term equity and economic impacts of policies in real time before implementation. - Component: Health Protection and Regulation; Predicted Roles: Continuous AI-driven monitoring of supply chains, environmental systems, and workplaces; Expected Outcomes: Flag, report, and even correct hazards in real time. - Component: Prevention Services; Predicted Roles: AI-guided precision prevention at the individual genetic and behavioral level; Expected Outcomes: Deliver fully personalized preventive care recommendations integrated into daily life. - Component: Workforce Development; Predicted Roles: AI mentors and digital assistants to guide public health professionals through tasks; Expected Outcomes: Provide context-aware coaching during fieldwork or emergencies. - Component: Community Engagement and Partnerships; Predicted Roles: AI-enabled “societal digital twins” that model disease outbreaks and how proposed interventions affect trust and equity. ; Expected Outcomes: Forecast community response to interventions before rollout, preventing mistrust and resistance. - Component: Emergency Preparedness and Response; Predicted Roles: Fully autonomous logistics systems powered by AI and drones; Expected Outcomes: Support logistics systems in disasters and pre-position resources. - Component: Evaluation and Research; Predicted Roles: AI-driven discovery engines that generate new hypotheses, design trials, and interpret results; Expected Outcomes: Conduct near real-time global meta-analyses and adapt interventions. Bibliography: Oleribe, O. O., Uzoaru, F., Tarfa, A., Olaniran, O. H., & Taylor-Robinson, S. D. (2026). Transforming Public Health Practice with Artificial Intelligence: A Framework-Driven Approach. Healthcare, 14(3), 385. 7. Γενικά σχόλια Επίσης θεωρούμε ότι θα πρέπει να διευκρινιστεί ο τρόπος που θα είναι προσβάσιμα τα δεδομένα υγείας δεδομένου ότι απαιτείται συνεργασία μεταξύ διαφορετικών φορέων για την υγεία όπως Υπουργείο Υγείας, Οργανισμός Ασφάλισης Υγείας, Οργανισμός Κρατικών Υπηρεσιών Υγείας, Εθνική Αρχή Ηλεκτρονικής Υγείας, Εθνική Επιτροπή Βιοηθικής, Πανεπιστήμια, Ερευνητικά Κέντρα, κέντρα και εργαστήρια του εξωτερικού. Τα κλινικά δεδομένα θα πρέπει να είναι ανώνυμα και η Υπηρεσία μας θα πρέπει να έχει πρόσβαση σε αυτά για την περαιτέρω ανάλυση τους για την πρόληψη επιδημιών. Θεωρούμε σημαντικό ότι έχει ψηφιστεί ο περί Ηλεκτρονικής Υγείας Νόμος (59(Ι)/2019) ο οποίος προβλέπει τη δημιουργία ηλεκτρονικού φακέλου ασθενών στον οποίο θα περιέχονται το βασικό σύνολο δεδομένων υγείας των πολιτών. Βάσει του νόμου οι πολίτες διατηρούν το δικαίωμα για κλείδωμα ορισμένων δεδομένων υγείας τα οποία θα καθίστανται μη προσβάσιμα στον πάροχο υπηρεσιών υγείας. Επίσης ο πάροχος υπηρεσιών υγείας έχει πρόσβαση στον ηλεκτρονικό φάκελο υγείας μόνο εάν έχει εξουσιοδότηση από τον κάτοχο του ηλεκτρονικού φακέλου υγείας. Ως εκ τούτου εισηγούμαστε όπως γίνει αναφορά στους φορείς του τομέα της υγείας οι οποίοι δημιουργούν, καταχωρούν και επεξεργάζονται δεδομένα υγείας και να γίνεται αναφορά στην συγκατάθεση των πολιτών για την πρόσβαση των κρατικών υπηρεσιών δημόσιας υγείας για την ανώνυμη επεξεργασία τους." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",ffeast83,"Excellent and highly ambitious document! However, as a practicing IT specialist living and working in Cyprus, I would like to offer some pragmatic, technical adjustments to ensure this Strategy translates into successful, resilient, and highly impactful implementation. To make this feedback easy to process for the working group, I have structured my suggestions into two logical categories: Horizontal Enablers and Sector-Specific Initiatives. SECTION 1 - HORIZONTAL ENABLERS AND INFRASTRUCTURE 1.1 - G-Cloud Migration Timeline and Operational Stress-Testing [Reference: Strategy Document, Section 3.4 ""AI Adoption Across Government"" and Annex C ""Government and Public Sector"", Page 62] THE BLUEPRINT TIMELINE: The roadmap currently schedules G-Cloud architecture design completion for December 2026, with the migration of the first three pilot applications completed by March 2027. THE OPERATIONAL CHALLENGE: A three-month window to migrate legacy government systems into a brand-new hybrid cloud environment is an extremely high-risk schedule that even agile private corporations rarely manage. A rushed sprint here poses severe architectural, operational, and security risks, including database integration failures, service downtime, and security vulnerabilities. THE PROPOSED ADJUSTMENT: I suggest extending the pilot migration window from three to nine months, targeting September 2027. We should explicitly mandate that these first three applications must consist of non-critical, static datasets, such as public archival databases. This will allow the team to thoroughly stress-test G-Cloud's security baselines and API Fabric before any high-risk personal or transactional databases are touched. 1.2 - AI Talent Target Segmentation (Class-A vs. Class-B) [Reference: Strategy Document, Section 3.6 ""Talent, Skills and Workforce Transformation"" and Annex C ""Education and Human Capital Development - FutureAI CY"", Page 80] THE KPI IN THE BLUEPRINT: The strategy aims to train 3,000 AI professionals by 2032 through stackable micro-credentials of 5 to 15 ECTS (approx. 150-450 hours of study). THE OPERATIONAL CHALLENGE: Grouping high-end ML engineers, no-code creators, prompt writers, and basic public sector users under a single target of 3,000 professionals obscures the real engineering gap. A 150-hour course can train an administrator to use an AI interface, but it cannot produce an engineer capable of fine-tuning LLMs, managing security, or preventing model hallucinations in sensitive sovereign systems. THE PROPOSED ADJUSTMENT: Subdivide the 3,000-talent target into two distinct tracks. Class A should cover core ML Engineers and AI Architects with a dedicated target of at least 15% (450+ specialists). Class B should cover No-code Creators and Business Users for the remainder of the training pool. Funding under the FutureAI CY program should prioritize rigorous, long-term engineering tracks to build the actual technical capacity required for digital sovereignty. 1.3 - ""Zero-AI Baseline Test"" to Prevent AI-Washing in Public Procurement [Reference: Strategy Document, Section 3.1.2 ""Value-driven deployment"", Page 19 and Annex C, Page 61-62] THE TARGET IN THE BLUEPRINT: Flagship public sector initiatives, such as the Digital Company 2.0 registration processes or the Skills and Labour Market Platform (NASO), are currently categorized under the core AI portfolio. THE OPERATIONAL CHALLENGE: Aggregating job postings or automating basic business registrations are standard, deterministic database tasks. They are 100% solvable using secure relational databases, clean API integrations, and standard BI dashboards. Introducing probabilistic AI/LLMs where absolute, auditable accuracy is required introduces unnecessary risks of ""hallucinations"" and inflates software vendor quotes by 3x to 5x. THE PROPOSED ADJUSTMENT: Integrate a mandatory Zero-AI Baseline Test within the ApplyAI project selection framework. Before approving AI-specific budgets, the National AI Authority must verify if the problem can be solved with high accuracy using classical automation, secure APIs, and relational databases. If yes, the project must be routed to standard digital transformation budgets (DMRID), preserving scarce AI-expert hours and GPU capacities for truly complex cognitive workloads (such as court transcription or medical image diagnostics). SECTION 2 - SECTORAL INITIATIVES AND COMPLIANCE 2.1 - ""Simplified Compliance Sandbox"" for Startups and SMEs [Reference: Strategy Document, Section 3.11.2, Page 45 and Annex C ""Government and Public Sector - Private Companies"", Page 60] THE CONSTRAINT IN THE BLUEPRINT: To access state-subsidized grants, public datasets, or the national GPU cloud, private companies must share their ethical AI strategies and adhere to rigorous ISO 42001 and ISO 27001 standards. THE OPERATIONAL CHALLENGE: Enforcing formal ISO compliance on early-stage local startups and SMEs (with under 1 million Euros in turnover) creates an insurmountable financial and bureaucratic barrier, stifling local tech entrepreneurship before it can take root. THE PROPOSED ADJUSTMENT: Implement a Simplified Compliance Sandbox for startups and micro-SMEs. Instead of requiring external ISO certification on day one, the Ministry should provide free self-assessment templates, pre-audited compliance checklists, and automatic access to state-subsidized cloud resources. Formal ISO audits should only become mandatory once a startup matures or scales to high-risk public utility deployments. 2.2 - Establishing Physical IoT Foundations as a Prerequisite for ""Destination Digital Twins"" [Reference: Strategy Document, Annex C ""Tourism and Hospitality"", Page 71-73] THE TARGET IN THE BLUEPRINT: The strategy proposes developing complex ""Destination Digital Twins"" for tourism hubs (Limassol, Ayia Napa) to simulate climate impacts, heatwaves, and resource bottlenecks. THE OPERATIONAL CHALLENGE: A true digital twin is a dynamic mathematical model that requires continuous, real-time data streams to be useful. On Cyprus, real-time data streams from existing local utility sensors remain highly fragmented, siloed across disparate municipalities, and lack unified standards and API integrations. Building predictive AI simulations without clean, real-time data pipelines is mathematically impossible and risks wasting budgets on static 3D maps that offer limited operational utility. THE PROPOSED ADJUSTMENT: Postpone the modeling phase of ""Digital Twins"" to Phase 2 (post-2028). Reallocate Phase 1 budgets to co-fund the physical rollout of IoT sensor networks (smart water and electricity meters for hotels, traffic sensors) and to establish a Unified National IoT and Sensor Data Standard. Building this solid physical data foundation is a mandatory prerequisite before any intelligent predictive simulation can be successfully deployed." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Marios THOMA","The comments address three key dimensions of the Cyprus National AI Strategy 2032: (1) Governance, (2) Standardisation and Assurance, and (3) Technological and Security Sovereignty. COMMENTS 1. National AI Authority: Considering the evolving AI landscape and the strategic, cross-sectoral and security-sensitive implications of AI, the effective implementation of the Strategy should consider the establishment or designation of a strong and appropriately independent National AI Authority. Such an Authority could serve as the central institutional mechanism for coordinating the implementation of the Cyprus National AI Strategy 2032, while ensuring alignment with the National Interest and the broader European regulatory and policy framework. Given the strategic and cross-sectoral nature of its mandate, the Authority should operate under an appropriate legal framework, with clearly defined responsibilities, powers, accountability mechanisms and interfaces with the existing competent authorities of the Republic. Its governance and modus operandi should reflect the strategic importance, security requirements and institutional safeguards associated with national-level authorities dealing with critical and security-sensitive matters, while avoiding duplication or interference with the statutory responsibilities of existing authorities. The National AI Authority could provide the central governance and coordination layer required to align national activities across the Research, Innovation, Development and Deployment (R&I&D&D) lifecycle of AI. Its overarching purpose should be to ensure that AI capabilities are researched, developed, acquired and deployed in a trusted, secure, resilient and sovereign manner, while protecting people, critical assets, strategic resources and national data; managing systemic risks, technological dependencies and supply-chain exposure; and safeguarding the sovereignty, resilience, security and long-term strategic interests of the Republic of Cyprus. Given the strategic significance and horizontal responsibilities, its institutional positioning should reflect a level of authority and access commensurate with other relevant national security and strategic authorities of the Republic. (A) Proposed amendment to the Strategy: The establishment, designation, mandate and institutional positioning of a National AI Authority should be considered and discussed at the appropriate political and governmental level, taking into account the existing national institutional architecture and the applicable EU AI governance framework. 2. Standardisation and AI Assurance: Standardisation should constitute an integral component of the National AI Strategy and its implementation framework. This is critical for establishing the necessary levels of trust, interoperability, security, conformity and assurance across national AI activities. National participation in European and international AI standardisation is also strategically important for ensuring that Cyprus can both implement emerging standards and contribute to their development, particularly in areas related to trustworthy AI, cybersecurity, data, cloud/edge computing, AI assurance and conformity assessment. The contribution of the national standardisation bodies and relevant national experts of the Republic of Cyprus should therefore be explicitly incorporated into the governance and implementation mechanisms of the Strategy. (A) Proposed amendment to the Strategy: Section 3.3.1 – Governance Structure should include explicit provisions defining the role of the relevant national standardisation entities and mechanisms for integrating European and international standards into the national AI governance and assurance framework. 3. Chips – AI Infrastructure – Quantum Security: The strategic link between Section 3.7.5, “Integration with EuroHPC and the European AI Factory Ecosystem,” and the European semiconductor and chips ecosystem is fundamental (also the Quantum security part). AI capabilities increasingly depend on advanced processors, AI accelerators, heterogeneous computing architectures, chiplets and specialised semiconductor technologies. At the same time, a gap remains between chip-level security engineering and AI infrastructure security. Addressing AI infrastructure security exclusively at the software, platform or application layers would therefore leave an increasingly important part of the AI technology stack insufficiently addressed. Specific provisions should consequently strengthen the integration of chip and chiplet security engineering into national AI activities, including security-by-design, hardware roots of trust, trusted execution, supply-chain assurance, hardware-level resilience, secure lifecycle management and advanced semiconductor security engineering. As AI capabilities and infrastructures continue to expand, the convergence of AI, high-performance computing and trusted semiconductor technologies is becoming strategically important for the security, resilience and technological sovereignty of European and national AI infrastructures. The National AI Strategy should therefore recognise the hardware–software continuum as a fundamental dimension of AI sovereignty, addressing not only algorithms, data, software and computing capacity, but also the trusted semiconductor technologies on which those capabilities ultimately depend. (a) Proposed amendment to the Strategy: (A) Section 3.7.5 should include provisions strengthening the connection between AI infrastructure and the chips/chiplet ecosystem supported by tangible implementation actions. These could include, inter alia: (i) strengthening the participation of the Republic of Cyprus and its research and industrial ecosystem in relevant Chips Joint Undertaking (Chips JU) programmes and calls, (ii) supporting national R&D and investment in semiconductor, chiplet, hardware-security and AI-accelerator technologies, (iii) promoting participation in European semiconductor and AI infrastructure value chains, (iv) developing national capabilities in trusted and secure AI hardware, (v) connecting semiconductor research and innovation with EuroHPC, AI Factories and national AI infrastructure initiatives, (vi) supporting the development of a national ecosystem capable of addressing the full AI technology stack, from trusted hardware and computing infrastructure to data, models, applications and services. (B) AI, Cybersecurity and Quantum Security: Particular consideration should also be given to the convergence of AI, cybersecurity, semiconductor technologies (chip/chiplet) and quantum security. The development of increasingly powerful AI and HPC infrastructures introduces new security dependencies and systemic risks, including those associated with future quantum capabilities and the transition towards post-quantum and quantum-secure technologies. The Strategy should therefore establish a clear connection between the development of national AI capabilities, the chips/chiplet ecosystem, cybersecurity and quantum security, promoting security-by-design across the complete technology stack. This should include consideration of post-quantum cryptography, crypto-agility, trusted hardware, secure key management, hardware-assisted security, quantum-safe migration and, where appropriate, complementary quantum-security technologies. Given the highly cross-cutting nature of these domains, consideration could also be given to the idea of a national capability or coordination function at the intersection of AI, Cybersecurity, Quantum Security and Trusted Semiconductor Technologies. Such a capability could support the national AI ecosystem, monitor technological and security developments, coordinate relevant R&D and innovation activities, strengthen participation in European initiatives, and provide specialised technical expertise to competent national authorities and stakeholders and support the security of Critical Assets of the Republic. The appropriate institutional form i.e Centre of Excellence, specialised competence centre, or another suitable mechanism, should be subject to further analysis, taking into account existing national structures, competencies and European initiatives, with the objective of avoiding duplication while closing identified strategic and technological capability gaps." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Christiana Aristidou","HLTF-29. Publish an accessible, version-controlled and authoritative final Strategy Strategy reference: Whole document; Annexes G–H Comment type: Transparency / drafting / accessibility Comment and implementation risk. The 101-page document contains inconsistent body names, undefined frameworks, incomplete citations, drafting errors and a bibliography with no standardisation documents. It is available in English despite being a national public-policy instrument. A strategy that will guide procurement and compliance must have a reliable authoritative version, source hierarchy and amendment history. Requested amendment. Complete legal and technical editorial review; publish Greek and English versions, accessible formats, source register and change log. Proposed text for insertion or replacement Publication, version control and accessibility. Before adoption, the Strategy shall undergo legal, technical, linguistic and accessibility review. The Republic shall publish authoritative Greek and English versions, an accessible HTML version, a concise citizen summary and machine-readable annexes. Each version shall show approval authority, approval date, version number, change history and next review date. Defined terms and institutional names shall be consistent. Citations shall identify complete titles, dates, versions and stable links; primary law and official materials shall take priority over media, vendor and unsourced benchmark claims. Annex H shall include applicable EU and national law, CYS’s legal basis, CEN-CENELEC/ETSI work and relevant ISO/IEC standards. A public correction process shall address errors discovered after adoption. 4. Cross-cutting implementation package The following package converts the detailed amendments into a practicable delivery sequence. Dates run from final adoption of the Strategy, not from the consultation draft. Before final adoption 1. Complete legal and technical editorial review; update the AI Act timetable; remove or condition initiatives that lack legal authority. 2. Prepare the concordance with the final national AI implementing law and a definitive governance/RACI schedule. 3. Publish the methodology, comparator selection, evidence register and consultation-response report. 4. Reconcile all KPIs, dates, body names and glossary terms; produce authoritative Greek and English versions. Within 90 days 1. Publish the Digital Strategy 2020–2025 transition evaluation and current digital/data/cloud/interoperability baseline. 2. Agree cooperation protocols among the Deputy Ministry, competent AI authorities, CYS, the accreditation function, sector regulators and data/cyber authorities. 3. Create the legal-dependency register, public-sector AI inventory and standards roadmap. 4. Issue interim approval gates for legality, FRIA/DPIA, security, procurement, data and architecture. Within 120–180 days 1. Publish model AI tender and contract schedules, sector implementation dossiers and a national sandbox framework. 2. Cost the delivery portfolio; assign owners; define benefits, stop/scale criteria, independent assurance and evaluation. 3. Launch SME/startup clinics, compute/testing support and standards-participation funding. 4. Complete infrastructure criticality, concentration, energy, water, continuity and exit assessments. Annually 1. Publish a consolidated report on spending, outcomes, rights impacts, incidents, complaints, standards, market concentration, energy/water and stopped initiatives. 2. Update the law-and-standards register and sector profiles; record every material change to targets, scope or governance. 3. Commission independent evaluation and parliamentary/public scrutiny of high-impact public-sector uses. 4.1 Conditions before the first transformational procurements Minimum launch gate No major AI tender should be issued merely to meet the draft eight-month timetable. The minimum package is: named accountable owner; lawful purpose and AI Act classification; current data and system architecture; integrated rights/security assessment; budget and benefits case; standards profile; market and concentration analysis; complete contract schedules; independent assurance route; incident and evidence plan; portability and funded exit; and published decision to proceed. 4.2 Proposed annual assurance statement The accountable National AI Authority should publish a signed annual statement confirming which commitments were delivered, which were not, material departures from law or standards, unresolved high risks, total expenditure, realised benefits, major incidents and complaints, concentration exposures, and the actions required for the following year. The statement should be subject to independent audit or evaluation appropriate to each claim; it should not be called a conformity certificate unless issued under a defined lawful scheme.   Annex A. Legal and regulatory map This is a strategy-level map, not an exhaustive statement of applicable law. Each initiative requires a fact-specific legal assessment and review of the current consolidated text of the relevant instrument. A.1 AI governance. The principal instruments are Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744, together with the final Cyprus implementing law. Strategy implementation should address classification, duties by role, authorities, sandboxes, the database, enforcement and timing. A.2 Data and privacy. The relevant framework includes the GDPR, Data Governance Act, Data Act, Open Data Directive, EHDS and ePrivacy rules. Strategy implementation should address lawful access, roles, purpose, data rights, data spaces and health data. A.3 Cyber and resilience. The principal instruments are NIS2, the CER Directive, the EU Cybersecurity Act, the Cyber Resilience Act and DORA. Strategy implementation should address criticality, incident response, supply-chain requirements and operational resilience. A.4 Identity and evidence. The relevant framework includes eIDAS, as amended by Regulation (EU) 2024/1183, together with national evidence and procedural law. Strategy implementation should address identity, signatures, time stamps, ledgers, archiving and admissibility. A.5 Intellectual property and confidentiality. The relevant instruments include the DSM Copyright Directive, Database Directive, Trade Secrets Directive and the AI Act GPAI duties. Strategy implementation should address training data, text-and-data-mining reservations, provenance, licences and confidential inputs. A.6 Liability and consumers. The relevant framework includes Directive (EU) 2024/2853, the GPSR, the consumer acquis and national contract and tort law. Strategy implementation should address software and AI product liability, disclosure, remedies and allocation of contractual responsibility. A.7 Markets and procurement. The relevant framework includes the 2014 procurement directives, State-aid law, the DMA and sector-specific competition law. Strategy implementation should address neutral specifications, proportionality, contestability, subsidies and the avoidance of lock-in. A.8 Sector overlays. Sector-specific requirements may arise under the MDR/IVDR, MiCA, the DLT Pilot Regime, the AML package, machinery legislation and other applicable sectoral law. Strategy implementation should address product, financial, professional and safety authorisations. A.9 Fundamental rights. The relevant framework includes the Cyprus Constitution, the EU Charter, the ECHR, and applicable equality, accessibility and child-rights law. Strategy implementation should address necessity, proportionality, fair process, reasons, human review and effective remedy. Annex B. Standards architecture Standards should be selected by legal role, intended use, system risk and sector. The references below are illustrative anchors for the national roadmap. Edition status, adoption as a European or Cyprus standard, and any OJEU citation must be checked at the time of use. B.1 Management and governance. Illustrative standards routes include ISO/IEC 42001:2023 and ISO/IEC 38507:2022. These should be used for organisational systems and governing-body guidance and should not be treated as automatically establishing conformity with the AI Act. B.2 Risk and impact. Illustrative standards routes include ISO/IEC 23894:2023 and ISO/IEC 42005:2025. These should be used for risk-management and impact-assessment guidance. B.3 Lifecycle and data. Illustrative standards routes include ISO/IEC 5338:2023 and the ISO/IEC 5259 series. These should be used for lifecycle processes and data-quality governance and processes. B.4 Security. ISO/IEC 27001:2022 and relevant controls from the ISO/IEC 27000 series provide illustrative standards routes for information-security management and selected cloud and privacy controls. B.5 AI Act harmonisation. CEN-CENELEC JTC 21 deliverables should be monitored for adoption and OJEU citation. A presumption of conformity should be attributed only within the scope that is actually cited. B.6 Distributed systems. Relevant work from ISO/TC 307, CEN/CLC JTC 19 and ETSI should be considered for DLT terminology, architecture, governance, interoperability and sector application. B.7 Forensic readiness. Relevant ISO/IEC digital-evidence standards and emerging AI/DLT work should be considered for evidence identification, preservation, analysis, auditability and incident reconstruction. B.8 Proposed national standards mechanism CYS should convene a funded National AI Standards Roadmap with public authorities, industry, startups, academia, professions, workers, consumers and civil society. It should maintain a standards inventory, gap analysis, national positions, delegation support, training plan, procurement profiles and annual adoption report. Cyprus should contribute early to European and international work - including AI/DLT convergence and forensic evidence - while avoiding claims that work in development already constitutes a published or harmonised standard.   Annex C. Authoritative sources Principal sources reviewed or relied upon. Online sources were checked on 30 August 2026. The final Strategy should cite the current consolidated legal text and current edition/status of standards at implementation. 1. Cyprus National AI Strategy 2032 - consultation text (101 pages) 2. Draft Cyprus law implementing Regulation (EU) 2024/1689 - consultation opened 16 August 2026 3. CYS - official role as Cyprus’s National Standardisation Body 4. Law 156(I)/2002 on standardisation, accreditation and technical information (copy reviewed) 5. Cyprus National Digital Strategy 2020–2025 6. Cyprus National Digital Decade Strategic Roadmap - 2024 revision 7. European Commission - Cyprus 2026 Digital Decade Country Report 8. Regulation (EU) 2024/1689 (Artificial Intelligence Act) 9. Regulation (EU) 2026/1744 (Digital Omnibus on AI) 10. European Commission - current AI Act framework and application timeline 11. European Commission - standardisation under the AI Act 12. CEN-CENELEC - JTC 21 Artificial Intelligence 13. ISO/IEC 42001:2023 - AI management systems 14. ISO/IEC 23894:2023 - AI risk management 15. ISO/IEC 42005:2025 - AI system impact assessment 16. ISO/IEC 5338:2023 - AI system lifecycle processes 17. ISO/IEC 38507:2022 - governance implications of AI 18. ISO/IEC 5259-5:2025 - data quality governance for analytics and ML 19. Regulation (EU) 2016/679 (GDPR) 20. Regulation (EU) 2022/868 (Data Governance Act) 21. Regulation (EU) 2023/2854 (Data Act) 22. Regulation (EU) 2025/327 (European Health Data Space) 23. Directive (EU) 2022/2555 (NIS2) 24. Directive (EU) 2022/2557 (critical entities resilience) 25. Regulation (EU) 2024/2847 (Cyber Resilience Act) 26. Regulation (EU) 2024/1183 (European Digital Identity Framework / eIDAS amendment) 27. Directive (EU) 2019/790 (copyright in the Digital Single Market) 28. Directive (EU) 2024/2853 (liability for defective products) 29. EU Charter of Fundamental Rights, Article 47 30. European Commission - Better Regulation Document basis and limitations This submission is a public-policy contribution based on the consultation materials supplied and sources available at the review cut-off. It does not constitute client-specific legal advice, a conformity assessment or a certification. References to proposed Cyprus legislation are to consultation drafts and must be updated against the enacted text. References to standards do not reproduce their copyrighted content and do not imply that every listed standard is applicable to every AI system. THE HYBRID LAWTECH FIRM empowered by Christiana Aristidou LLC Submission focus: Law, regulation, standards, emerging technologies, startups and responsible innovation Prepared for the public consultation on the Cyprus National AI Strategy 2032. Submission date: 30 August 2026. Consultation deadline: 31 August 2026." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Christiana Aristidou","PUBLIC CONSULTATION SUBMISSION Cyprus National AI Strategy 2032 Legal, regulatory, policy and implementation amendments Submitted by: THE HYBRID LAWTECH FIRM, empowered by Christiana Aristidou LLC Consultation: National AI Strategy of the Republic of Cyprus to 2032 Consultation deadline: 31 August 2026 Submission date: 30 August 2026 Review cut-off: Law, policy, standards and published consultation material available by 30 August 2026 Scope: Legal architecture, regulatory coherence, standardisation, public policy, emerging-technology convergence, compliance, procurement, startups and delivery Recognition of the Strategy’s strengths THE HYBRID LAWTECH FIRM recognises the substantial work undertaken to develop a comprehensive national vision to 2032. The Strategy contains many very positive and forward-looking elements, particularly its commitments to trustworthy and human-centred AI, productivity, skills, research, public-service transformation, secure infrastructure, responsible governance and international cooperation. It gives Cyprus an important platform from which to build. This submission seeks to preserve those strengths and provide the legal, regulatory, standards and delivery architecture needed to make them implementable and internationally credible. Bottom line The Strategy’s ambition and strong elements should be retained. Before final adoption, however, it needs targeted but material refinement: a current policy baseline; concordance with the draft 2026 national AI implementing law and the enacted framework; clear institutional mandates; accurate treatment of law, standards and assurance; integrated rights, data, cybersecurity, procurement, liability and evidence controls; explicit treatment of technology convergence; and a costed, sequenced delivery plan. Flagship proposals must be reframed wherever a strategy cannot itself create regulatory approvals, EU-wide legal presumptions, judicial powers, certification status, legal equivalence or safe harbours. With these amendments, the Strategy can become a strong, executable foundation for trusted AI in Cyprus. Contents 1. Executive position 2. Assessment framework 3. Detailed consultation comments 4. Cross-cutting implementation package Annex A. Legal and regulatory map Annex B. Standards architecture Annex C. Authoritative sources How to use this document Section 1 may be pasted into the platform’s general-comment field. Each HLTF entry in Section 3 is self-contained and can be submitted against the identified Strategy section. Proposed wording is drafted for direct insertion or adaptation by the drafting authority.   1. Executive position THE HYBRID LAWTECH FIRM welcomes the substantial work undertaken to develop the Strategy and supports its objective of positioning Cyprus as a trustworthy, innovative and internationally connected jurisdiction for artificial intelligence. The draft contains many valuable and forward-looking elements. It does not yet, however, provide a sufficiently coherent legal and delivery architecture for a national strategy extending to 2032. Its principal weakness is not a lack of ideas or ambition; it is the absence of sufficiently disciplined boundaries between law, policy, standards, certification, institutional power, evidence and implementation. The final Strategy should be amended before adoption. In particular, it should no longer state without qualification that it builds on the National Digital Strategy 2020–2025. That strategy had expired before this consultation. The legally and strategically sound response is not to declare the AI Strategy automatically invalid, but to require a published transition evaluation and a live baseline connected to the National Digital Decade Strategic Roadmap and any formally adopted successor instruments. The sequencing of national measures also matters. A draft law implementing Regulation (EU) 2024/1689 was placed in public consultation on 16 August 2026 while the Strategy consultation remained open. That Bill identifies competent, notifying, market-surveillance, accreditation and sandbox functions. The final Strategy must therefore be conformed to the enacted national framework. A policy document should not anticipate, duplicate or contradict statutory mandates. The Strategy should also treat standardisation as implementation infrastructure, expressly recognise CYS and the national delegation/mirror-committee mechanism, and distinguish voluntary international standards from European harmonised standards cited in the Official Journal. This is essential to make governance, procurement, testing, evidence, interoperability, training and market access operational - not merely aspirational. 1.1 Text for the general-comment field THE HYBRID LAWTECH FIRM, empowered by Christiana Aristidou LLC, recognises the substantial work undertaken to prepare the Cyprus National AI Strategy 2032, welcomes its many positive and forward-looking elements, and supports its ambition. This submission seeks to preserve those strengths while recommending the material amendments needed before final adoption. The Strategy should be converted from a broad catalogue of aspirations into a legally coherent, costed and accountable delivery framework. First, it should replace unqualified reliance on the expired National Digital Strategy 2020–2025 with a published transition evaluation and a current baseline linked to Cyprus’s National Digital Decade Strategic Roadmap and any formally adopted successor policies. Secondly, following publication of the draft national law implementing Regulation (EU) 2024/1689 during this consultation, the final Strategy should include a formal concordance with the enacted law and should distinguish policy coordination from statutory regulation, market surveillance, accreditation, certification, enforcement and regulatory-sandbox functions. Thirdly, it should accurately distinguish binding law, European harmonised standards, other European and international standards, professional credentials and government guidance; recognise CYS and Cyprus’s national delegates; correct the treatment of ISO/IEC 42001; and establish a standards roadmap covering CEN-CENELEC JTC 21, ISO/IEC JTC 1/SC 42, ETSI and relevant DLT, cybersecurity and sector committees. Fourthly, major initiatives should pass integrated legality, fundamental-rights, data-protection, equality, accessibility, security, procurement, competition, liability, evidence and sustainability gates. Claims concerning an ‘AI judge’, EU-wide ownership presumptions through AIREG, AML certificates that enable reliance, pre-certification and international equivalence should be deleted or reframed within applicable law. Finally, the Strategy should address the convergence of AI with blockchain/DLT, smart contracts, digital identity and trust services, IoT, digital twins, cloud-edge/HPC, robotics and cybersecurity through technology-neutral architectures and use-case tests. Delivery should be supported by named owners, budgets, baselines, model procurement clauses, SME pathways, public registers, independent evaluation and an annual legal/standards update. These changes would preserve ambition while materially increasing lawfulness, implementability, investor confidence, public trust and international interoperability. 1.2 Priority amendments 1. Legal concordance: Conform governance, powers, sandboxes and enforcement to the final 2026 implementing law. 2. Current policy baseline: Replace unqualified reliance on the expired 2020–2025 Digital Strategy with an evaluated transition and current roadmap. 3. Clear legal hierarchy: Separate binding law, harmonised standards, voluntary standards, guidance and aspirational programmes. 4. Institutional integrity: Publish a RACI and separate sponsor, operator, assurance, accreditation, certification and enforcement functions. 5. Rights-by-design: Apply integrated legality, FRIA/DPIA, equality, accessibility and remedy gates before public-sector use. 6. Procurement controls: Adopt mandatory AI tender and contract clauses before launching transformational procurements. 7. Data governance: Create lawful, federated and documented access rules rather than relying on the metaphor of State ownership. 8. Critical infrastructure: Map NIS2/CER/CRA duties, concentration risks, continuity, incident reporting and resource constraints. 9. Convergence: Address AI with DLT, identity, IoT, digital twins, cloud-edge/HPC, robotics, cybersecurity and smart contracts. 10. Correct flagship claims: Recast AI judge, AIREG, AML certificates, pre-certification and equivalence claims within lawful limits. 11. SME scale-up: Provide proportionate clinics, test support, templates, compute and procurement access tied to evidence. 12. Measurable delivery: Cost the portfolio, reconcile KPIs, assign owners and publish independent evaluation and change logs. 1.3 Overall institutional position 1. Regulation creates enforceable duties; standards provide common technical and organisational methods; accreditation attests competence of conformity-assessment bodies; certification evaluates against a defined scheme; policy selects public outcomes. The final Strategy should keep these functions separate and deliberately connected. 2. The Strategy should be technology-neutral but not technology-blind. AI is increasingly embedded in distributed systems. Cyprus can build a defensible niche by combining legal and regulatory capability with active European and international standards participation across AI, DLT and digital evidence. 3. Public trust will depend less on visionary labels than on visible control: lawful authority, transparent procurement, demonstrable evidence, human accountability, complaint routes, secure and portable infrastructure, and the capacity to stop systems that do not deliver safe public value. 2. Assessment framework This submission reviewed the full Strategy, relevant Cyprus and EU legislation and policy instruments, applicable standardisation materials, the proposed 2026 national AI implementing law, and the public comments available on the consultation platform as at 30 August 2026. Public comments and other consultation materials were used only to identify recurring implementation concerns; the analysis, conclusions and proposed wording are presented independently by THE HYBRID LAWTECH FIRM. 2.1 Five tests applied 1. Legality: Is there an identified competence, legal basis, responsible authority, procedural safeguard and route of review? 2. Regulatory coherence: Does the proposal fit the AI Act as amended, the draft national law, the wider EU digital acquis and sector regulation? 3. Assurance: Can the claimed outcome be evidenced through standards, testing, audit, conformity assessment, records and independent oversight without confusing their legal effects? 4. Deliverability: Are the owner, budget, procurement route, dependencies, skills, infrastructure, contract rights, timeline and stop/scale criteria specified? 5. Future fitness: Does the proposal remain technology-neutral, interoperable, portable, rights-preserving and adaptable to convergence and regulatory change? 2.2 Four-layer drafting rule The Strategy should apply a four-layer drafting rule that clearly distinguishes law, standards, assurance, and policy and delivery. Law: EU and Cyprus legislators, together with competent authorities, create duties, powers, procedures, sanctions and legal effects. The Strategy must not imply that a policy statement itself creates a legal power or exemption. Standards: CEN, CENELEC and ETSI, together with ISO/IEC and the national standards system, provide consensual specifications and, in defined cases, support conformity. The Strategy must not imply that all standards are mandatory or that compliance with a standard automatically confers a presumption of conformity. Assurance: Accreditation bodies, conformity-assessment bodies, auditors and testing facilities assess competence, evidence or conformity within a defined scope. The Strategy must not imply that participation in a sandbox, laboratory, badge or audit is equivalent to regulatory approval. Policy and delivery: Government and accountable public bodies set outcomes, fund, procure, coordinate, publish guidance and evaluate. The Strategy must not imply that a proposed programme overrides law, regulators, courts or independent bodies. 2.3 Principal implementability risks 1. Institutional risk: overlapping authority names and functions may produce unlawful delegation, duplicated supervision or conflicted assurance. 2. Reliance risk: users may treat policy labels, registries, credentials or laboratory outputs as legal certification or safe harbour. 3. Procurement risk: ambitious early tenders may entrench proprietary models, weak audit rights and expensive exit before the governance framework exists. 4. Rights risk: high-impact public AI may be piloted without a complete legality, necessity, discrimination, accessibility and remedy analysis. 5. Investment risk: unsupported KPIs and selective international comparisons may weaken credibility with investors, EU institutions and funding evaluators. 6. Infrastructure risk: cloud/model concentration and energy-water constraints may undermine claimed sovereignty and resilience. 7. Evidence risk: insufficient provenance and forensic readiness may make incidents, liability and regulatory investigations difficult to reconstruct.   3. Detailed consultation comments Each entry below is drafted to stand alone in the public-consultation platform. References are to the numbered sections and descriptive passages of the consultation version of the Strategy. Proposed text may be inserted directly or adapted while preserving the legal distinction and implementation control identified in the comment. HLTF-01. State the legal status of the Strategy and establish a legal-dependency rule Strategy reference: Cross-cutting; §§1.1, 2.3.3, 3.3, 3.9.6, 4.3 and Annex A Comment type: Legal / governance / drafting Comment and implementation risk. The text alternates between policy language, mandatory language and claims that new authorities, registries, audits, certificates and legal presumptions will exist. A strategy may direct policy and spending, but cannot itself create statutory powers, binding duties, judicial procedures, presumptions of ownership, certification status or regulatory equivalence. Leaving the hierarchy unstated exposes ministries, procurers, businesses and citizens to reliance on propositions that may have no legal basis. Requested amendment. Insert an interpretation clause that separates law, standards, government policy and proposed initiatives, and make every legally dependent initiative conditional on competence, enactment, funding and impact assessment. Proposed text for insertion or replacement Legal status and dependencies. This Strategy is a policy framework. It does not of itself create statutory powers, legal duties, regulatory approvals, evidential presumptions, certification status or rights of reliance. References to ‘shall’ bind public bodies only to the extent authorised by applicable law and a duly approved implementation instrument. Each initiative shall be entered in a public legal-dependency register identifying the legal basis, competent authority, required primary or secondary legislation, applicable EU law, standards profile, budget, accountable owner and commencement condition. No initiative affecting rights, market access, supervision, certification or judicial decision-making shall become operational until those conditions are satisfied. HLTF-02. Replace the expired digital-strategy foundation with a current, evidenced baseline Strategy reference: §2.3.2 and footnote 10; §2.2; Annex A Comment type: Strategic / evidence / drafting Comment and implementation risk. Section 2.3.2 says the Strategy is aligned with the ‘existing Digital Strategy’, while footnote 10 identifies the National Digital Strategy 2020–2025. That instrument had expired before this 2026–2032 Strategy was consulted. Expiry does not automatically invalidate the AI Strategy, but it makes the asserted foundation incomplete and potentially misleading unless there is an evaluation of delivery, unresolved dependencies and a formal transition to current policy. The document also uses the undefined expression ‘revised Digital Strategy’ elsewhere. Requested amendment. Delete the unqualified reliance on the expired instrument. Add a transition and baseline annex linked to the National Digital Decade Strategic Roadmap and any successor digital strategy, with version control and an update trigger. Proposed text for insertion or replacement Digital-policy baseline. The Strategy takes account of lessons and assets arising from the National Digital Strategy 2020–2025, but does not treat that expired instrument as the current policy foundation. Within 90 days of adoption, the Deputy Ministry shall publish a transition statement that: (a) evaluates the 2020–2025 Strategy against its objectives; (b) identifies completed, continuing, superseded and unimplemented measures; (c) maps dependencies to the current National Digital Decade Strategic Roadmap and any formally adopted successor digital strategy, data strategy, cloud policy and interoperability framework; and (d) reconciles baselines, budgets, owners and dates. References in this Strategy shall identify the title, version, approval date and status of the policy instrument relied upon. HLTF-03. Make the methodology, country benchmarking and evidence base reproducible Strategy reference: §§1.6–1.7; sector ‘International alignment’ passages; Annex H Comment type: Policy / evidence / international relations Comment and implementation risk. The Strategy names a small set of countries as ‘pioneers’ and states that selected national strategies informed the work, but gives no selection criteria, comparator groups, variables, time periods, performance evidence or transferability test. Comparative learning is valuable; selective endorsement without a method may imply an official ranking, overlook relevant Member States and create unnecessary reputational or competitive signalling. The listed meetings likewise do not amount to a published stakeholder map, evidence register or impact assessment. Requested amendment. Replace country praise with a neutral benchmarking method and publish the evidence, assumptions, limitations and consultation-response report. Proposed text for insertion or replacement Comparative and consultation methodology. International examples shall be used as evidence sources, not as country rankings or general endorsements. A benchmarking annex shall identify the policy question, transparent selection criteria, peer group, indicators, data year, source quality, implementation outcomes, Cyprus transferability constraints and limitations for each comparator. The final Strategy shall include an evidence register, stakeholder-category map, summary of options considered, principal assumptions, distributional and fundamental-rights impacts, and a reasoned consultation report explaining which material comments were accepted, partly accepted or rejected. Country references unsupported by that method shall be removed or expressed neutrally. HLTF-04. Conform the Strategy to the 2026 draft AI implementing law and the final enacted framework Strategy reference: §3.3.1; §3.9.6; §§3.13–4.3; Annexes A–C Comment type: Legal / institutional sequencing Comment and implementation risk. The proposed national law for implementing Regulation (EU) 2024/1689 was published for consultation on 16 August 2026, during the Strategy consultation. It allocates functions to the Commissioner of Electronic Communications, the Commissioner for Personal Data Protection, the Central Bank and any further designated authority; identifies the national accreditation function; and provides a national regulatory-sandbox mechanism. The Strategy instead creates or names bodies with overlapping regulatory, audit, registry, certification and sandbox functions. The two instruments cannot safely proceed on parallel, inconsistent institutional assumptions. Requested amendment. Require a formal concordance after the Bill is finalised, preserve the authority of the legislature and regulators, and distinguish policy coordination from statutory supervision. Proposed text for insertion or replacement Institutional concordance. Before the Strategy is submitted for final approval, and again following enactment of the national law implementing Regulation (EU) 2024/1689, the Attorney-General’s Office and the responsible Deputy Ministry shall complete and publish an article-by-article concordance table. It shall map every Strategy body and function to the competent authority, legal basis, accountability route, appeal or complaint mechanism, information-sharing power and funding source. Strategy bodies may coordinate policy and delivery but shall not exercise market-surveillance, notifying-authority, accreditation, certification, enforcement, complaints, sanctioning or regulatory-sandbox powers unless those powers are expressly conferred by applicable law. Any inconsistent Strategy wording shall be amended automatically through a published conformance update. HLTF-05. Clarify governance, names, accountability and separation of functions Strategy reference: §§3.3.1–3.3.2; glossary; Annex B Comment type: Governance / administrative law Comment and implementation risk. The governance architecture uses inconsistent names and roles, including ‘Council’ and ‘Committee’, and describes the Taskforce both as independent advisory body and central coordinating body. The National AI Authority is simultaneously presented as policy coordinator, executor and control gatekeeper. Other entities prototype, validate, procure, approve, monitor or certify. Without a single responsibility matrix, the same institution may sponsor a system and assure it, weakening independence and creating conflicts. Requested amendment. Publish a definitive governance schedule and apply separation of policy, delivery, assurance and enforcement. Proposed text for insertion or replacement Governance and separation of functions. Annex A shall contain the definitive name, legal form, mandate, membership, appointment process, term, conflicts policy, decision rights, reporting line, budget and review date for every Strategy body. A RACI matrix shall cover policy, funding, procurement, data access, development, deployment approval, conformity assessment, audit, incident response, market surveillance and redress. No body that develops, funds, procures or operates an AI system shall provide the final independent assurance or statutory enforcement decision for that same system. Duplicate names and inconsistent glossary definitions shall be corrected. Existing constitutional, ministerial, regulatory, judicial and independent-authority competences remain unaffected. HLTF-06. Recognise CYS and preserve the national quality-infrastructure boundaries Strategy reference: §§1.4.3–1.4.10, 2.5.1, 3.3.1, 3.12; §4.3; Annexes A, C and H Comment type: Legal / standards / institutional Comment and implementation risk. Formal standardisation is treated intermittently, CYS is not assigned a role, and ‘standards’ are sometimes described as outputs of the proposed National AI Authority. CYS is Cyprus’s official National Standardisation Body and exercises the national standardisation activity pursuant to Law 156(I)/2002, including national coordination and representation in CEN, CENELEC, ISO and IEC. Standardisation, accreditation, conformity assessment/certification, regulation and policy guidance are related but legally distinct functions. Requested amendment. Insert CYS into the governance and implementation architecture as standards coordinator, while expressly preserving the roles of regulators, the national accreditation body and conformity-assessment bodies. Proposed text for insertion or replacement National standardisation and quality infrastructure. CYS, as Cyprus’s official National Standardisation Body exercising the national standardisation activity pursuant to Law 156(I)/2002, shall coordinate national standards intelligence, national mirror-committee participation, adoption of European standards and access to international standards work relevant to this Strategy. The National AI Authority may issue policy frameworks, implementation guidance and common administrative controls, but shall not present those instruments as national, European, harmonised or international standards. Accreditation shall remain with the legally designated national accreditation body; certification and conformity assessment shall be performed only by competent bodies under applicable schemes; and statutory supervision shall remain with the competent authorities. A written cooperation protocol shall prevent overlap. HLTF-07. Correct the legal effect and technical description of standards Strategy reference: §§2.3.4, 3.11.2, 3.12.4, 3.13.1–3.13.3; Annex A; Annex H Comment type: Technical / legal accuracy Comment and implementation risk. The Strategy recommends ‘ISO 42001 as a standard for risk management’, treats ISO/IEC 27001 as if it were sufficient for AI security, and places the AIGP professional credential alongside standards. ISO/IEC 42001 is an AI management-system standard; ISO/IEC 23894 is dedicated AI risk-management guidance. A voluntary standard does not itself prove compliance with the AI Act. Under Article 40 of the AI Act, only an applicable harmonised standard or part cited in the Official Journal may confer the specified presumption of conformity. Requested amendment. Replace the current wording with a standards taxonomy and risk-based profile; correct Annex H. Proposed text for insertion or replacement Use and legal effect of standards. ISO/IEC 42001:2023 may support an organisational AI management system; ISO/IEC 23894:2023 may support AI risk management; ISO/IEC 42005:2025 may support AI system impact assessment; ISO/IEC 5338:2023 may support lifecycle processes; the ISO/IEC 5259 series may support data-quality governance; and ISO/IEC 27001:2022 and related controls may support information security. These references are voluntary unless law or contract makes them applicable. They do not replace legal analysis or automatically demonstrate AI Act conformity. Applicable European harmonised standards developed through CEN-CENELEC JTC 21 shall be monitored and used where appropriate after adoption and, for presumption of conformity, OJEU citation. Professional credentials shall be listed as training credentials, not standards. HLTF-08. Use the current AI Act and remove blanket registration and obsolete timing claims Strategy reference: §3.9.6; §§3.11–3.13; Annex A; sector roadmaps Comment type: EU law / compliance Comment and implementation risk. The Strategy includes readiness language tied to 2 August 2026, although consultation continues after that date, and says every organisation must register AI systems in the EU database ‘without exception’. Registration under the AI Act is role- and category-specific; it is not a universal registry duty. The legal timetable was also amended by Regulation (EU) 2026/1744, which entered into force on 27 July 2026. Static or inaccurate dates will make a 2032 strategy obsolete immediately. Requested amendment. Replace blanket claims with a maintained obligations register based on the AI Act as amended. Proposed text for insertion or replacement AI Act implementation register. All references to Regulation (EU) 2024/1689 shall mean that Regulation as amended, including Regulation (EU) 2026/1744, and any applicable delegated or implementing acts. The National AI Authority shall maintain, with the competent authorities, a dated public implementation register identifying obligations by role, system category and commencement date. Registration in the EU database or any national register shall be required only where applicable law requires it. The national implementation plan shall distinguish prohibited practices, transparency obligations, general-purpose AI obligations, Annex III high-risk systems, safety components of regulated products, public-authority deployer duties, fundamental-rights authorities and sector-specific law. HLTF-09. Redesign NAICF, audits and the proposed certification lab around lawful conformity routes Strategy reference: §3.9.6; Legal Services pillar; §4.3 Comment type: Conformity assessment / legal / market access Comment and implementation risk. The text proposes annual audits by a ‘Cyprus AI Security & Certification Authority’, a central registry of systems ‘certified under EU rules’, pre-certification of high-risk and ‘foundation’ models, and international equivalence bridges. It does not identify the legal basis, applicable standard, scheme, accreditation, notified-body route, scope of certificate, surveillance, complaints, liability or recognition mechanism. The AI Act uses the term general-purpose AI model and prescribes conformity routes; policy branding cannot create EU recognition or equivalence. Requested amendment. Convert NAICF into optional readiness support unless and until a lawful scheme is established, and remove ‘pre-certification’, ‘dual recognition’ and blanket annual-audit claims. Proposed text for insertion or replacement National AI Compliance Framework. NAICF shall operate as a non-binding readiness, evidence and implementation-support framework unless a specific function is conferred by law. It shall not issue or imply regulatory approval, CE marking, presumption of conformity, notified-body status, accreditation, legal equivalence or safe harbour. Any audit or certification scheme shall identify its owner, normative requirements, competence criteria, accreditation basis, assessment route, scope, validity, surveillance, complaints, impartiality, liability and relationship to Articles 40–49 of the AI Act. The proposed laboratory may provide testing, evaluation and sandbox support; the terms ‘pre-certification’, ‘certified under EU rules’, ‘dual recognition’ and ‘foundation model’ shall be replaced by legally accurate descriptions. HLTF-10. Create an integrated fundamental-rights and public-law assurance gate Strategy reference: §§1.4.8, 2.5.5, 3.3.2, 3.9, 3.13; Annex B Comment type: Fundamental rights / administrative law Comment and implementation risk. The Strategy refers generally to ethics, fairness and mandatory legal assessments for high-impact systems but does not specify decision criteria, responsible officials, publication rules or interaction with the AI Act fundamental-rights impact assessment, GDPR data-protection impact assessment, equality, accessibility, children’s rights and administrative-law duties. ‘Ethics’ cannot replace legality, and a checklist cannot legitimise a use that lacks statutory competence or necessity. Requested amendment. Add one integrated, risk-based assessment and approval gate before procurement and deployment of high-impact public-sector AI. Proposed text for insertion or replacement Integrated rights and legality assessment. Before procurement, pilot or deployment of high-impact public-sector AI, the accountable public body shall document: legal competence and purpose; necessity and proportionality; AI Act classification and any required fundamental-rights impact assessment; GDPR lawful basis, Article 22 analysis and any required DPIA; equality and non-discrimination; accessibility; child and vulnerable-person safeguards; human decision authority; notice, reasons, review, complaint and remedy; security; evidential integrity; and less intrusive alternatives. The assessment shall be reviewed by the competent legal, data-protection, security and domain functions. A non-confidential summary and decision shall be published, subject only to lawful restrictions. Ethics review supplements and does not replace legal compliance. HLTF-11. Establish a lawful public-sector AI register, notice, human review and redress Strategy reference: §§3.3.2, 3.4, 3.9.6; Annexes B–C Comment type: Transparency / public law / rights Comment and implementation risk. The proposed ‘AI Registry’ is framed as cataloguing all market solutions, but no purpose, legal basis, scope, confidentiality rule or relationship with EU registration is defined. Citizens need transparency about State use, while businesses require protection of trade secrets and security information. Article 86 of the AI Act provides a limited right to explanation in specified circumstances; it should not be expanded or reduced by imprecise strategy language. Requested amendment. Create a public-sector register first, avoid duplicate filings, and define individual safeguards in legally accurate terms. Proposed text for insertion or replacement Public-sector AI transparency and redress. Cyprus shall maintain a public register of AI systems used by public bodies, linked where practicable to required EU registrations and avoiding duplicate filings. Each entry shall identify the accountable body, purpose, provider and material subcontractors, legal basis, AI Act classification, affected groups, data categories, human-oversight model, impact-assessment status, performance indicators, material incidents, procurement reference and complaint channel. Security-sensitive and protected commercial information may be withheld only on a documented legal basis. Affected persons shall receive meaningful notice and access to human review, reasons or explanation, complaint and judicial or administrative remedy to the extent provided by applicable law, without limiting stronger rights under other law. Non-digital service channels shall remain available for essential services. HLTF-12. Recast data as a governed resource rather than an unqualified national asset Strategy reference: §3.2; §3.7; sector data proposals; Annex A Comment type: Data law / governance / interoperability Comment and implementation risk. Calling data a ‘strategic national asset’ may be a useful policy metaphor but does not determine ownership, lawful access or reuse. The proposed lake, warehouse and hub model lacks a legal classification of personal, non-personal, confidential, open, sectoral and protected data; a controller/processor map; purpose and access rules; retention; provenance; data-quality metrics; rights management; and a decision between centralised and federated architecture. Requested amendment. Insert a national AI data-governance framework aligned with the GDPR and the EU data acquis, and require data-product documentation. Proposed text for insertion or replacement Data governance for AI. Data shall be treated as a governed public-interest resource where law permits, not as property of the State by default. Before access or reuse, each dataset shall have a named steward; legal and rights classification; controller/processor or other role allocation; purpose and lawful basis; provenance; quality and representativeness measures; access conditions; licensing and intellectual-property status; retention and deletion rule; security classification; data-subject or third-party rights process; and audit record. Architecture shall favour federated access, minimisation and purpose limitation where centralisation is unnecessary. The framework shall align, as applicable, with the GDPR, Data Governance Act, Data Act, Open Data Directive, EHDS, trade-secret and copyright law, sector confidentiality and the European Interoperability Framework, supported by the ISO/IEC 5259 series and relevant European standards. HLTF-13. Make public procurement the principal implementation control Strategy reference: §§3.3.2, 3.4.1, 4.1; first six transformational procurements; Annex B Comment type: Public procurement / contracts / implementation Comment and implementation risk. The Strategy proposes six transformational procurements within eight months and an ‘AI-first’ procurement direction, but does not supply minimum readiness gates or contract terms. Buying quickly before requirements, data rights, interfaces, evidence and exit are defined can lock the State into providers and shift compliance risk to taxpayers. ‘AI-first’ may also bias problem definition toward technology instead of public value and proportionality. Requested amendment. Replace ‘AI-first’ with problem-led, outcome-based and rights-preserving procurement, and publish mandatory clauses before major tenders. Proposed text for insertion or replacement AI procurement standard. Public bodies shall procure AI only where a documented problem, lawful purpose and proportionate business case show that AI is suitable compared with non-AI alternatives. Before tender, the body shall complete classification, data-readiness, rights, security, accessibility, competition and exit assessments. Mandatory contract schedules shall address: provider/deployer roles; model and material-subcontractor transparency; data, input and output rights; training and improvement use; logging and evidence retention; performance and bias testing; human oversight; cybersecurity; incident and regulator cooperation; material model-change control; audit access; service levels; intellectual property; confidentiality; product and professional liability; insurance; portability, open formats, interfaces and exit assistance; deletion/return of data; sustainability metrics; and termination. No transformational procurement shall launch until these templates and an independent assurance route are approved. HLTF-14. Unify regulatory sandboxes, testbeds and innovation facilities Strategy reference: §§3.4–3.9; LegalTech and sector sandboxes; §4.3 Comment type: Regulatory governance / innovation Comment and implementation risk. The Strategy repeatedly proposes sector sandboxes and testing facilities without distinguishing a statutory AI regulatory sandbox from experimentation, testbeds, accelerators, centres of excellence and conformity assessment. The draft implementing Bill assigns the national regulatory sandbox to the identified competent authorities. Multiplying ‘sandboxes’ without a common legal gateway risks regulatory arbitrage, duplicated applications and false impressions of approval. Requested amendment. Create one national sandbox framework with sector pathways and common entry, exit and publication rules. Proposed text for insertion or replacement Sandbox and testing architecture. The national AI regulatory sandbox shall be operated only by the authority or authorities designated by law and in accordance with the AI Act. Sector regulators, the Data Protection Commissioner, CYS, accreditation and conformity-assessment actors, research facilities and domain experts shall participate within their respective competences. Innovation hubs, accelerators and testbeds may provide technical experimentation but shall not imply regulatory approval. A single public framework shall define eligibility, SME and startup support, application criteria, real-world testing conditions, data protection, intellectual property, confidentiality, liability, incident response, standards participation, regulator coordination, duration, exit report, evidential value and the express statement that participation does not remove legal obligations. HLTF-15. Treat the National AI Infrastructure as a regulated critical dependency Strategy reference: §§3.7.1–3.7.4 and 3.13.2–3.13.3; Annex A Comment type: Cybersecurity / resilience / critical infrastructure Comment and implementation risk. The Strategy describes the National AI Infrastructure as critical national infrastructure but does not map designation, competent authorities or duties under NIS2, the CER Directive, the Cybersecurity Act, the Cyber Resilience Act or sector rules. Generic ‘national cybersecurity frameworks’ are insufficient for shared compute, model access, sensitive data, cross-border cloud, supply-chain threats and systemic concentration. Requested amendment. Require a criticality and regulatory assessment before architecture or procurement, plus measurable resilience and recovery controls. Proposed text for insertion or replacement Critical AI infrastructure assurance. Before design approval, the responsible authority shall determine and publish the legal classification, essential/important-entity status, critical-entity dependencies and competent supervisory arrangements for each infrastructure component under NIS2, the CER Directive, applicable Cyprus law, the EU Cybersecurity Act, the Cyber Resilience Act and sector regimes. Architecture and procurement shall include zero-trust access, tenant isolation, secure development, model and data supply-chain controls, vulnerability handling, cryptographic agility, adversarial testing, logging, forensic readiness, continuity, geographic and provider concentration limits, tested recovery objectives, portability and exit, incident-reporting interfaces and independent security evaluation. ENISA guidance and applicable standards shall be tracked in a maintained control profile. HLTF-16. Define digital sovereignty through measurable control, competition and exit Strategy reference: §3.7.3; public-sector platforms; Annex C Comment type: Competition / cloud / strategic autonomy Comment and implementation risk. ‘Digital sovereignty’ is defined at a high level and then associated with specific infrastructure choices. Sovereignty is not achieved merely through local hosting, ownership or a favoured hardware architecture. A system may be physically local yet operationally dependent on a foreign hyperscaler, proprietary model, unavailable weights, non-portable data or a single integrator. Conversely, carefully governed European or cross-border services may increase resilience. Requested amendment. Adopt outcome-based sovereignty criteria and technology-neutral procurement. Proposed text for insertion or replacement Digital sovereignty and contestability. Sovereignty shall be measured by lawful control over data and keys; ability to audit and govern models; continuity under supplier failure or geopolitical disruption; portability of data, prompts, logs, configurations and workloads; open and documented interfaces; substitutability of critical components; availability of skills and maintenance; compliance with EU law; and tested exit within defined time and cost. Procurement shall be technology-neutral and shall not prescribe a processor, model or distributed architecture without a published proportionality, security, competition and lifecycle-cost assessment. Multi-cloud or sovereign-cloud claims shall be evidenced, and material provider/model concentration shall be reported annually. HLTF-17. Add a technology-convergence and distributed-systems strategy Strategy reference: §§1.3–1.4, 2.3.4, 3.7, 3.12; sector roadmaps Comment type: Emerging technology / standards / strategic Comment and implementation risk. The Strategy largely treats AI as a standalone technology even though implementation will depend on cloud-edge/HPC, IoT, robotics, digital twins, digital identity and trust services, cybersecurity, smart contracts, tokenisation and blockchain/DLT. The absence is especially striking where the text already proposes a blockchain registry. Convergence affects architecture, evidence, security, liability, interoperability and skills; it should not be addressed through isolated use cases. Requested amendment. Insert a horizontal, technology-neutral convergence section with a use-case test and coordinated standards participation. Proposed text for insertion or replacement Converging technology systems. Cyprus shall govern AI as part of distributed socio-technical systems that may combine cloud and edge computing, high-performance computing, IoT, digital twins, robotics and autonomous systems, digital identity and trust services, cybersecurity, smart contracts, tokenisation and blockchain/DLT. Each proposed combination shall pass a documented use-case test covering necessity, comparative architecture, legal roles, data flows, security, interoperability, environmental cost, governance, evidence and exit. DLT shall be used only where distributed control, tamper-evidence or shared state provides demonstrable value over a conventional database. CYS shall coordinate relevant participation across ISO/IEC JTC 1/SC 42, ISO/TC 307, CEN-CENELEC JTC 21, CEN/CLC JTC 19, ETSI and sector committees so that common system descriptions and interfaces can be developed without displacing committee competence. HLTF-18. Correct AIREG: DLT records can support evidence, not manufacture ownership Strategy reference: Legal Services pillar, pp. 74–76; AIREG Comment type: Intellectual property / evidence / DLT Comment and implementation risk. AIREG is said to provide ‘immutable certification’ and a strong presumption of ownership across the EU. A ledger entry can help prove that a particular hash or assertion existed at a time and has not been altered. It does not establish authorship, originality, title, lawful training, absence of infringement or the truth of the recorded claim, and a Cyprus strategy cannot create an EU-wide ownership presumption. Immutability also conflicts with rectification, revocation, key compromise and data-protection requirements if designed poorly. Requested amendment. Recast AIREG as a feasibility study for a rights-evidence and provenance service aligned with eIDAS and IP law. Proposed text for insertion or replacement AI provenance and rights-evidence feasibility study. The proposed AIREG shall not be described as certifying ownership or creating a legal presumption across the Union. A feasibility study shall compare conventional and DLT architectures and assess legal basis, governance, evidential effect, identity assurance, time-stamping, qualified electronic ledgers and archiving under eIDAS as amended, WIPO and EU intellectual-property rules, GDPR, trade secrets, cybersecurity, interoperability, correction and revocation, key loss, dispute resolution, liability and long-term preservation. Any pilot may record signed claims, hashes, provenance events and licences, but shall state that technical integrity does not prove the truth, lawfulness, authorship or ownership of the underlying asset. Legal effect shall arise only from applicable law and admissible evidence. HLTF-19. Remove the ‘AI Judge’ commitment pending constitutional and justice-system reform Strategy reference: Legal Services pillar, pp. 74–76; Annex C Comment type: Constitutional / judicial / fundamental rights Comment and implementation risk. The proposal for an ‘AI judge’ in low-value, factually uncontested cases is not a mere digital-service project. It concerns the exercise of judicial power, independence and impartiality, Article 30 of the Constitution, Article 47 of the EU Charter, Article 6 ECHR, procedural law, open justice, evidence, reasons, appeal and equality of arms. Monetary value and absence of a factual dispute do not remove questions of law or vulnerability. AI used to prepare judicial decisions is also a high-risk category under the AI Act. Requested amendment. Delete the commitment to an AI judge. Permit carefully governed administrative and judicial support only, unless future primary law and constitutional analysis authorise more. Proposed text for insertion or replacement Justice-sector AI. The term and proposal ‘AI Judge Capability’ shall be deleted. AI may be evaluated for transcription, translation, scheduling, search, document triage, legal research and non-binding decision support, subject to judicial governance, procurement, security, evidence, data protection, professional secrecy, accessibility and fundamental-rights safeguards. A natural judge or legally authorised decision-maker shall retain responsibility for the decision, factual and legal assessment, reasons and remedy. Any future proposal for automated adjudication shall require a separate public justice strategy, constitutional and human-rights opinion, primary legal basis, judicial and Bar consultation, equality and accessibility assessment, pilot evaluation, public transparency and an effective right to human determination and appeal. HLTF-20. Govern court transcription and a Cyprus case-law model as justice infrastructure Strategy reference: Legal Services pillar, pp. 74–76 Comment type: Justice / data / evidence / procurement Comment and implementation risk. AI transcription and a case-law language model can improve access, but the current text does not address authoritative records, correction, speaker identification, protected hearings, anonymisation, hallucinations, source citation, copyright/database rights, judicial independence, professional secrecy or whether citizens may rely on outputs. A model trained on incomplete or non-authoritative judgments may entrench error. Requested amendment. Add a justice-data governance and staged evaluation programme; never label model output as authoritative legal advice or an official judgment. Proposed text for insertion or replacement Court records and case-law AI. The Supreme Court and competent justice authorities shall own governance of any transcription or case-law AI service. A pilot shall define the authoritative record, human verification, correction procedure, source provenance, citation to the controlling judgment, coverage limitations, protected-hearing controls, anonymisation, retention, access tiers, cybersecurity, professional secrecy, copyright and database rights, model evaluation and incident response. Public outputs shall disclose that they are generated or assisted by AI and are not the authoritative judgment or legal advice. No system shall train on confidential material or use court data for provider model improvement without express legal and contractual authority. Independent accuracy, language and equality testing shall precede scale-up. HLTF-21. Limit the Digital AML Certification Scheme to interoperable evidence exchange Strategy reference: Legal Services pillar, pp. 74–76; Financial Services pillar Comment type: AML / financial regulation / liability Comment and implementation risk. The proposed certificate would ‘enable reliance’ by obliged entities and authorities. Under EU and national AML rules, reliance, outsourcing and information exchange do not automatically transfer each obliged entity’s responsibility for customer due diligence, risk assessment, monitoring, sanctions controls and suspicious-activity reporting. A certificate may become stale, be wrong, reveal sensitive data or create systemic reliance on one provider. Requested amendment. Reframe the initiative as a regulated, revocable and purpose-limited evidence exchange; do not promise discharge from AML duties. Proposed text for insertion or replacement Digital AML evidence exchange. Any Digital AML Certification Scheme shall be developed with the competent AML supervisors, Data Protection Commissioner and obliged-sector representatives, and aligned with the applicable EU AML package, GDPR, eIDAS, DORA and sector secrecy. It may support interoperable, verifiable and time-bounded exchange of specified due-diligence evidence, but shall not state or imply that an obliged entity is discharged from its own legal duties. The scheme shall define issuer competence, assurance level, data minimisation, consent or other legal basis, permitted reliance, freshness, revocation, sanctions and PEP updates, correction, audit, liability allocation, regulator access, cross-border transfer, cyber incident handling and alternatives for persons unable to use the service. HLTF-22. Add a complete intellectual-property, trade-secret and AI value-chain framework Strategy reference: §§3.2, 3.5, 3.11; Legal Services pillar; Annex A Comment type: IP / commercial law / GPAI Comment and implementation risk. The Strategy proposes clarifying protection for ‘computer-generated works’ but does not address the full value chain: training-data acquisition and text-and-data-mining reservations; rights in datasets, models, prompts and outputs; open-source licences; employee/contractor ownership; confidential information; model-provider terms; GPAI copyright duties; provenance; infringement allocation and remedies. Creating a bespoke national right without EU-compatibility analysis could fragment the internal market or produce false confidence. Requested amendment. Replace the narrow promise with an expert review and standard contractual toolkit aligned with EU law. Proposed text for insertion or replacement AI intellectual-property and value-chain framework. Cyprus shall undertake an evidence-based review of copyright, database rights, trade secrets, patents, open-source licensing, contractual rights and GPAI obligations across data acquisition, training, fine-tuning, retrieval, deployment and output use. The review shall assess EU competence and harmonisation limits before proposing national legislation. Public procurement and SME support shall include model clauses on authorised data use, text-and-data-mining reservations, provenance, confidential inputs, provider training use, model and output licences, open-source obligations, infringement warranties, notice-and-takedown, indemnities, audit evidence and termination. No registry entry or contractual label shall be presented as creating ownership that applicable law does not recognise. HLTF-23. Build a proportionate startup and SME compliance-to-scale pathway Strategy reference: §§2.5.4, 3.5, 4.2–4.3; NAICF Comply and AdoptNAICF Comment type: Startups / SMEs / investment / State aid Comment and implementation risk. The Strategy rightly prioritises adoption and funding, but certification-heavy or one-size-fits-all requirements may price startups out before product-market fit. Conversely, grants without legal, procurement and evidence readiness can fund pilots that never scale. National-residency preferences may also conflict with EU procurement, establishment and State-aid rules. Support must follow role, risk and maturity. Requested amendment. Create staged support from classification to cross-border scale, using lawful access criteria and reusable evidence. Proposed text for insertion or replacement Startup and SME implementation pathway. Cyprus shall provide a proportionate, risk-based pathway comprising: free classification and regulatory clinics; AI literacy and standards navigation; model contract and DPIA/FRIA templates; compute and test-data vouchers; access to the statutory sandbox and testing facilities; security and red-team support; procurement-readiness coaching; staged grants tied to evidence and milestones; and support for CE-marking or conformity routes where legally applicable. Requirements shall scale by role, system risk and maturity. Public procurement shall use proportionate turnover, insurance and prior-experience criteria, suitable lotting and transparent challenge-based procedures, without unlawful nationality or residence discrimination. Funding shall address State-aid rules, intellectual property, follow-on finance, commercialisation and measurable additionality. HLTF-24. Add liability, insurance, incident and forensic-evidence architecture Strategy reference: §§3.3.2, 3.9, 3.13; Annexes B–C Comment type: Liability / evidence / enforcement Comment and implementation risk. The Strategy focuses on controls but not on who bears loss when AI fails. Software and AI are addressed by the revised EU Product Liability Directive, while contract, tort, professional duties, public-law liability and sector rules continue to apply. Dynamic models also require evidence that can reconstruct versions, inputs, outputs, human interventions and post-deployment changes. Ordinary logs may be incomplete or controlled by the supplier. Requested amendment. Add a liability and evidence workstream before procurement, not after an incident. Proposed text for insertion or replacement Liability, insurance and forensic readiness. Every high-impact AI initiative shall maintain a responsibility and liability map covering provider, deployer, importer, distributor, integrator, data supplier, cloud/model provider, professional user and public authority. Procurement shall address the revised Product Liability Directive, applicable contract, tort, professional, public-law and sector liability; evidence disclosure; warranties; indemnities; caps; insurance; limitation periods; and recourse through the supply chain. Systems shall preserve proportionate, secure and admissible evidence of model/version, configuration, data provenance, inputs and outputs, human review, changes, incidents and remediation, with retention and access rules. Cyprus shall support CYS-coordinated participation in relevant AI, DLT and digital-evidence standardisation, including international forensic-evidence work, without predetermining its outcome. HLTF-25. Make sustainability and island-resource constraints binding investment gates Strategy reference: §§3.7.1–3.7.4, 3.13; Annexes C and F Comment type: Sustainability / infrastructure / investment Comment and implementation risk. Compute ambitions are not tied to an energy, water, land, grid, carbon or hardware-lifecycle baseline. For an island system, data-centre and AI-factory decisions can create material grid and water dependencies, stranded assets and exposure to imported equipment. Generic references to sustainable infrastructure are not enough for investment appraisal. Requested amendment. Require resource and climate gates for all publicly funded compute and major cloud procurements. Proposed text for insertion or replacement Sustainable AI infrastructure. No major public AI compute or data-centre investment shall proceed without a published whole-life assessment of demand, utilisation, alternatives and shared European capacity; grid connection and resilience; energy source and additionality; water availability and WUE; PUE; embodied carbon and equipment lifecycle; heat reuse; land and permitting; supply-chain concentration; climate adaptation; decommissioning; and total public cost. Tenders shall include comparable metrics, metering, reporting, efficiency thresholds and improvement obligations. The National AI Infrastructure Council shall publish annual capacity, utilisation, energy, water, carbon, outage and cost indicators and explain whether local build, federated access or European shared capacity offers the best public value. HLTF-26. Add labour, professional-responsibility, education and accessibility safeguards Strategy reference: §§3.4–3.6; Education and Human Capital pillar; Annex C Comment type: Employment / education / inclusion Comment and implementation risk. The Strategy promotes augmentation and reskilling but does not provide workforce-impact assessment, worker consultation, protections for algorithmic management, professional accountability, academic integrity or equitable access. AI literacy is a legal obligation in the AI Act but cannot be reduced to tool training. Children, persons with disabilities, non-digital users and workers affected by monitoring or task redesign require specific safeguards. Requested amendment. Insert a social and professional transition framework with accessibility by design. Proposed text for insertion or replacement Human capability and just transition. Public bodies and publicly funded projects shall assess workforce, professional-responsibility, equality, accessibility and skills impacts before deployment. Employers shall provide role-based AI literacy, consult workers and representatives where required, and retain accountable human professional judgement in regulated services. Education uses shall address child rights, teacher control, academic integrity, assessment validity and age-appropriate data protection. Digital services shall meet applicable accessibility requirements and maintain reasonable non-digital alternatives for essential services. The National AI Skills Observatory shall publish disaggregated outcomes, job-quality effects and skills gaps, while training credentials shall be quality-assured and clearly distinguished from standards, licences and regulatory certifications. HLTF-27. Create sector legal maps before sector deployment Strategy reference: Priority-sector roadmaps and Annex C Comment type: Sector regulation / implementation Comment and implementation risk. The Strategy’s sector roadmaps often state ‘full alignment’ with EU law without identifying the actual regulatory perimeter, competent regulator, professional decision-maker, evidence standard or additional sector approval. The result is greatest in health, finance, education, employment, maritime, critical infrastructure, justice, law enforcement and public benefits, where AI Act duties coexist with product, safety, data, consumer and professional rules. Requested amendment. Make a sector legal and standards map a condition to funding and procurement. Proposed text for insertion or replacement Sector implementation dossiers. Before funding or procurement in a priority sector, the responsible ministry and competent regulators shall publish a dossier identifying: intended use and AI Act classification; provider/deployer and product-supply-chain roles; applicable sector and professional law; competent authorities; data-access and confidentiality rules; required authorisations and conformity route; fundamental-rights and safety assessment; standards profile; clinical, financial, educational, judicial or operational evidence; human decision authority; incident and complaint routes; liability and insurance; and post-deployment monitoring. At minimum, the dossiers shall address health and medical-device law and EHDS; DORA, MiCA, the DLT Pilot Regime and AML law for finance; education, employment and platform-work law; maritime and product-safety rules; and justice, law-enforcement and biometric safeguards. HLTF-28. Replace aspirational KPIs with baselines, owners, budgets and independent evaluation Strategy reference: §§1.5, 2.4, 4.4; Annex F; sector targets Comment type: Delivery / public finance / evaluation Comment and implementation risk. Headline targets - including GDP uplift, productivity, 75% adoption and three unicorns - are not accompanied by definitions, baselines, causal models, costs, sensitivity analysis or accountable owners. Adoption is not consistently dated (2030 and 2032). Annex F is described as indicative and may be changed without revising the core Strategy, weakening accountability. Counting deployments can reward low-value or risky use. Requested amendment. Publish a costed delivery portfolio and independent evaluation protocol before commitments are treated as targets. Proposed text for insertion or replacement Delivery, finance and evaluation. Within 120 days, each programme shall have an accountable senior owner, delivery partner, legal basis, baseline, target definition, population, data source, methodology, milestones, dependencies, budget and funding source, procurement route, risk appetite, benefits-realisation plan and stop/scale criteria. Targets shall distinguish adoption from effective, lawful and sustained use. The 75% target and its year shall be reconciled across the document. Macroeconomic and productivity claims shall disclose the model, assumptions, confidence range and attribution limits. An independent evaluator shall publish annual results, incidents, distributional impacts, cost variance and reasons for continuation, modification or termination. Material KPI changes shall require a dated public change notice and governance approval." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",Shadgunya,"Commentary on the Cyprus National AI Strategy 2032 Building an Operational Sovereign AI Ecosystem for Cyprus and Europe Submitted by Shadgunya Technologies Group Shadgunya Technologies welcomes the Cyprus National AI Strategy 2032 and strongly supports its ambition to establish Cyprus as a trusted AI hub in the Eastern Mediterranean and a reliable European jurisdiction for AI-enabled services. The Strategy correctly recognises that AI sovereignty does not require technological isolation. It requires Cyprus to retain meaningful control over critical compute infrastructure, strategic data, models, operational governance, security and skills, while using trusted European and international partnerships to achieve scale. Its proposals for a National AI Infrastructure, federated data architecture, sovereign specialised language models, the Government Innovation Hub, Pharos-CY integration and European AI assurance capabilities provide a strong foundation. The next step should be to translate these principles into an enforceable national architecture, procurement framework and funded implementation programme. 1. Define AI sovereignty as measurable control The Strategy should include an operational definition of sovereignty covering six layers: 1. Data sovereignty: Cyprus retains control over the location, access, classification, reuse, retention and deletion of national data. 2. Compute sovereignty: Sensitive workloads can be operated within infrastructure controlled by Cyprus, including protected on-island and offline environments. 3. Model sovereignty: Cyprus can inspect, evaluate, fine-tune, replace and independently operate the models used for critical public functions. 4. Operational sovereignty: Government systems can continue functioning during loss of external connectivity, geopolitical disruption, vendor failure or suspension of a commercial service. 5. Security and supply-chain sovereignty: Cyprus retains encryption-key custody, complete auditability and visibility into software, model and hardware dependencies. 6. Economic and intellectual-property sovereignty: Public investment creates local skills, Cypriot employment, locally anchored IP and exportable European products. Every critical AI procurement should be assessed against these six dimensions. Any exception should require documented approval from the National AI Authority. 2. Establish a tiered National Sovereign AI Infrastructure The proposed National AI Infrastructure should not be treated as a single data centre or GPU cluster. It should be a distributed national capability with three security zones: ● European and commercial compute: For non-sensitive research, general experimentation and large-scale training. ● Cyprus Government AI Cloud: For regulated public-sector workloads, operated under Cypriot governance and integrated with the G-Cloud. ● Protected sovereign environments: On-island, offline, air-gapped or edge infrastructure for defence, law enforcement, healthcare, critical infrastructure and other highly sensitive applications. Large-scale training may use EuroHPC and European AI Factories, while sensitive data processing and mission-critical inference remain under Cypriot control. This would implement the Strategy’s intended balance between sovereign capability and European integration The infrastructure roadmap should specify: ● Initial and projected GPU capacity. ● Guaranteed compute allocation for government, universities and startups. ● Two-site resilience and disaster recovery. ● Encryption-key custody and privileged-access controls. ● Minimum availability and recovery targets. ● Energy source, cooling, water consumption and power-usage efficiency. ● GPU utilisation, waiting time and cost per workload. ● Hardware and software renewal cycles. ● Procedures for disconnected and degraded operations. A minimum viable sovereign infrastructure should become operational before 2028, followed by modular expansion through 2032. 3. Correct the sequencing between architecture and procurement The Strategy proposes launching procurements for six transformational AI solutions within eight months. This creates a risk that applications will be purchased before national standards for data, models, APIs, security and portability have been established. During the first 180 days, Cyprus should complete: ● A National Sovereign AI Reference Architecture. ● Government-wide data classification and AI workload classification. ● Common API, identity, logging and model-interface standards. ● Standard contractual clauses for AI procurement. ● A national model and application registry. ● Minimum security, testing and lifecycle requirements. ● Vendor exit, data portability and continuity procedures. Critical AI contracts should require open interfaces, exportable data, reproducible deployment, source-code or model-artifact escrow where appropriate, software and model bills of materials, independent security testing, local knowledge transfer and clearly defined government rights over improvements developed using public data. This would prevent foreign platform dependence from becoming embedded through early procurements. 4. Build a federated national data fabric—not merely a central warehouse The Strategy appropriately calls for federated data architecture and sectoral data spaces. This should be expanded into an operational National Data Fabric containing: ● A catalogue of national and sectoral datasets. ● Standard metadata and semantic definitions. ● Data lineage, provenance and quality scoring. ● Purpose-based access and consent controls. ● Privacy-preserving research environments and data clean rooms. ● Federated query and analytics capabilities. ● APIs for authorised government and industry use. ● Immutable audit trails for sensitive access. ● Synthetic and anonymised datasets for innovation. Cyprus should also create trusted national language and knowledge resources covering Cyprus-relevant legal, administrative, financial, maritime, tourism and public-service terminology. These resources can support specialised multilingual models without requiring Cyprus to train a very large general-purpose model from the beginning. 5. Prioritise specialised sovereign models and reusable components Cyprus does not need to compete by building the largest foundation model. It can differentiate by developing smaller, efficient and auditable models for regulated European use. A National AI Model Gateway should allow ministries to use multiple European, open-weight and commercial models through a common governed interface. It should support: ● Specialised language models for Cypriot law and public administration. ● Retrieval from authoritative government sources. ● Multilingual document and speech intelligence. ● Model routing based on security, cost and accuracy. ● Central evaluation and approval. ● On-premise and edge inference. ● Model replacement without rewriting applications. ● Continuous monitoring for accuracy, bias, hallucination and data leakage. Common capabilities such as document intelligence, identity resolution, multilingual assistants, entity correlation, geospatial analytics and case management should be built once and reused across ministries, consistent with the Strategy’s own “build once, reuse everywhere” principle. 6. Make AI security and assurance a continuous operational function Compliance should not stop at certification. Cyprus should establish continuous AI assurance covering: ● Prompt-injection and data-exfiltration testing. ● Model poisoning and adversarial manipulation. ● Supply-chain and dependency assessment. ● Red-team testing before production. ● Runtime monitoring and anomaly detection. ● Human override and safe fallback. ● Version control, rollback and decommissioning. ● Incident reporting and coordinated response. ● Periodic re-evaluation after model or data changes. The proposed European AI Certification Lab should maintain appropriate organisational independence between system developers, operators and assessors. It can become an important European capability by combining EU AI Act readiness with practical cybersecurity and operational-resilience testing. 7. Simplify governance and assign delivery accountability The Strategy proposes several authorities, councils, committees, observatories, hubs and Centres of Excellence. While each has value, overlapping responsibilities could slow execution. The National AI Authority should be the single accountable owner of: ● National architecture and technical standards. ● Common platforms. ● Compute allocation. ● Procurement templates. ● Portfolio prioritisation. ● Programme-level budgets. ● Quarterly delivery reporting. Specialised committees should provide oversight and expert advice without creating additional approval chains. Every flagship programme should have one accountable owner, a defined budget, a delivery timetable and measurable citizen or economic outcomes. Headline targets such as GDP expansion, the creation of three unicorns and the number of AI professionals should be supplemented with controllable operational indicators: production systems deployed, processing-time reduction, cost avoidance, locally owned IP, export revenue, compute utilisation, public trust, security incidents, SME participation and the percentage of critical workloads that can operate independently. 8. Lessons from Shadgunya’s experience in India Through its group companies, Pinaca Technologies and Saptang Labs, Shadgunya has worked on sovereign AI, analytics, digital forensics and cybersecurity systems for sensitive government, law-enforcement, defence and national-security environments in India. Relevant completed and operational experience includes: ● Serving as a technology partner to MARVEL and supporting sensitive law-enforcement and intelligence requirements, including work associated with Maharashtra ATS. ● Providing digital-forensics capabilities to more than 15 Indian agencies, including Income Tax, Customs, the Enforcement Directorate, CBI and NIA. ● Delivering operational social-media monitoring services for India’s Ministry of Electronics and Information Technology. ● Supporting the Indian Cyber Crime Coordination Centre in money-mule and financial-investigation requirements. ● Deploying BlackFence remote-audit capabilities within Indian Army infrastructure. ● Delivering Sovereign AI Products through Indian Army and Indian Navy AI incubation ecosystems. ● Completing Soverign AI based engagements with BSNL and RailTel for network-scale cybersecurity capabilities. Our experience has produced five important observations: 1. Government AI projects usually fail at the data and workflow layers, not at the model layer. Data preparation, system integration and operational adoption must therefore precede model selection. 2. Sensitive systems require deployment flexibility. On-premise, offline, air-gapped, hybrid-cloud and edge deployment patterns must be part of the original architecture. 3. Auditability is as important as accuracy. Investigative and regulatory systems require provenance, chain of custody, role-based access, human review and reproducible results. 4. Shared capabilities create national scale. Document intelligence, entity correlation, language processing, geospatial analysis and case management should not be procured repeatedly by separate departments. 5. Sovereignty ultimately depends on people. A system is not sovereign if local engineers cannot operate, secure, modify and recover it without continuous external dependence. 9. Proposed Shadgunya contribution in Cyprus Shadgunya looks forward to adapting these field-tested engineering patterns to Cyprus under European legal, ethical and institutional requirements. We do not propose transferring Indian systems or operating models unchanged. The objective would be to co-develop Cyprus-owned, EU-aligned capabilities with local government, universities, research institutions and industry. Potential areas of collaboration include: ● Designing the National Sovereign AI Reference Architecture. ● Establishing a secure multi-model government AI platform. ● Developing specialised sovereign models for regulated sectors. ● Creating an AI cybersecurity, red-team and assurance environment. ● Supporting financial-crime, AML and fraud-intelligence applications. ● Building critical-infrastructure, maritime and national-resilience analytics. ● Developing offline and edge AI for sensitive government operations. ● Training Cypriot engineers, AI Officers and security professionals. ● Establishing joint R&D in RISC-V security, sovereign chiplets, SLMs and secure edge AI. ● Creating locally anchored IP and export-ready products from Cyprus. An initial programme could begin with three lighthouse implementations: a reusable government knowledge and document-intelligence platform, a regulated financial-crime and compliance platform, and an AI security and critical-infrastructure monitoring capability. Conclusion Cyprus has an opportunity to become more than a consumer of foreign AI services. It can become a European centre for the design, assurance and export of sovereign AI systems for governments and regulated industries. The Strategy provides the right direction. Its next iteration should define exactly what Cyprus must control, what it will build nationally, what it will access through Europe, and what every supplier must transfer to the Cypriot ecosystem. Shadgunya Technologies looks forward to establishing a Cyprus-based sovereign AI engineering, assurance and productisation capability. Our objective is to adapt experience gained from operational government, defence, investigative and cybersecurity projects in India; co-develop these capabilities within Cyprus; ensure alignment with European rights and regulatory frameworks; and use Cyprus as the base from which trusted sovereign AI products can be delivered across Europe." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",Shadgunya,"Commentary on the Cyprus National AI Strategy 2032 Building an Operational Sovereign AI Ecosystem for Cyprus and Europe Submitted by Shadgunya Technologies Group Shadgunya Technologies welcomes the Cyprus National AI Strategy 2032 and strongly supports its ambition to establish Cyprus as a trusted AI hub in the Eastern Mediterranean and a reliable European jurisdiction for AI-enabled services. The Strategy correctly recognises that AI sovereignty does not require technological isolation. It requires Cyprus to retain meaningful control over critical compute infrastructure, strategic data, models, operational governance, security and skills, while using trusted European and international partnerships to achieve scale. Its proposals for a National AI Infrastructure, federated data architecture, sovereign specialised language models, the Government Innovation Hub, Pharos-CY integration and European AI assurance capabilities provide a strong foundation. The next step should be to translate these principles into an enforceable national architecture, procurement framework and funded implementation programme. 1. Define AI sovereignty as measurable control The Strategy should include an operational definition of sovereignty covering six layers: 1. Data sovereignty: Cyprus retains control over the location, access, classification, reuse, retention and deletion of national data. 2. Compute sovereignty: Sensitive workloads can be operated within infrastructure controlled by Cyprus, including protected on-island and offline environments. 3. Model sovereignty: Cyprus can inspect, evaluate, fine-tune, replace and independently operate the models used for critical public functions. 4. Operational sovereignty: Government systems can continue functioning during loss of external connectivity, geopolitical disruption, vendor failure or suspension of a commercial service. 5. Security and supply-chain sovereignty: Cyprus retains encryption-key custody, complete auditability and visibility into software, model and hardware dependencies. 6. Economic and intellectual-property sovereignty: Public investment creates local skills, Cypriot employment, locally anchored IP and exportable European products. Every critical AI procurement should be assessed against these six dimensions. Any exception should require documented approval from the National AI Authority. 2. Establish a tiered National Sovereign AI Infrastructure The proposed National AI Infrastructure should not be treated as a single data centre or GPU cluster. It should be a distributed national capability with three security zones: ● European and commercial compute: For non-sensitive research, general experimentation and large-scale training. ● Cyprus Government AI Cloud: For regulated public-sector workloads, operated under Cypriot governance and integrated with the G-Cloud. ● Protected sovereign environments: On-island, offline, air-gapped or edge infrastructure for defence, law enforcement, healthcare, critical infrastructure and other highly sensitive applications. Large-scale training may use EuroHPC and European AI Factories, while sensitive data processing and mission-critical inference remain under Cypriot control. This would implement the Strategy’s intended balance between sovereign capability and European integration The infrastructure roadmap should specify: ● Initial and projected GPU capacity. ● Guaranteed compute allocation for government, universities and startups. ● Two-site resilience and disaster recovery. ● Encryption-key custody and privileged-access controls. ● Minimum availability and recovery targets. ● Energy source, cooling, water consumption and power-usage efficiency. ● GPU utilisation, waiting time and cost per workload. ● Hardware and software renewal cycles. ● Procedures for disconnected and degraded operations. A minimum viable sovereign infrastructure should become operational before 2028, followed by modular expansion through 2032. 3. Correct the sequencing between architecture and procurement The Strategy proposes launching procurements for six transformational AI solutions within eight months. This creates a risk that applications will be purchased before national standards for data, models, APIs, security and portability have been established. During the first 180 days, Cyprus should complete: ● A National Sovereign AI Reference Architecture. ● Government-wide data classification and AI workload classification. ● Common API, identity, logging and model-interface standards. ● Standard contractual clauses for AI procurement. ● A national model and application registry. ● Minimum security, testing and lifecycle requirements. ● Vendor exit, data portability and continuity procedures. Critical AI contracts should require open interfaces, exportable data, reproducible deployment, source-code or model-artifact escrow where appropriate, software and model bills of materials, independent security testing, local knowledge transfer and clearly defined government rights over improvements developed using public data. This would prevent foreign platform dependence from becoming embedded through early procurements. 4. Build a federated national data fabric—not merely a central warehouse The Strategy appropriately calls for federated data architecture and sectoral data spaces. This should be expanded into an operational National Data Fabric containing: ● A catalogue of national and sectoral datasets. ● Standard metadata and semantic definitions. ● Data lineage, provenance and quality scoring. ● Purpose-based access and consent controls. ● Privacy-preserving research environments and data clean rooms. ● Federated query and analytics capabilities. ● APIs for authorised government and industry use. ● Immutable audit trails for sensitive access. ● Synthetic and anonymised datasets for innovation. Cyprus should also create trusted national language and knowledge resources covering Cyprus-relevant legal, administrative, financial, maritime, tourism and public-service terminology. These resources can support specialised multilingual models without requiring Cyprus to train a very large general-purpose model from the beginning. 5. Prioritise specialised sovereign models and reusable components Cyprus does not need to compete by building the largest foundation model. It can differentiate by developing smaller, efficient and auditable models for regulated European use. A National AI Model Gateway should allow ministries to use multiple European, open-weight and commercial models through a common governed interface. It should support: ● Specialised language models for Cypriot law and public administration. ● Retrieval from authoritative government sources. ● Multilingual document and speech intelligence. ● Model routing based on security, cost and accuracy. ● Central evaluation and approval. ● On-premise and edge inference. ● Model replacement without rewriting applications. ● Continuous monitoring for accuracy, bias, hallucination and data leakage. Common capabilities such as document intelligence, identity resolution, multilingual assistants, entity correlation, geospatial analytics and case management should be built once and reused across ministries, consistent with the Strategy’s own “build once, reuse everywhere” principle. 6. Make AI security and assurance a continuous operational function Compliance should not stop at certification. Cyprus should establish continuous AI assurance covering: ● Prompt-injection and data-exfiltration testing. ● Model poisoning and adversarial manipulation. ● Supply-chain and dependency assessment. ● Red-team testing before production. ● Runtime monitoring and anomaly detection. ● Human override and safe fallback. ● Version control, rollback and decommissioning. ● Incident reporting and coordinated response. ● Periodic re-evaluation after model or data changes. The proposed European AI Certification Lab should maintain appropriate organisational independence between system developers, operators and assessors. It can become an important European capability by combining EU AI Act readiness with practical cybersecurity and operational-resilience testing. 7. Simplify governance and assign delivery accountability The Strategy proposes several authorities, councils, committees, observatories, hubs and Centres of Excellence. While each has value, overlapping responsibilities could slow execution. The National AI Authority should be the single accountable owner of: ● National architecture and technical standards. ● Common platforms. ● Compute allocation. ● Procurement templates. ● Portfolio prioritisation. ● Programme-level budgets. ● Quarterly delivery reporting. Specialised committees should provide oversight and expert advice without creating additional approval chains. Every flagship programme should have one accountable owner, a defined budget, a delivery timetable and measurable citizen or economic outcomes. Headline targets such as GDP expansion, the creation of three unicorns and the number of AI professionals should be supplemented with controllable operational indicators: production systems deployed, processing-time reduction, cost avoidance, locally owned IP, export revenue, compute utilisation, public trust, security incidents, SME participation and the percentage of critical workloads that can operate independently. 8. Lessons from Shadgunya’s experience in India Through its group companies, Pinaca Technologies and Saptang Labs, Shadgunya has worked on sovereign AI, analytics, digital forensics and cybersecurity systems for sensitive government, law-enforcement, defence and national-security environments in India. Relevant completed and operational experience includes: ● Serving as a technology partner to MARVEL and supporting sensitive law-enforcement and intelligence requirements, including work associated with Maharashtra ATS. ● Providing digital-forensics capabilities to more than 15 Indian agencies, including Income Tax, Customs, the Enforcement Directorate, CBI and NIA. ● Delivering operational social-media monitoring services for India’s Ministry of Electronics and Information Technology. ● Supporting the Indian Cyber Crime Coordination Centre in money-mule and financial-investigation requirements. ● Deploying BlackFence remote-audit capabilities within Indian Army infrastructure. ● Delivering Sovereign AI Products through Indian Army and Indian Navy AI incubation ecosystems. ● Completing Soverign AI based engagements with BSNL and RailTel for network-scale cybersecurity capabilities. Our experience has produced five important observations: 1. Government AI projects usually fail at the data and workflow layers, not at the model layer. Data preparation, system integration and operational adoption must therefore precede model selection. 2. Sensitive systems require deployment flexibility. On-premise, offline, air-gapped, hybrid-cloud and edge deployment patterns must be part of the original architecture. 3. Auditability is as important as accuracy. Investigative and regulatory systems require provenance, chain of custody, role-based access, human review and reproducible results. 4. Shared capabilities create national scale. Document intelligence, entity correlation, language processing, geospatial analysis and case management should not be procured repeatedly by separate departments. 5. Sovereignty ultimately depends on people. A system is not sovereign if local engineers cannot operate, secure, modify and recover it without continuous external dependence. 9. Proposed Shadgunya contribution in Cyprus Shadgunya looks forward to adapting these field-tested engineering patterns to Cyprus under European legal, ethical and institutional requirements. We do not propose transferring Indian systems or operating models unchanged. The objective would be to co-develop Cyprus-owned, EU-aligned capabilities with local government, universities, research institutions and industry. Potential areas of collaboration include: ● Designing the National Sovereign AI Reference Architecture. ● Establishing a secure multi-model government AI platform. ● Developing specialised sovereign models for regulated sectors. ● Creating an AI cybersecurity, red-team and assurance environment. ● Supporting financial-crime, AML and fraud-intelligence applications. ● Building critical-infrastructure, maritime and national-resilience analytics. ● Developing offline and edge AI for sensitive government operations. ● Training Cypriot engineers, AI Officers and security professionals. ● Establishing joint R&D in RISC-V security, sovereign chiplets, SLMs and secure edge AI. ● Creating locally anchored IP and export-ready products from Cyprus. An initial programme could begin with three lighthouse implementations: a reusable government knowledge and document-intelligence platform, a regulated financial-crime and compliance platform, and an AI security and critical-infrastructure monitoring capability. Conclusion Cyprus has an opportunity to become more than a consumer of foreign AI services. It can become a European centre for the design, assurance and export of sovereign AI systems for governments and regulated industries. The Strategy provides the right direction. Its next iteration should define exactly what Cyprus must control, what it will build nationally, what it will access through Europe, and what every supplier must transfer to the Cypriot ecosystem. Shadgunya Technologies looks forward to establishing a Cyprus-based sovereign AI engineering, assurance and productisation capability. Our objective is to adapt experience gained from operational government, defence, investigative and cybersecurity projects in India; co-develop these capabilities within Cyprus; ensure alignment with European rights and regulatory frameworks; and use Cyprus as the base from which trusted sovereign AI products can be delivered across Europe." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",AlexiaAchilleos,"Αρ. Άρθρου:  3.9 Ethics, Trust and Responsible AI Σχόλιο: An intersectionally diverse and representative taskforce/cohort of contributors must be ensured with regard to any AI policymaking and governance on a national level.  Αιτιολόγηση σχολίου / Εισήγησης:  The section rightly highlights the importance of ethics, accountability, fairness, transparency, and safeguarding societal values, achieving these goals requires a task force that genuinely reflects all stakeholders and the diversity of Cypriot society. A homogeneous, male-dominated cohort composed primarily of Greek/Greek Cypriots, academic institutions, and private corporations should be avoided. Such narrow governance inevitably skews the values and priorities driving national AI policymaking, which in turn can have considerable political impact on a national level. A lack of diversity creates policy blind spots and reinforces systemic inequalities that dominant groups can overlook. This issue is particularly critical for AI technologies, which have been proven to exacerbate inequality and further marginalise vulnerable communities across various global contexts, especially when deployed in the public sector, healthcare, recruitment, and law enforcement. In Cyprus, initial research indicates that the most vulnerable groups of the island (such as low-skilled workers, ethnic and sexual minorities, people with disabilities, migrants, and asylum seekers) may face the highest risk of AI-related harm.  Instead, having a cohort that is inclusive in terms of gender, ethnicity, and discipline (including civil society, labour unions, etc) can contribute towards ensuring human rights, fairness and equity, particularly taking the local Cypriot context into consideration. It also ensures that the values and priorities driving AI governance in Cyprus will not be limited to benefitting only a small, dominant section of society. It is recommended that the formation of diverse and inclusive cohorts is embedded directly into the government's strategic AI planning, and be formally integrated within the Cypriot AI strategy and policymaking infrastructure." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",AndreasKazamias,"CONTRIBUTION TO THE PUBLIC CONSULTATION ON THE NATIONAL ARTIFICIAL INTELLIGENCE STRATEGY 2032 Submitted by: Andreas Kazamias Founder, Platanus Services Ltd, Cyprus Managing Director EMEA, Liberty IT Consulting Group, Australia Date: 29 August 2026 Article / Section concerned National AI Strategy 2032 as a whole, with particular reference to Sections 1.4, 3.2–3.13, 4–5 and Annexes A–F. Comment / Recommendation It is encouraging to see Cyprus develop a National AI Strategy and make it available for public consultation. The Deputy Ministry of Research, Innovation and Digital Policy, the Chief Scientist for Research, Innovation and Technology, the National AI Taskforce and all those involved in preparing the Strategy should be congratulated. The Strategy is ambitious and identifies many of the capabilities Cyprus will require. The principal opportunity before it is finalised is to strengthen the connection between vision, strategic choice and execution. My principal recommendations are: 1. Sharpen prioritisation. Cyprus should distinguish between capabilities it must maintain nationally, a limited number of areas where it intends to develop internationally differentiated capability, and capabilities that can be accessed more effectively through European or international partnerships. Possible areas for further assessment include AI assurance and regulatory science, AI for island, climate and resource resilience, and maritime and shipping applications. 2. Define AI sovereignty more practically. Full technological self-sufficiency is neither realistic nor necessary. For Cyprus, sovereignty should mean retaining control over critical data and functions, sufficient technical knowledge, interoperability, portability, contractual rights and credible alternative suppliers. Sovereignty should mean retaining the capacity to choose, not restricting the technologies from which Cyprus can choose. 3. Link public-sector AI to measurable benefits. AI creates additional technology, training, governance and operating costs. Every material public-sector AI programme should therefore identify the capacity expected to be released, the full lifecycle cost and how the benefit will be realised through improved services, redeployment, avoided future recruitment, reduced cost or other measurable public value. AI deployment is an activity. Realised public value is the outcome. 4. Redesign processes before automating them. AI should not simply automate existing administrative procedures. Major projects should first simplify processes, eliminate unnecessary approvals and duplicated information requirements, improve data reuse and review workforce responsibilities. AI should not automate yesterday's bureaucracy. 5. Make ethics operational. Ethical principles should be implemented through risk assessment, accountable ownership, testing, documentation, monitoring, incident management and redress. Ethics committees may provide valuable specialist challenge but should not substitute for lifecycle governance. The several ethics-related bodies referred to in the Strategy should also be reconciled and given clear Terms of Reference. 6. Clarify human oversight. Human-centred AI should preserve accountability and meaningful human intervention in appropriate circumstances, but should not necessarily require a human to repeat every routine AI-supported assessment. Human-in-command does not require human-in-every-transaction. 7. Establish a proportionate private-sector AI governance pathway. The Strategy provides detailed governance for government but less operational guidance for ordinary enterprises and SMEs. NAICF Comply and AdoptNAICF could provide the basis for a horizontal private-sector framework rather than appearing primarily within Legal Services. 8. Clarify the State's role in Financial Services and Financial Technology. Several proposed use cases are principally matters for individual financial institutions. The National Strategy should concentrate on what Cyprus can provide collectively that institutions cannot efficiently provide themselves: coordinated regulatory pathways, appropriate sandboxes, skills, assurance, shared mechanisms where justified, RegTech and SupTech capability and FinTech ecosystem development. 9. Extend data governance beyond access. The Strategy should address not only who may access public data, but also who may derive models, embeddings, inferred information or other intellectual property from it, on what terms, and who retains the resulting capability. 10. Simplify institutional and sandbox architecture. Regulatory sandboxes, technical test environments, secure data environments and physical testbeds serve different purposes. Cyprus should avoid creating parallel sector structures where common national capability with specialist participation would suffice. Similarly, Centres of Excellence should strengthen existing universities, research organisations and private capability rather than unnecessarily duplicate them. 11. Clarify specific governance ambiguities. These include the reporting line and authority of ministry AI Officers; the distinction between development, testing, assurance and formal certification; the relationship between private Legal Services and judicial or public-sector AI; and the status of testing performed by the proposed Industrial Centre of Excellence. 12. Move measurement from indicative to operational. Annex F is a useful starting point, but each core KPI should define its baseline, target, methodology, source, accountable owner, reporting frequency and intervention threshold. Deployment should be distinguished from measurable outcomes. 13. Apply a consistent evidential standard throughout. The Education and Human Capital Development section provides a useful example of detailed references and supporting evidence. Material numerical targets, international comparisons and statements of best practice elsewhere in the Strategy should be supported to the same standard. 14. Address additional cross-cutting implementation issues. The final Strategy should also consider the role of open-source and open-weight AI, contractual allocation of AI procurement risk, retention and traceability of AI-assisted public records, and the risk of excessive concentration around a small number of cloud, model and systems-integration providers. Justification Cyprus does not need to lead in every field of Artificial Intelligence. Its size can instead become an advantage if the country is clear about where it intends to lead, where it requires sufficient national capability, and where European and international collaboration will produce better results. The Strategy already contains much of the necessary foundation. The recommendations above are intended primarily to make the final document more selective, operational and measurable: clearer choices, clearer ownership, realistic sequencing and resources, and a stronger connection between AI investment and demonstrable national benefit. A full submission has also been provided separately in PDF form. It is structured in three parts: the Main Response, setting out the principal strategic observations and recommendations; a detailed Appendix, containing section- and page-specific observations and recommendations against the National AI Strategy; and a Sources and References section supporting the analysis. This structure allows the broader strategic recommendations to be considered alongside the specific provisions of the Strategy to which they relate. The PDF should therefore be read together with this summary as the complete contribution to the consultation." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",CITEA,"Section 3.11 “Measuring Impact and National KPIs” Suggestion: Enhance the existing KPI framework by establishing a comprehensive National AI Performance Scorecard supported by a formal measurement governance structure. Each KPI should be accompanied by a clear definition, baseline value, target trajectory, data source, accountable owner, reporting frequency, calculation methodology, dependencies, and escalation criteria. Furthermore, the scorecard should differentiate between implementation metrics (such as training programmes delivered, AI pilots completed, or digital services enhanced) and impact metrics (such as productivity gains, AI adoption rates, citizen trust, investment attraction, economic contribution, and societal outcomes). Justification: The strategy identifies several key dimensions for measuring success, including AI adoption, public sector transformation, talent development, trust, compliance, and economic impact. However, the absence of a structured measurement governance framework may limit the ability to consistently monitor progress and assess the effectiveness of strategic initiatives. A comprehensive performance scorecard would improve transparency, accountability, and evidence-based decision-making by ensuring that all stakeholders operate against a common set of measurable objectives. Clearly defined baselines, ownership responsibilities, and escalation mechanisms would facilitate early identification of underperforming initiatives and support timely corrective actions. This would strengthen the overall governance of the strategy and provide greater confidence that reported progress reflects tangible national outcomes rather than activity levels alone. Section 3.3, “Governance and Controls” Suggestion: Introduce a detailed Roles, Responsibilities and Decision-Making Framework that clearly defines the responsibilities, accountabilities, consultation requirements, and reporting obligations of all governance and delivery stakeholders involved in the implementation of the National AI Strategy. The framework should specify governance interactions across the National AI Authority, the responsible Ministry or Deputy Ministry, the Interministerial AI Council, specialised advisory committees, delivery organisations, regulators, public sector entities, research institutions, local authorities, and private-sector partners. Justification: The strategy establishes a robust multi-layer governance structure; however, the practical interaction between the various bodies and stakeholders is not always fully defined. As AI initiatives frequently span multiple policy areas, organisations, and sectors, unclear accountability arrangements may lead to overlapping responsibilities, duplication of effort, delayed decision-making, and implementation challenges. A formal governance and decision-making framework would provide greater clarity regarding ownership of strategic initiatives, funding decisions, risk management, regulatory oversight, and benefit realisation. It would also improve coordination across stakeholders, strengthen accountability for delivery milestones and outcomes, and support more effective escalation and resolution of implementation issues. Ultimately, this would enhance the efficiency and effectiveness of the strategy's execution and increase the likelihood of achieving its long-term objectives. Section 3.10.3 “Funding and Renewal Model ” Suggestion: Introduce a dedicated, multi-year budget and funding framework for the implementation of the National AI Strategy, including indicative budgets per strategic pillar, funding sources, responsible authorities, and annual allocation mechanisms. Justification: While the strategy establishes a clear vision, objectives, and initiatives, it does not provide sufficient visibility regarding the financial resources required to achieve them. Successful implementation of national AI programmes requires sustained investment in digital infrastructure, data platforms, skills development, research and innovation, public sector transformation, cybersecurity, and governance mechanisms. Without a dedicated budget, there is a risk that strategic initiatives will be delayed, scaled back, or implemented inconsistently across government entities. A defined funding framework would enhance accountability, facilitate long-term planning, improve stakeholder confidence, and enable the government to leverage European Union funding programmes and private sector co-investment more effectively. Section 1.5 “Implementation Timeline and Success Metrics"" Suggestion: Develop a detailed implementation roadmap with clear milestones, timelines, deliverables, responsible organisations, dependencies, and key performance indicators (KPIs) covering the period up to 2032. Justification: The strategy outlines strategic priorities and desired outcomes but would benefit from a more structured execution plan. A roadmap with phased milestones (short-term, medium-term, and long-term) would provide clarity on implementation priorities and sequencing of activities. It would also enable monitoring of progress, facilitate coordination among government entities, academia, and industry, and allow early identification of implementation challenges. Furthermore, measurable milestones would support transparent reporting to stakeholders, strengthen governance, and ensure that progress towards the strategy's objectives can be objectively assessed and adjusted where necessary. Such an approach aligns with international best practices for national digital and AI strategies and increases the likelihood of achieving the intended outcomes by 2032." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Periklis Theodoridis","The below 8 recommendations focus on tangible amendments that can strengthen the Strategy’s implementation, accountability, business adoption and investment attractiveness. 1. Costed implementation and investment plan Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Sections 1.5, 3.10, 3.11 and 5; Annex F. Σχόλιο / Εισήγηση: Within 90 days of the Strategy’s adoption, an Implementation and Investment Plan should be approved and published. For every strategic initiative, the Plan should identify the accountable owner, delivery milestones, budget range, funding source, dependencies, procurement route, measurable KPIs and continuation or exit criteria. Αιτιολόγηση σχολίου / Εισήγησης: The Strategy includes several ambitious initiatives and timelines, but many do not yet have an identified owner, budget, funding route or measurable delivery condition. A single costed implementation portfolio would support effective prioritisation, prevent duplication and enable transparent monitoring of delivery, expenditure and public value. 2. Separation of delivery and statutory supervision Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Sections 1.4.3, 3.3.1, 3.9.6 and 4.3; Annex A. Σχόλιο / Εισήγηση: The final Strategy should clearly distinguish the Strategy owner and delivery office from the competent authorities responsible for market surveillance, conformity assessment, data protection, cybersecurity and sectoral regulation. No organisation should simultaneously fund or develop AI solutions and provide binding assurance, certification or enforcement concerning those same solutions. Αιτιολόγηση σχολίου / Εισήγησης: Clear institutional separation protects regulatory independence, avoids conflicts of interest and provides businesses with greater legal and regulatory certainty. Innovation support, regulatory sandboxes and pre-compliance guidance are valuable functions, but they should not be confused with statutory supervision, certification or enforcement under the EU AI Act and existing national law. 3. Measurable and consistent national targets Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Sections 1.5, 2.5 and 3.11; Annex F. Σχόλιο / Εισήγηση: For every national KPI, the final Strategy should define: * The baseline year and value. * The calculation formula. * The authoritative data source. * The accountable owner. * The reporting frequency. * The annual target trajectory to 2032. Any inconsistent adoption percentages or target dates should be reconciled. GDP and productivity estimates should be presented as scenarios until independently validated. Αιτιολόγηση σχολίου / Εισήγησης: Targets cannot guide investment or demonstrate impact unless they are clearly and consistently defined. A public KPI register, updated at least annually, would allow government, businesses and society to distinguish measurable outcomes from activity indicators such as the number of pilots, tools purchased or people attending training. 4. Mandatory data-readiness control gate Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Sections 2.2.2 and 3.2.2; Section 5; Annex B, Control Gates 1 and 2. Σχόλιο / Εισήγηση: The Strategy should establish a target publication date for the National Data Policy and the National Data Governance Framework. Before the procurement, funding or scaling of any public-sector AI use case, the responsible organisation should be required to demonstrate: * An identified data owner. * A documented lawful basis. * Defined data-quality thresholds. * Data classification, metadata and lineage. * Retention and access-control requirements. * Confirmed availability of the required data. This should become an explicit requirement within the Strategy’s AI use-case control gates. Αιτιολόγηση σχολίου / Εισήγησης: AI projects frequently fail or underperform because the required data is unavailable, unreliable, incomplete or not lawfully usable. A mandatory data-readiness gate would prevent premature procurement, reduce rework and ensure that pilots are selected because they can deliver measurable outcomes—not merely because the technology is available. 5. Investment-compatible definition of AI sovereignty Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Sections 1.1, 1.2-National Strategic Objectives 6 and 8-1.4.6, 1.6 and 3.7. Σχόλιο / Εισήγηση: Expressions such as “controlling all critical layers” and general references to “foreign platforms” should be replaced with objective requirements relating to: * Effective governance and legal control. * Security and resilience. * Legal enforceability. * Interoperability and portability. * Operational continuity. * Supplier choice and exit capability. Cyprus-only or EU-only hosting requirements should apply only to clearly defined workloads where localisation is required by law or justified by a documented risk assessment. Suggested wording: “Cyprus will maintain effective governance, security, resilience and strategic choice across critical AI capabilities through secure architecture, interoperability, enforceable controls and trusted partnerships.” Αιτιολόγηση σχολίου / Εισήγησης: For a small and open economy, strategic autonomy should mean retaining effective control and choice while using trusted partnerships to obtain scale and specialist capabilities. Origin-based preferences or blanket localisation could increase costs, restrict access to innovation and create uncertainty for international investors without necessarily improving security or resilience. 6. Avoidance of duplicative national certification and registration Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Sections 3.9.6 and 4.3; Annex A. Σχόλιο / Εισήγηση: The EU AI Act should remain the principal regulatory baseline. The Strategy should not introduce mandatory national AI certification, universal registration of AI systems or duplicate documentation requirements unless these are supported by a specific legal basis and a demonstrated need. Compulsory registration should be limited to requirements arising from EU or national law and to proportionate transparency obligations concerning material public-sector AI systems. Cyprus should instead provide voluntary pre-compliance assessments and coordinated regulatory guidance through a one-stop service. Αιτιολόγηση σχολίου / Εισήγησης: Additional national regulatory layers could fragment the EU Single Market, delay product launches and impose disproportionate costs on Cypriot SMEs. Cyprus can create a genuine competitive advantage through clear guidance, rapid regulatory navigation and credible assurance capabilities rather than through duplicative national obligations. 7. Technology-neutral AI procurement and IP protection Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Sections 1.4.3, 3.4 and 4.2; Annex B and Annex C-Government and Public Sector. Σχόλιο / Εισήγηση: The Strategy should provide for the publication of standard AI procurement clauses covering: * Outcome-based specifications. * Total lifecycle cost. * Data and model rights. * Data and model provenance. * Security and auditability. * Model changes and performance drift. * Interoperability and portability. * Incident response and business continuity. * Supplier transition and exit. Procurement terms should clearly distinguish pre-existing supplier intellectual property from project-created intellectual property. Model weights, source code, trade secrets and cybersecurity-sensitive information should be protected through proportionate audit and assurance arrangements. Αιτιολόγηση σχολίου / Εισήγησης: Public procurement will play an important role in shaping Cyprus’s AI market. Clear, transparent and technology-neutral requirements would reduce supplier lock-in, allow Cypriot SMEs and international providers to compete fairly and protect legitimate public oversight. They would also avoid discouraging companies from bringing proprietary technology, investment or research and development activity to Cyprus. 8. One practical pathway for business adoption and investment Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Sections 3.6, 3.8, 4.4 and 5; Annex C-Entrepreneurship and Innovation. Σχόλιο / Εισήγηση: A single, coordinated AI business-adoption and investor pathway should be established, combining: * AI readiness assessment. * Regulatory and compliance triage. * Standard documentation and templates. * Access to regulatory sandboxes. * Vouchers or co-funding. * Access to computing resources. * Connections with universities and research organisations. * Talent and relocation guidance. * Access to public-sector and private-sector pilots. * Commercialisation and export support. Each business or investor should have one accountable case manager, supported by published service standards and response times. The programme should measure productivity gains, exports, investment, skilled employment and successful scaling, not only participation or the number of supported projects. Αιτιολόγηση σχολίου / Εισήγησης: Businesses currently risk having to navigate multiple organisations, funding schemes and regulatory processes independently. A coordinated pathway would reduce adoption barriers for SMEs, improve Cyprus’s investor experience and convert the Strategy’s ecosystem ambition into measurable commercial outcomes." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",dvlosik,"Comments on the Healthcare and Life Sciences pillar Submitted by: Denis Losik, PhD Cardiologist, CMO of eMed Support Systems, Limassol registered company 28.08.2026 COVER NOTE We welcome the Healthcare and Life Sciences pillar, particularly its commitments to data in standards of HL7 FHIR, SNOMED CT, and ICD, as well as its alignment with European Health Data Space principles. We especially support its focus on clinician enablement through accountable AI, intelligent triage and care navigation, and patient-centric service improvement. The three comments below address one question: how the pillar's 2032 ambitions for clinician enablement, intelligent triage and care clinical decision support navigation become a dated, measurable program inside the GeSY within the Strategy's own implementation windows. Declaration of interest: eMed Support Systems is a Cyprus-based AI-native platform that provides advanced analytics and clinical decision support for primary care physicians. The platform integrates with healthcare systems via FHIR/HL7 standards as a read-only layer, avoiding disruption to clinical workflows. By applying clinical guideline logic, the platform identifies patients who need attention and recommends next steps to the clinical team, supported by personalized care and population-level analytics. Annex C, Healthcare and Life Sciences (printed p. 68); Strategic objectives and 2032 target 1) Suggestion/comments: The Healthcare and Life Sciences pillar could be strengthened by defining a near-term implementation pathway that links the Strategy’s objectives for clinician enablement, intelligent triage and care navigation with current priorities of GeSY. Recent analysis of the Cypriot health system identifies several areas where this implementation pathway could deliver early measurable value. These include using clinical data from the State Health Services Organization (SHSO) to support AI-enabled data processing, improve chronic disease management, reduce low-value specialist use, improve referral appropriateness, and provide the Health Insurance Organization with better evidence on population health needs, quality of care, and variation in care pathways. Such an approach could support Personal Doctors in making timely decisions and reducing the costs of chronic disease management. Annex C, Healthcare and Life Sciences (printed p 68) National frameworks and governance 2) Suggestion/comments: Within the NeHA framework, a dedicated regulatory framework could be developed to address key challenges related to data interoperability and exchange processes. This framework should draw on documents and standards already developed under the EHDS and should be aligned with Regulation (EU) 2025/327 on the European Health Data Space in the Healthcare pillar's governance provisions, and align the national framework with Article 53 of that Regulation, which sets out the purposes for which electronic health data may be processed for secondary use. Those purposes include scientific research in the health or care sector, including development and innovation activities for products or services and the training, testing and evaluation of algorithms; and the provision of personalized healthcare. At a later stage, subject to the applicable regulatory and clinical-governance requirements, patient-level decision-support capabilities could be introduced into Personal Doctor workflows to support treatment decisions, investigations, prioritization and indications for specialist referral, while preserving clinical accountability. The sandbox for AI-enabled products should be organized under the NeHA regulation and the data access regulation. National IT infrastructure should be required to ensure the secure and sovereign use of AI with data from the National Health Data Repository. This should include an evaluation of the computing, storage, interoperability, and security resources needed to process health data at the national level. The Task Force should also explore potential technical cooperation with cloud and AI infrastructure providers, such as Nebius, Google Cloud, Oracle, Microsoft Azure, and other relevant market participants. These discussions should focus on infrastructure design, data protection, scalability, cost, and compliance with national and EU requirements for the use of health data. Regulatory classification. Where the pilot advances, at a later stage and subject to clinical-governance requirements, to patient-level decision support in Personal Doctor workflows — treatment decisions, investigations, prioritisation, indications for referral — the Strategy should state that such a system is a medical device under Rule 11 of Annex VIII to Regulation (EU) 2017/745, Class IIa at minimum, requiring a notified body, and that EU AI Act obligations attach on top of that classification rather than in place of it. Annex C, Healthcare and Life Sciences (printed p 69). Implementation, evidence and compliance 3) Suggestion/comments: A practical first step of implementation could be a controlled AI-enabled healthcare platform for a pilot in 2026/2027, consistent with the Strategy’s wider implementation timeline for launching pilots within 6-12 months and scaling successful use cases within 12-24 months. The pilot could focus on a defined high-burden chronic disease population, with cardiovascular disease and diabetes representing a suitable initial use case as one of the largest and most vulnerable patient cohorts. Its purpose would be to test whether routinely available healthcare data from GeSY or SHSO can be used to support: - systematic identification of population health needs and gaps in care; - measurement of guideline-based quality indicators and treatment-target attainment, creating a basis for future performance monitoring and Pay-4-Performance frameworks; - identification of variation in care pathways across providers and patient populations; - assessment of which patient groups can be appropriately managed in primary care and which meet predefined criteria for further investigation or specialist assessment; - more timely access to relevant clinical information for healthcare professionals and system planners. If validated, these capabilities could subsequently be scaled across GeSY to support continuous quality monitoring, stronger primary-care-led chronic disease management, more appropriate use of specialist services, evidence-based resource allocation and the development of performance-based reimbursement models, including Pay-for-Performance. Justification: This addition would provide a practical bridge between the Strategy’s 2032 healthcare ambitions and near-term implementation. It would also align the AI Strategy more closely with current priorities of the Cypriot health system. Recent WHO/European Observatory analysis, developed with the support of HIO, identifies underuse of primary care, overuse of outpatient specialist care, weaknesses in the gatekeeping role of Personal Doctors, variation in referral pathways, and limited availability of population-health and performance data. It highlights the need for stronger health information systems, routine population-health analysis, quality and performance indicators, and AI-native decision-support tools for Personal Doctors. The scale of the utilization challenge is significant. Cyprus residents make approximately 8.7 physician visits per year, including 4.3 outpatient specialist visits, while cardiology alone accounted for approximately 320,000 specialist visits in 2024. Strengthening Personal Doctors and reducing low-value specialist care are therefore directly relevant to both health-system efficiency and quality of care. A phased implementation pathway could be assessed against clear system-level outcomes, including: - higher healthcare workforce productivity, through faster analysis of longitudinal patient information and more efficient identification of relevant patient cohorts; - more appropriate triage and referral, helping Personal Doctors manage suitable patients within primary care while directing higher-risk or complex patients to specialist care; - educed low-value specialist utilization and unnecessary follow-up, particularly in high-burden chronic disease populations; - continuous quality and performance monitoring, enabling HIO to measure treatment-target achievements, guideline adherence and agreed clinical KPIs, and providing a stronger knowledge for performance-based reimbursement, Pay-for-Performance and strategic purchasing; - better chronic disease outcomes and lower downstream utilization, including avoidable specialist care and hospitalizations, to be measured prospectively during pilot and scale-up phases. Defining these outcomes at the outset would support the Strategy’s broader objective of progressing from isolated AI experimentation toward demonstrable public value. Successful healthcare use cases could subsequently be integrated with the planned Secure National Health Data Repository, in alignment with NeHA regulations for the Digital Healthcare Twin, the Virtual AI Patient Orchestrator, and preparations for EHDS infrastructure. This would help ensure that national investments in data and AI translate into measurable improvements in care delivery, quality, and resource utilization." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Antonis Kakas","The document/strategy is good but in many places it reads generic. To avoid this, it could shorten/omit some of the generics giving emphasis to the local Cypriot dimension. I would also like to offer the following (five) specific suggestions. A) Healthcare and Education are missing from the vision part of the document. B) The emphasis on a human-center perspective in the national vision is commendable but this does not resonate in the document. Also, we need to remember that at present the technology does not admit the tools that would help companies to easily develop systems that are transparent and compliant by design. Asking for systems that are proactively designed for ethical fairness requires strong regulation from EU which alas is not forthcoming. The only way to provide some such guarantees is with a strong “human in the loop” element, as the document points out. The strategy could include actions that would support this: Suggestion: Set up instruments to support a continuous consultation with the stakeholders and the general public before, during and after the development of AI systems. C) The national strategy needs to focus on the local reality of the reach of the capabilities of Cyprus. AI has not yet proved that it can provide growth and acceleration of productivity, especially in small and medium scale companies. In Cyprus, we cannot sustain infrastructure for large-scale AI and its applications. Putting the emphasis on the local reality the major related strength of Cyprus is its human resource, particularly within the younger age. AI is an innovation enabler amongst young fresh ideas. Cyprus could set up the aim to create an ever-increasing innovation culture in its society. One suggested action for this the following. Suggestion: The government can expand its scheme for setting up and funding AI (and other types) start-up companies whose founders are young entrepreneurs. The scheme should be aggressive in recruiting interest and setting up the startups, with little interference from the funding department, expect to monitor that the companies are taking mentor advice on the business side of start-up companies. The government funding could be generous so that the 2-3 young founders can work full time to set up their innovation and move to the next level of investment funding. D) Another local advantage is the high-density of medical experts (doctors and others) together researchers in medical informatics and AI. AI can help put together solutions to medical needs that are sensitive to local data that at the same time can form proof of principle solutions for other EU countries. Suggestion: Create an environment to foster working collaborations targeted on specific local healthcare needs. E) Regarding AI & Education the challenge is complex. Nevertheless, it is paramount to have a reform in the educational system where emphasis is put on language and dialectic critical thinking skills. AI is turning Natural Language into a Technology Language. For details of our suggestion on this reform see: https://paideia-news.com/i-texniti-noimosyni-epanaprosdiorizei-tin-ekpaideysi" "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",gac,"ΣΧΟΛΙΟ 5 — AI-enabled Built Environment and Permitting Pilot Αρ. Άρθρου και εδαφίου Annex C — Government and Public Sector / Priority Sectors · 3.11 Measuring Impact and National KPIs Σχόλιο / Εισήγηση Να εξεταστεί η δημιουργία πιλοτικής δράσης “AI-enabled Built Environment and Permitting Pilot”, με αρχική εφαρμογή σε περιορισμένο και ελεγχόμενο πεδίο. Η πιλοτική δράση προτείνεται να αναπτυχθεί σε τρεις συνδεδεμένους άξονες:
α) Planning and Building Permitting,
β) Construction Safety and Inspection, και
γ) Building Lifecycle and Energy Renovation. Η εφαρμογή να πραγματοποιηθεί με ανθρώπινη εποπτεία και να αξιολογηθεί βάσει προκαθορισμένων και μετρήσιμων δεικτών, μετά την καταγραφή των αντίστοιχων υφιστάμενων δεδομένων αναφοράς. Αιτιολόγηση σχολίου / Εισήγησης Ο τομέας του δομημένου περιβάλλοντος προσφέρει κατάλληλο πεδίο πιλοτικής εφαρμογής ΤΝ, επειδή περιλαμβάνει συγκεκριμένες διοικητικές και τεχνικές διαδικασίες, σημαντικό όγκο δεδομένων και δυνατότητα αντικειμενικής μέτρησης των αποτελεσμάτων. Στον άξονα της αδειοδότησης μπορούν να αξιολογηθούν εφαρμογές για τον αρχικό έλεγχο πληρότητας, την επεξεργασία εγγράφων και σχεδίων, την υποστήριξη ελέγχου και τη διαχείριση υποθέσεων. Στον άξονα της κατασκευής και επιθεώρησης μπορούν να εξεταστούν εφαρμογές computer vision, risk analytics, ψηφιακής τεκμηρίωσης, καταγραφής ελαττωμάτων και υποστήριξης θεμάτων ασφάλειας και υγείας. Στον κύκλο ζωής των κτιρίων μπορούν να εξεταστούν εφαρμογές BIM, digital twins, ενεργειακής απόδοσης, predictive maintenance και υποστήριξης προγραμμάτων ανακαίνισης και ενεργειακής αναβάθμισης. Πριν από τον καθορισμό ποσοτικών στόχων πρέπει να καταγραφούν τα υφιστάμενα δεδομένα αναφοράς. Στη συνέχεια μπορούν να καθοριστούν δείκτες όπως ο χρόνος αρχικού ελέγχου πληρότητας, ο συνολικός χρόνος διεκπεραίωσης, ο αριθμός επαναλαμβανόμενων παρατηρήσεων, η ακρίβεια των επισημάνσεων του συστήματος, το ποσοστό ανθρώπινης παράκαμψης εισηγήσεων ΤΝ και ο αριθμός επαγγελματιών και τεχνικών που καταρτίστηκαν. Η πιλοτική εφαρμογή θα επιτρέψει την αξιολόγηση της πραγματικής αποτελεσματικότητας, του κόστους, των κινδύνων και της δυνατότητας επέκτασης πριν από οποιαδήποτε εφαρμογή σε μεγαλύτερη κλίμακα." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",gac,"ΣΧΟΛΙΟ 4 — ΤΝ στην πολεοδομική και οικοδομική αδειοδότηση / ΙΠΠΟΔΑΜΟΣ Αρ. Άρθρου και εδαφίου 3.4.1 Priority Areas for Government Adoption · 3.4.2 Prioritization of AI Use Cases · Annex C — Government and Public Sector Σχόλιο / Εισήγηση Να συμπεριληφθούν η πολεοδομική και οικοδομική αδειοδότηση, ο οικοδομικός έλεγχος και η επιθεώρηση κατασκευών ως συγκεκριμένη οικογένεια περιπτώσεων χρήσης ΤΝ στον δημόσιο τομέα. Προτείνεται η ανάπτυξη εφαρμογών AI-assisted decision support, με αξιοποίηση και διασύνδεση με την υφιστάμενη ψηφιακή υποδομή αδειοδότησης, περιλαμβανομένου του συστήματος ΙΠΠΟΔΑΜΟΣ, χωρίς αντικατάσταση της τελικής ανθρώπινης και διοικητικής κρίσης. Αιτιολόγηση σχολίου / Εισήγησης Η πολεοδομική και οικοδομική αδειοδότηση αποτελεί διαδικασία με μεγάλο όγκο αιτήσεων, σχεδίων, πιστοποιητικών, τεχνικών εκθέσεων και λοιπών εγγράφων, τα οποία αξιολογούνται έναντι καθορισμένων απαιτήσεων. Προσφέρεται συνεπώς για εφαρμογές ΤΝ που μπορούν να υποστηρίζουν τον αρχικό έλεγχο πληρότητας του φακέλου, την εξαγωγή δομημένων δεδομένων από αιτήσεις και τεχνικά έγγραφα, την υποβοήθηση ανάγνωσης σχεδίων, τον εντοπισμό αντιφάσεων μεταξύ υποβαλλόμενων στοιχείων, την επισήμανση πιθανών αποκλίσεων προς περαιτέρω έλεγχο και την ταξινόμηση και δρομολόγηση υποθέσεων. Αντίστοιχες εφαρμογές μπορούν να υποστηρίζουν τον προγραμματισμό επιθεωρήσεων βάσει κινδύνου, την ψηφιακή τεκμηρίωση επιτόπιων ελέγχων και την καταγραφή ελαττωμάτων. Η ΤΝ πρέπει να λειτουργεί υποστηρικτικά και όχι ως μηχανισμός αυτόματης έκδοσης διοικητικών αποφάσεων. Η τελική διοικητική κρίση πρέπει να παραμένει στην αρμόδια αρχή και η επαγγελματική ευθύνη των αδειούχων μελετητών να διατηρείται για τις μελέτες και πιστοποιήσεις που εμπίπτουν στην αρμοδιότητά τους. Η εφαρμογή μπορεί να δημιουργήσει μετρήσιμη δημόσια αξία μέσω της μείωσης του διοικητικού φόρτου, της ταχύτερης επεξεργασίας των αιτήσεων και της βελτίωσης της συνέπειας των αρχικών ελέγχων. Οι δυνατότητες document intelligence, case routing και compliance support που θα αναπτυχθούν μπορούν επιπλέον να επαναχρησιμοποιηθούν σε άλλες διαδικασίες αδειοδότησης του δημόσιου τομέα, σύμφωνα με την αρχή “Build Once, Reuse Everywhere”." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",gac,"ΣΧΟΛΙΟ 3 — FutureAI CY, ΑνΑΔ και επαγγελματικά προσόντα Αρ. Άρθρου και εδαφίου Annex C — Education and Human Capital Development (FutureAI CY) · 3.3.1.7 National AI Skills Observatory Σχόλιο / Εισήγηση Να δημιουργηθεί στο FutureAI CY ειδική διαδρομή μάθησης για τις Κατασκευές και το Δομημένο Περιβάλλον, αξιοποιώντας, όπου είναι θεσμικά κατάλληλο, την υφιστάμενη υποδομή επαγγελματικής κατάρτισης και το Σύστημα Επαγγελματικών Προσόντων της ΑνΑΔ. Να εξεταστεί η αντιστοίχιση και συμπληρωματικότητα των νέων AI micro-credentials με το CyQF/EQF και τα υφιστάμενα επαγγελματικά προσόντα. Παράλληλα, να συμπεριληφθούν τα επαγγελματικά προφίλ των Κατασκευών και του Δομημένου Περιβάλλοντος στον Cyprus AI Skills Gap Atlas του National AI Skills Observatory. Αιτιολόγηση σχολίου / Εισήγησης Ο κατασκευαστικός τομέας αποτελεί κατάλληλο πεδίο εφαρμογής του FutureAI CY λόγω της παρουσίας πολύ μικρών και μικρών επιχειρήσεων, ρυθμιζόμενων επαγγελμάτων και μεγάλου αριθμού διαφορετικών τεχνικών ειδικοτήτων. Η Κύπρος διαθέτει ήδη οργανωμένη υποδομή επαγγελματικής κατάρτισης και αξιολόγησης επαγγελματικών προσόντων μέσω της ΑνΑΔ, με Κέντρα Επαγγελματικής Κατάρτισης, Κέντρα Αξιολόγησης Επαγγελματικών Προσόντων, εκπαιδευτές και αξιολογητές. Η αξιοποίηση της υφιστάμενης υποδομής μπορεί να επιταχύνει τη διάχυση δεξιοτήτων ΤΝ στον κατασκευαστικό τομέα και να περιορίσει την ανάγκη δημιουργίας παράλληλων μηχανισμών. Προτείνεται συνεπώς να εξεταστεί θεσμικά η αντιστοίχιση και συμπληρωματικότητα των νέων micro-credentials με το υφιστάμενο πλαίσιο CyQF/EQF και τα σχετικά επαγγελματικά προσόντα, όπου αυτό είναι εφικτό. Η προσέγγιση αυτή συνάδει με την αρχή “Build Once, Reuse Everywhere” της Στρατηγικής, εφαρμοζόμενη και στην υφιστάμενη υποδομή ανάπτυξης ανθρώπινου κεφαλαίου." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",gac,"ΣΧΟΛΙΟ 2 — Εξειδικευμένες δεξιότητες ΤΝ για τις Κατασκευές Αρ. Άρθρου και εδαφίου 2.5.5 Objective 5: Develop, attract and retain AI-related skills and talent · 3.6.2 Advanced and Sector-Specific Skills Σχόλιο / Εισήγηση Να προστεθούν οι Κατασκευές και το Δομημένο Περιβάλλον στους τομείς για τους οποίους προβλέπεται ανάπτυξη εξειδικευμένων και προσαρμοσμένων δεξιοτήτων ΤΝ. Προτείνεται η ανάπτυξη διακριτών επιπέδων κατάρτισης για:
α) μηχανικούς και άλλους επαγγελματίες του δομημένου περιβάλλοντος, και
β) τεχνικό, εποπτικό και εργατικό προσωπικό του κατασκευαστικού τομέα. Αιτιολόγηση σχολίου / Εισήγησης Η Ενότητα 3.6.2 συνδέει τις απαιτούμενες δεξιότητες ΤΝ με το ειδικό επαγγελματικό και ρυθμιστικό πλαίσιο κάθε τομέα. Οι Κατασκευές αποτελούν έντονα ρυθμιζόμενο επαγγελματικό και τεχνικό περιβάλλον, στο οποίο εμπλέκονται μηχανικοί διαφορετικών κλάδων, μελετητές, εργολήπτες, επιβλέποντες, τεχνικό προσωπικό και δημόσιες αρχές. Η χρήση ΤΝ μπορεί να αφορά BIM και digital twins, ανάλυση σχεδίων και τεχνικών εγγράφων, επιμετρήσεις, εκτίμηση κόστους, προγραμματισμό έργων, υποστήριξη ελέγχου κανονιστικής συμμόρφωσης, διαχείριση συμβάσεων, επιθεωρήσεις, καταγραφή ελαττωμάτων και θέματα ασφάλειας και υγείας. Η κατάρτιση δεν πρέπει να περιορίζεται στη χρήση γενικών εργαλείων ΤΝ. Πρέπει να περιλαμβάνει αξιολόγηση της αξιοπιστίας των αποτελεσμάτων, αναγνώριση εσφαλμένων ή μη τεκμηριωμένων αποτελεσμάτων, προστασία προσωπικών και εμπιστευτικών δεδομένων, επαγγελματική ευθύνη και καθορισμό των περιπτώσεων στις οποίες απαιτείται ανθρώπινη επαλήθευση. Παράλληλα, το εργατικό δυναμικό του κλάδου παρουσιάζει σημαντική διαφοροποίηση ως προς την τυπική εκπαίδευση, τις ψηφιακές δεξιότητες και τη γλωσσική επάρκεια. Απαιτούνται συνεπώς διαφορετικά επίπεδα και μορφές κατάρτισης, προσαρμοσμένα στις πραγματικές ανάγκες κάθε επαγγελματικής ομάδας." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",gac,"ΣΧΟΛΙΟ 1 — Κατασκευές και Δομημένο Περιβάλλον ως Τομέας Προτεραιότητας Αρ. Άρθρου και εδαφίου 1.3 Priority Sectors for Leadership · 2.4.1 Priority Sectors for Leadership Σχόλιο / Εισήγηση Να προστεθεί ο τομέας Κατασκευών και Δομημένου Περιβάλλοντος (Construction and Built Environment) στους Τομείς Προτεραιότητας της Εθνικής Στρατηγικής για την Τεχνητή Νοημοσύνη. Σε περίπτωση που διατηρηθεί ο υφιστάμενος αριθμός των οκτώ Τομέων Προτεραιότητας, προτείνεται, ως εναλλακτική, η ρητή αναγνώριση των Κατασκευών και του Δομημένου Περιβάλλοντος ως αυτοτελούς οριζόντιου τομέα εφαρμογής, με καθορισμένο φορέα συντονισμού, συγκεκριμένες δράσεις και μετρήσιμους δείκτες αποτελέσματος. Αιτιολόγηση σχολίου / Εισήγησης Ο τομέας των Κατασκευών και του Δομημένου Περιβάλλοντος πρέπει να αξιολογηθεί τόσο βάσει της άμεσης οικονομικής του συνεισφοράς όσο και βάσει της εθνικής και συστημικής του σημασίας. Αποτελεί βασική υποδομή για τη στέγαση, τα δημόσια και ιδιωτικά έργα, τις μεταφορές, την ενεργειακή αναβάθμιση του κτιριακού αποθέματος, την τουριστική ανάπτυξη και σημαντικό μέρος των επενδύσεων της χώρας. Παράλληλα, παρουσιάζει εκτεταμένο πεδίο αξιοποίησης ΤΝ σε ολόκληρο τον κύκλο ζωής των έργων. Ενδεικτικές εφαρμογές περιλαμβάνουν BIM και digital twins, ανάλυση τεχνικών εγγράφων και σχεδίων, υποστήριξη ελέγχου κανονιστικής συμμόρφωσης, επιμετρήσεις, εκτίμηση κόστους και χρονοδιαγραμμάτων, computer vision για επιθεωρήσεις, εντοπισμό ελαττωμάτων, predictive maintenance και εφαρμογές ασφάλειας και υγείας. Πρόκειται επίσης για τομέα στον οποίο τα αποτελέσματα εφαρμογών ΤΝ μπορούν να επηρεάζουν τη δομική ασφάλεια, την ποιότητα των κατασκευών, την ασφάλεια και υγεία στην εργασία και την κανονιστική συμμόρφωση. Απαιτείται συνεπώς οργανωμένη υιοθέτηση, με ανθρώπινη εποπτεία, σαφή επαγγελματική ευθύνη και κατάλληλη διακυβέρνηση δεδομένων. Η συμπερίληψη του τομέα θα συνδέσει τη Στρατηγική με έναν βασικό τομέα υλοποίησης της οικονομικής, στεγαστικής, ενεργειακής και αναπτυξιακής πολιτικής της Δημοκρατίας." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Cyprus Innovation Technologies","PUBLIC CONSULTATION SUBMISSION Cyprus National AI Strategy 2032 Consolidated Response Submitted by: Cyprus Innovation Technologies (CyIT) Organisation: Not-for-profit technology think tank and enterprise association Consultation: Cyprus National AI Strategy 2032 Consultation deadline: 31 August 2026. 1. General Position CyIT welcomes the Cyprus National AI Strategy 2032 and its ambition to strengthen Cyprus's competitiveness, public-sector modernisation, innovation capacity and responsible AI adoption. CyIT particularly welcomes the Strategy's emphasis on research and innovation, public-private collaboration, entrepreneurship, skills, testbeds, sectoral adoption and a stronger national technology ecosystem. CyIT is a not-for-profit technology think tank bringing together expertise from technology, academia, finance, banking and professional services. Having evolved from Cyprus Blockchain Technologies into Cyprus Innovation Technologies, CyIT considers AI within the broader development — and increasing convergence — of emerging technologies. The comments below are offered constructively. CyIT considers the Strategy an important foundation and identifies a set of areas where greater strategic coherence, costed delivery detail and connection with the wider technology ecosystem would make it more effective and more implementable. 2. Summary of Recommendations The following fifteen comments are set out in full, with section references, in Section 3 below. ● 1. Anchor the AI Strategy within an updated Digital Strategy. (Section 2.3.2) ● 2. Recognise technology convergence as a horizontal principle. (Sections 2.5, 3.5, 3.7, 3.8) ● 3. Consolidate governance into one coordinating body with clear, costed, time-bound mandates. (Section 3.3.1 and related governance provisions) ● 4. Extend digital readiness and legacy-system planning to systems — not data alone — modernisation, on a phased and costed timeline. (Sections 2.2.1, 2.2.2, 2.2.4, 3.2.5, 3.4.1, 3.7) ● 5. Build a genuine implementation and accountability architecture. (Sections 3.3.1, 3.5, 3.9) ● 6. Publish a costed national AI financing architecture. (Sections 3.3.1, 3.5, 3.7, 3.9, 3.10) ● 7. Recognise established, revenue-generating Cypriot firms as a distinct AI delivery and funding route. (Annex C) ● 8. Name a single approving authority and published criteria for use-case and moonshot selection. (Sections 1.4, 3.3.1, 3.4.2, 3.5) ● 9. Give the innovation ecosystem a structured, continuing implementation role. (Sections 3.3, 3.8, 4) ● 10. Design testbeds to accommodate converged, multi-technology solutions. (Sections 3.8, 3.8.5) ● 11. Extend private-sector support from pilots into funded production implementation. (Section 3.5) ● 12. Add local government as a distinct, resourced delivery layer. (Sections 3.4–3.5 and public-sector implementation generally) ● 13. Broaden AI-literacy programmes to cover emerging-technology convergence. (Section 3.6) ● 14. Extend the KPI framework to measure implementation and ecosystem outcomes. (Section 3.11) ● 15. Build in a periodic horizon-scanning and review mechanism. (Section 3.13) 3. Detailed Comments and Recommendations Comment 1 — Anchor the AI Strategy within an updated Digital Strategy Relevant section(s): Section 2.3.2 (Alignment with Digital and Data Strategies); cross-cutting Issue: The Strategy is intended to guide Cyprus to 2032 but continues to rely partly on the National Digital Strategy 2020–2025. AI depends on wider digital foundations — data, connectivity, cybersecurity, digital identity, cloud/compute infrastructure, interoperability and digital public services — and increasingly interacts with blockchain/DLT, IoT, digital twins, robotics and automation. Recommendation: Update the overarching Digital Strategy for the period ahead and position the National AI Strategy clearly as a major implementation pillar within it, so AI and other emerging technologies develop within one coherent architecture rather than through separate technology silos. Comment 2 — Recognise technology convergence as a horizontal principle Relevant section(s): Sections 2.5, 3.5, 3.7, 3.8; Annexes C–D Issue: Although the Strategy references digital twins, robotics, autonomous systems and cybersecurity, it treats AI predominantly as a standalone technology. Cyprus already has capability and market experience in blockchain, fintech and distributed technologies that should be leveraged as AI develops, rather than treated as unrelated prior initiatives. Recommendation: Introduce technology convergence as a horizontal principle. Keep national programmes and use cases technology-neutral, but explicitly consider AI–blockchain/DLT convergence (trusted data and provenance, digital identity, tokenisation, smart contracts, supply chains, machine-to-machine transactions) where it improves outcomes. Comment 3 — Consolidate governance into one coordinating body with clear, time-bound mandates Relevant section(s): Section 3.3.1 and related governance provisions (pp.21–27); Sections 3.5, 3.9 (pp.33, 43); Annex A Issue: The Strategy creates at least ten standing bodies — the National AI Authority, Interministerial AI Council, National AI Taskforce, National AI Infrastructure Committee/Council, National Ethics and Values Committee, National AI Misinformation and Security Council, National AI Skills Observatory, Government Innovation Hub, AI Industrial Centre of Excellence and Cyprus AI Security and Certification Authority — plus AI Officers/Ambassadors and two designated resources in every ministry. No decision-rights map shows where one body's mandate ends and another's begins: the infrastructure body is named inconsistently as both ""Council"" and ""Committee,"" and Annex A refers to a ""National AI Council"" that is absent from the governance chapter itself. Neither the Deputy Ministry of Research, Innovation and Digital Policy (named as current implementation owner, p.8) nor the Department of Information Technology Services (not otherwise mentioned in the draft) is given a boundary against the new bodies. No body carries a term, review point or wind-down provision, even though the Strategy itself decommissions underperforming systems and programmes elsewhere (Annex B, Stage 5; §3.11.4). Recommendation: Consolidate to a single coordinating authority, with specialist functions (ethics, misinformation/security, infrastructure, skills) run as advisory panels sharing one secretariat rather than as standing bodies. Define that authority explicitly against the Deputy Ministry and DITS, stating what it does that they do not. Choose a lifespan: either a fixed term (five years is a reasonable default) with named successor arrangements for each function, or a broader ""Modernisation and Innovation"" mandate that outlasts the current AI technology cycle. Where a function can be carried by an existing institution, it should be, rather than creating a new standing body for it. Comment 4 — Extend digital readiness and legacy-system planning to systems — not data alone — modernisation, on a phased and costed timeline Relevant section(s): Sections 2.2.1, 2.2.2, 2.2.4, 3.2.5, 3.4.1, 3.7 (pp.10–11, 20–21) Issue: The Strategy correctly diagnoses fragmented, low-interoperability public-sector data and computing infrastructure, and acknowledges that ""digital maturity varies across ministries and agencies"" (§2.2.4), with some organisations lacking the capability to ""identify, procure, and manage AI systems."" However, the stated prerequisite covers data modernisation only (§2.2.2); legacy systems, application modernisation and technical debt are not addressed, even though fragmented data is itself a symptom of an unintegrated application estate. The national data layer and National Intelligent Digital API Fabric (§3.2.5) — though called a prerequisite for the flagship portals — carry no owner, date or budget, and §3.4.1 commits only to ""work towards"" AI-first procurement principles ""by 2032"" with no interim milestones. Recommendation: Widen the stated prerequisite from data modernisation to systems-and-data modernisation, and assess the application estate alongside the data. Give each modernisation instrument, including the data layer and API Fabric, a named owner, budget and completion date. Require a published digital-readiness assessment for each ministry before AI systems are integrated into its legacy estate, and express at least one modernisation milestone as a gate on the adoption target so sequencing is visible and testable, rather than relying on the 2032 horizon alone. Comment 5 — Build a genuine implementation and accountability architecture Relevant section(s): Sections 3.3.1, 3.5, 3.9 Issue: The Strategy sets out governance bodies, timelines and KPIs, but this falls short of delivery discipline. It does not yet translate the 2032 vision into programme-by-programme ownership, annual milestones, inter-programme dependencies, decision rights, a benefits-realisation methodology, or stated consequences when a programme falls behind. Without these elements, the 16 flagship programmes and 6 moonshots referenced in §3.5 risk remaining a strategic framework rather than a delivery programme. Recommendation: Require, for each moonshot programme once selected, a one-page delivery charter naming an accountable senior owner, annual (not only 2032) milestones, a dependency map against other programmes and infrastructure, a benefits-realisation plan with measurable indicators, and defined remedies for slippage. Review progress against these implementation commitments, not only against final 2032 targets. Comment 6 — Publish a costed national AI financing architecture Relevant section(s): Sections 3.3.1, 3.5, 3.7, 3.9, 3.10 Issue: The Strategy commits repeatedly to expenditure without figures. Section 3.3.1 states only that ""budget allocations will be aligned with the strategic performance goals agreed between the Ministry of Finance and the Deputy Ministry,"" with no per-programme costing; Section 3.10 promises ""multi-year investment with clear ROI tracking"" without numbers; and Section 3.7 commits to a National AI Infrastructure described as a ""strategic national asset"" with no costed funding plan attached. This makes it difficult to assess whether the Strategy's ambitions, including its 75% adoption target, are financially achievable. Recommendation: Publish an indicative national AI financing architecture for 2026–2032, itemising expected investment and the expected return or outcome metric by source — government funding, EU funding, private investment, R&D support, SME adoption subsidies, compute credits, procurement expenditure and venture/scale-up capital — and cross-reference it explicitly to the 75% adoption target so funding and ambition can be assessed together. Attach indicative cost ranges, funding sources, milestones and review dates to each major commitment, particularly the National AI Infrastructure. Comment 7 — Recognise established, revenue-generating Cypriot firms as a distinct AI delivery and funding route Relevant section(s): Annex C (pp.60–87, including p.73, p.86); Sections 3.3.1 (p.26), 3.3.2 (p.27), 5 (p.50) Issue: The Strategy builds two funding and delivery routes well — public-sector adoption (institutional AI strategies, delivery bodies, dated procurements) and the startup/spin-off pipeline (incubation, venture co-investment, university commercialisation). Established Cypriot firms past the startup stage but below corporate scale — already profitable and already holding sector knowledge in shipping, law, hospitality or finance — are the most likely source of exportable Cypriot AI products, yet they are named only once, in passing (""targeting the development of existing SMEs and MEs,"" p.50). The nearest instrument, the AI Sovereign Investment Matching Fund, is shaped for equity rounds (25% pre-seed/seed, 75% Series A/B; conditions written for ""any startup receiving government support,"" p.86) and does not fit a profitable firm that is not raising a round. Recommendation: Name established AI-building/selling firms as a distinct route alongside the public-sector and startup routes, with its own logic from product development through capital to first customer and export. Clarify what ""ME"" means (align to the EU small mid-cap definition if intended) and ensure profitable firms not raising equity can access support. Prioritise funding for defined products with an identified buyer and a credible revenue path over studies and assessments, and consider models (e.g. the Israel Innovation Authority) where support is repaid from resulting revenue. Measure products reaching market, revenue and export revenue in Annex F, and give the AI Industrial Centre of Excellence a clear establishment date, budget and access criteria. Comment 8 — Name a single approving authority and published criteria for use-case and moonshot selection Relevant section(s): Sections 1.4, 3.3.1, 3.4.2, 3.5; Annexes B–C (Figures 5–12) Issue: Annex C lists ""Recommended Use Cases, Moonshots and KPIs to be considered"" for each of the eight priority sectors without making clear whether these are illustrative or committed. Section 3.5 states 16 flagship programmes will be assessed and narrowed to 6 moonshots by the National AI Authority ""following stakeholder consultation"" — without defining which stakeholders, what criteria, what weighting, or a decision date. At least three parallel, unreconciled approval pathways exist: the National AI Authority's 16-to-6 selection; the Government Innovation Hub's separate validation gate (§1.4.3); and ministries' independent authority to identify and prioritise their own use cases (§3.3.1) through mandatory Applied AI Strategies. Annex B's control gates add further checkpoints without specifying gate criteria or committee composition. The Strategy itself warns against ""AI theatre"" — ""many experiments, little impact"" (§1.4) — the likely outcome of naming aspirational use cases without a single approving authority. Recommendation: Name a single final approving authority for moonshot selection, publish selection criteria and their weighting, and fix a decision date for the 16-to-6 narrowing. Amend Annex B to name the approving body and pass/fail criteria for each control gate. Require ministry-level use cases selected outside the moonshot list to pass through the same Government Innovation Hub validation gate. Require multidisciplinary validation (public bodies, industry, academia, ecosystem) before major investment is committed, and review the use-case portfolio periodically. Comment 9 — Give the innovation ecosystem a structured, continuing implementation role Relevant section(s): Sections 3.3, 3.8, 4 Issue: The Strategy's emphasis on government–industry–academia collaboration is welcome, but effective implementation requires continuing engagement beyond consultation and strategy-development. Cyprus already has technology associations, not-for-profit organisations, innovation communities, professional bodies, startups and enterprises able to contribute market knowledge, identify use cases and support technology literacy. Recommendation: Provide a structured mechanism for continuing ecosystem participation during implementation, using existing ecosystem organisations rather than creating new public structures for functions they can already perform. CyIT would be willing to contribute within its areas of expertise and through its multidisciplinary membership. Comment 10 — Design testbeds to accommodate converged, multi-technology solutions Relevant section(s): Sections 3.8, 3.8.5; Annex D Issue: CyIT strongly supports the proposed testbeds, sandboxes and experimentation environments, but real-world innovation increasingly involves systems combining AI with other technologies; environments designed too narrowly around AI alone may limit experimentation and commercialisation. Recommendation: Design national testbeds to accommodate integrated solutions combining AI with blockchain/DLT, IoT, digital identity, digital twins, robotics, autonomous systems and cybersecurity where appropriate. Encourage a ""pilot before scale"" approach with measurable outcomes, and share non-confidential lessons from successful and unsuccessful pilots across the ecosystem. Comment 11 — Extend private-sector support from pilots into funded production implementation Relevant section(s): Section 3.5 (Supporting SMEs; NAICF Comply / AdoptNAICF) Issue: The private-sector support architecture is built almost entirely around SME adoption assistance, and specifically around preparatory stages: AdoptNAICF's subsidy is gated behind NAICF Comply's baseline AI Act governance requirement, and industry adoption is described as ""not mandatory... however, highly recommended."" This funds compliance groundwork, studies, assessments and pilots, without a stated mechanism for funding the point at which a company integrates a system into production and runs it. The adoption challenge is also not limited to SMEs — larger Cyprus enterprises face similar implementation, integration, skills and infrastructure barriers, with no distinct support track outside the SME band. Recommendation: Restructure AdoptNAICF, or add a parallel instrument, to fund the ongoing running and integration costs of production AI implementations, not only studies and pilots. Introduce a distinct implementation-support track for enterprises outside the SME band, naming specific enablers — production-grade sandbox access, technical integration assistance, a delivery-support function — separate from NAICF Comply's compliance guidance. Comment 12 — Add local government as a distinct, resourced delivery layer Relevant section(s): Sections 3.4–3.5 and public-sector implementation generally Issue: The Strategy focuses on central government and the eight priority economic sectors. Municipalities, however, deliver many services citizens experience directly — permits, waste management, planning, local infrastructure, traffic, environmental management and local-language services — and are not treated as a distinct delivery stream. Recommendation: Add local government as a named, distinct delivery stream within the public-sector programme, with its own use cases, resourcing pathway and digital-readiness assessment — paralleling the ministry-level readiness work in Comment 4 — rather than addressing municipalities only implicitly through national programmes. Comment 13 — Broaden AI-literacy programmes to cover emerging-technology convergence Relevant section(s): Section 3.6 (Talent, Skills and Workforce Transformation) Issue: CyIT strongly supports the emphasis on AI literacy and workforce transformation. However, executives, professionals, public officials and citizens increasingly need to understand AI within the wider technology environment — data, cybersecurity, cloud infrastructure, digital identity — with which it interacts. Recommendation: Add an emerging-technologies and technology-convergence dimension to AI-literacy programmes, particularly for policymakers, business leaders, professionals, SMEs and public-sector decision-makers, to support more informed technology selection and reduce both under-adoption and hype-driven adoption. Comment 14 — Extend the KPI framework to measure implementation and ecosystem outcomes Relevant section(s): Section 3.11; Annex F Issue: The Strategy contains extensive KPIs, but the ultimate test of a national technology strategy is successful implementation and a sustainable innovation ecosystem — whether pilots reach production, research is commercialised, SMEs and startups gain access to infrastructure and markets, and Cyprus develops internationally scalable solutions. Recommendation: Add measurable implementation and ecosystem indicators to the KPI framework alongside adoption metrics: pilot scale-up, industry–academia collaboration, SME/startup participation, private investment mobilised, commercialisation outcomes and internationally scalable solutions. Comment 15 — Build in a periodic horizon-scanning and review mechanism Relevant section(s): Section 3.13 (Risk Management, Resilience and Adaptation); cross-cutting Issue: A Strategy extending to 2032 must recognise that technologies, deployment models and significant use cases will emerge that cannot be fully predicted in 2026 — the pace of change in generative and agentic AI already demonstrates this. Recommendation: Include a periodic horizon-scanning and review mechanism covering material developments in AI and other emerging technologies (including their convergence), new use cases, risks, infrastructure requirements and international developments, drawing on government, academia, industry and the wider ecosystem, capable of informing adjustments to priorities and investment during implementation. 4. Sector-Specific Observations Two further, narrower points from the underlying review drafts are recorded here for completeness, as they concern specific sector proposals rather than cross-cutting Strategy design. Comment 16 — Broaden the Financial Services / FinTech use-case programme Relevant section(s): Financial Services and Financial Technology priority sector Issue: The existing focus on AML, fraud detection, intelligent insurance, AI-augmented advisory and regulatory reporting is useful, but understates how quickly the sector is converging with tokenised assets, blockchain-based market infrastructure, digital identity, programmable payments, RegTech/SupTech and agentic financial services — an area where Cyprus already has deep professional, regulatory and market capability. Recommendation: Expand the financial-services use-case programme into an AI, FinTech and Digital Finance Innovation Track capable of considering convergent technology models. Comment 17 — Reconsider the role of blockchain in AIREG as part of a wider innovation programme Relevant section(s): Legal Services – AIREG Issue: CyIT welcomes blockchain's appearance in the Strategy through the AIREG proposal, but no technology should be selected solely because it appears innovative, and blockchain should not be confined to a single registry use case without a feasibility assessment against alternative architectures. Recommendation: Reframe AIREG as one candidate use case within a broader, technology-neutral Trusted AI and Digital Provenance Programme, subject to a multidisciplinary feasibility and pilot process considering interoperability, data/metadata requirements, privacy, governance, digital identity, cybersecurity and evidentiary requirements — so that lessons generated can support other sectors. 5. Standards and Regulatory Coherence CyIT recognises that implementation of the National AI Strategy will take place within the framework of the EU Artificial Intelligence Act, the national legislation being developed for its implementation, and the wider European regulatory environment. CyIT also recognises the important role of standards and of the Cyprus Organisation for Standardisation (CYS) in supporting interoperability, security, trustworthy AI and market access. These matters should be appropriately reflected in the final Strategy; CyIT does not consider it necessary in this submission to duplicate the detailed legal or standardisation analysis more appropriately addressed by competent institutions and specialist stakeholders. From CyIT's perspective, the principal objective is to ensure that the regulatory and standards environment provides certainty and trust while remaining capable of supporting responsible experimentation, innovation, commercialisation and scaling. 6. Conclusion Cyprus's National AI Strategy 2032 sets an ambitious and largely well-founded direction, but its biggest risks are structural: it stacks new institutions, funding commitments and use-case selections without a single coordinating authority, a costed budget, or a clear decision-rights map, and it leans on the National Digital Strategy 2020–2025 rather than an updated digital foundation. Fixing these — one accountable governance body, a published financing architecture, and a clearer path from proposed use case to funded delivery — would do more for credibility than any single new programme. Beyond that, implementation readiness needs more attention than the draft currently gives it: legacy-system and digital-maturity gaps across ministries aren't sequenced or costed, the moonshot/use-case approval process runs through at least three overlapping pathways, and established Cypriot firms sit in a funding gap between the startup and public-sector tracks the Strategy does address. Finally, the Strategy would be strengthened by treating AI as one part of a wider, converging technology landscape — recognising local government, the private sector beyond pilots, and the broader innovation ecosystem as ongoing implementation partners, broadening technology literacy accordingly, and building in periodic review so the Strategy can adapt as the technology and its use cases evolve through 2032." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",VasosVassiliou,"1. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Section 3.8.1 and Annex D, Focus Area 5 (Next-Generation Wireless Telecommunications, printed p. 89); Section 2.2.1 (printed p. 9); Section 3.8.5 (National Testbeds, printed p. 41). Σχόλιο / Εισήγηση: Focus Area 5 should be given the same institutional treatment as the other focus areas: a named delivery mechanism, an associated testbed or experimentation facility, and at least one indicator in the Annex F framework. Specifically, add an advanced connectivity and network-AI testbed to the national testbed programme in §3.8.5, and state which body is responsible for the focus area. Αιτιολόγηση σχολίου / Εισήγησης: The six focus areas are presented as equivalent, but their institutional backing is not. Autonomous Systems is tied to a physical test park and to the maritime pillar; Healthcare to the National Health Data Repository; Security, Defence and Space to a dedicated Centre of Excellence. Next-Generation Wireless has three bullet points, no host, no facility and no indicator, and telecommunications does not appear among the eight priority sectors. Section 2.2.1 treats connectivity as an achieved condition (95.5% FTTH, 100% 5G coverage), which explains the omission but does not justify it: the Strategy elsewhere requires real-time AI services, edge deployment and national interoperability, all of which are network capabilities that do not exist today and will not arrive without directed investment. A research priority with no delivery mechanism attached will not attract funding and will not be measured." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",VasosVassiliou,"1. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο Section 3.8.1 and Annex D, Focus Area 5 (Next-Generation Wireless Telecommunications, printed p. 89); Section 2.2.1 (printed p. 9); Section 3.8.5 (National Testbeds, printed p. 41). Σχόλιο / Εισήγηση Focus Area 5 should be given the same institutional treatment as the other focus areas: a named delivery mechanism, an associated testbed or experimentation facility, and at least one indicator in the Annex F framework. Specifically, add an advanced connectivity and network-AI testbed to the national testbed programme in §3.8.5, and state which body is responsible for the focus area. Αιτιολόγηση σχολίου / Εισήγησης The six focus areas are presented as equivalent, but their institutional backing is not. Autonomous Systems is tied to a physical test park and to the maritime pillar; Healthcare to the National Health Data Repository; Security, Defence and Space to a dedicated Centre of Excellence. Next-Generation Wireless has three bullet points, no host, no facility and no indicator, and telecommunications does not appear among the eight priority sectors. Section 2.2.1 treats connectivity as an achieved condition (95.5% FTTH, 100% 5G coverage), which explains the omission but does not justify it: the Strategy elsewhere requires real-time AI services, edge deployment and national interoperability, all of which are network capabilities that do not exist today and will not arrive without directed investment. A research priority with no delivery mechanism attached will not attract funding and will not be measured. 2. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο Section 1.4.3 (printed p. 4); Section 3.3.1, Innovation and Development Bodies (printed p. 22); Section 3.3.1, National AI Industrial Centre of Excellence (printed p. 26); Section 3.4 (printed p. 31); Annex C, Government and Public Sector (printed p. 63); Section 2.2.3 (printed p. 10). Σχόλιο / Εισήγηση The Strategy should state the legal form and ownership model of each proposed Centre of Excellence, and should state the intended relationship between the new national Centres and the seven Centres of Excellence already operating in Cyprus, i.e whether the new Centres are to be hosted by, built upon, or established independently of them. A single consistent name should be adopted for each Centre throughout the document. Αιτιολόγηση σχολίου / Εισήγησης The Industrial Centre of Excellence is described in four incompatible ways: as an entity ""dedicated to the private sector"" (p. 4); as a body within the national governance structure (p. 22); as an entity that ""reports to the National AI Authority"" (p. 31); and as ""a publicly supported private entity"" (p. 63). These imply different procurement routes, different state aid treatment, different IP arrangements and different accountability lines. The question cannot be deferred to implementation, because the choice determines who may host or participate before any host is selected. Separately, §2.2.3 records that Cyprus already has seven Centres of Excellence, and no subsequent text connects them to the new bodies. Establishing national Centres alongside existing ones without stating the relationship risks precisely the duplication of public investment that §3.7 identifies as a structural weakness. The Centre is also named five different ways across the document, which should be corrected in the final text. 3. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο Section 3.3.1, National AI Industrial Centre of Excellence (printed p. 26); Annex C, Financial Services (printed p. 66); Section 3.9.6 (printed p. 43); Section 4.3, NAICF (printed p. 49); Annex A, EU AI Act (printed p. 53). Σχόλιο / Εισήγηση The Strategy should separate the development and assurance functions currently assigned to the Industrial Centre of Excellence. A body providing ""development and engineering"" across priority sectors should not also validate models against EU AI Act requirements before commercial deployment. The Strategy should further clarify the division of responsibility between the Centre, NAICF, the national certification registry, the ""Cyprus AI Security & Certification Authority"" named at p. 43, and the Competent Authorities already designated under the AI Act. Αιτιολόγηση σχολίου / Εισήγησης Page 26 tasks the Centre with resources, development and engineering; page 66 tasks the same Centre with validating models against EU AI Act requirements before commercial deployment and with producing compliance blueprints. An organisation cannot credibly assess systems it has helped build, and market participants that compete with the Centre's engineering work will not accept its conformity judgements. The confusion is compounded by the number of assurance actors: NAICF, the registry, the Certification Authority (which appears once and does not appear in the governance structure at §3.3.) and the Communications Commissioner and Data Protection Commissioner, who hold the statutory role under the Act. 4. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο Section 3.3.1, National AI Cybersecurity Centre of Excellence (printed p. 26); Section 5, item 3 (printed p. 51); Section 3.3.1.6, National AI Misinformation and Security Council (printed p. 24); Section 4.2.1 (printed p. 49). Σχόλιο / Εισήγηση The two descriptions of the Cybersecurity Centre of Excellence should be reconciled, and the boundary between the Centre and the National AI Misinformation and Security Council should be drawn explicitly. The final text should also state on what terms international partners participate, in particular the ownership of intellectual property arising from jointly developed work and the treatment of results produced by Cypriot research institutions. Αιτιολόγηση σχολίου / Εισήγησης Page 26 describes a centre bringing together industry, academia and public institutions around frontier security research and practical standards. Page 51 describes a body operating ""in partnership with leading global players"" and developing ""AI cyberwarfare professionals."" These are different institutions with different governance requirements, different security classifications and different funding models. The misinformation and disinformation remit at p. 51 also duplicates the mandate given to the Misinformation and Security Council at p. 24. On the partnership question, an anchor-partner model in which an international participant leads the technical work and domestic institutions supply personnel produces a centre that is located in Cyprus without building national capability(the outcome Objective 8 is intended to prevent!). Stating the IP and knowledge-transfer terms in the Strategy is what makes Objective 8 operative rather than aspirational. 5. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο Section 1.2 (printed p. 3); Section 1.4.3, ""AI Centres of Excellence"" (printed p. 4); Section 1.3 (printed p. 3); Section 3.3.1 (printed pp. 22, 26); Section 5, item 3 (printed p. 51); Annex C, Maritime (printed p. 83). Σχόλιο / Εισήγηση Reconcile the plural ""AI Centres of Excellence dedicated to the private sector"" at §1.4.3 with the two horizontal Centres actually defined at §3.3.1. Either state that sector-specific Centres will be established and identify which sectors, or amend §1.4.3 to describe a single horizontal Industrial Centre and drop the ""dedicated to the private sector"" characterisation, which does not match a body that also reports to the National AI Authority and supports ministries directly. The plural framing is unsupported. §1.2 (p. 3) describes CoEs as ""industry-oriented""; §1.4.3 (p. 4) describes them as ""dedicated to the private sector to accelerate use case adoption."" But the two actually defined are horizontal layers, not sector bodies, and the mapping onto the eight sectors is incoherent: The Industrial CoE is assigned to government (p. 63), financial services (p. 66), tourism (pp. 34, 73), legal services (p. 74), and at p. 51 to ""GovTech, FinTech, ShipTech, tourism, and HealthTech."" That is one body for at least six of the eight sectors. The Cybersecurity CoE maps to no priority sector at all. It corresponds to Annex D Focus Area 4 (Security, Defence and Space), which is a research focus area and not a priority sector. Shipping and Maritime, the sector where Cyprus has its strongest global position, gets only a conditional: it ""may be supported by a Centre of Excellence"" (p. 83). Education, and Entrepreneurship and Innovation, get no CoE reference. Αιτιολόγηση σχολίου / Εισήγησης As drafted, one Industrial Centre of Excellence is expected to provide engineering, adoption support, governance guidance, compliance blueprints and sandbox validation across at least six of the eight priority sectors, each with distinct regulators, data regimes, professional bodies and technical requirements. No single organisation can hold credible domain depth across shipping, healthcare, legal services, tourism, finance and public administration simultaneously, and a body that attempts it will deliver generic advisory output — which is the ""AI theatre"" outcome the Strategy identifies as an execution risk at §1.4. Conversely, the Cybersecurity Centre is mapped to no priority sector, so the two Centres between them are simultaneously over-extended and unaligned to the sector structure the Strategy is organised around. Maritime is the clearest case: it is the sector with the strongest existing international position and the only one where a Centre is proposed conditionally. 6. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο Section 3.3.1, National AI Cybersecurity Centre of Excellence (printed p. 26); Section 1.1, Fundamental Principles (printed p. 2); Section 3.3.1.5 (printed p. 24); Section 3.9 and 3.13.3 (printed pp. 43, 46); Annex D, Focus Areas 4 and 6 (printed pp. 89–90); Section 5, item 3 (printed p. 51). Σχόλιο / Εισήγηση Rename National AI Cybersecurity Centre of Excellence to “National Centre of Excellence for Trustworthy and Secure AI”, and extend its mandate beyond cybersecurity to cover the full technical assurance of AI systems: adversarial robustness, model evaluation and benchmarking, red-teaming, bias and fairness auditing, explainability methods, privacy-preserving learning, and the development of national testing methodologies for high-risk systems under the EU AI Act. Cybersecurity remains within the mandate; it becomes one dimension of trustworthiness rather than the whole of it. Αιτιολόγηση σχολίου / Εισήγησης The Fundamental Principles at §1.1 commit Cyprus to security and resilience, fairness and non-discrimination, transparency and human oversight. Of these, only security is assigned to a body with technical capability. The National Ethics and Values Committee is advisory and described in a single sentence; NAICF addresses compliance and certification, which is a documentation function rather than a testing one. No body in the Strategy is responsible for determining whether a deployed system is actually robust, actually unbiased, or actually explainable. That is a technical question requiring laboratory capability, not an ethical or administrative one, and without it the AI Act conformity assessments the Strategy anticipates will rest on vendor self-declaration. Extending the Centre's scope is also methodologically coherent: adversarial robustness testing, model evaluation, red-teaming and fairness auditing share techniques, tooling and expertise. Establishing a Centre that covers only the security subset and leaving the remainder unassigned would fragment a single technical discipline across bodies that do not exist. The narrower title also mismatches the mandate already given at p. 26, which includes securing AI systems themselves, which is an activity that is inseparable from evaluating them. 7. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο Section 2.2.2, final paragraph (printed p. 10); Section 1.5 (printed p. 6); Section 3.2.2 (printed p. 20); Section 5, items 1 and 6 (printed pp. 50, 52); Annex B, Control Gates 1 and 2 (printed pp. 58–59). Σχόλιο / Εισήγηση The characterisation of the National Data Policy and the National Data Governance Framework as a prerequisite rather than a parallel activity is correct and should be retained. It should also be made operative: state a target publication date for both instruments, sequence the implementation timeline at §1.5 and the immediate steps at §5 against that date, and add an explicit data-readiness condition at Annex B Control Gate 1 or 2, so that a use case cannot pass the gate without demonstrating that the data it depends on is governed, documented and lawfully available under the national framework. Αιτιολόγηση σχολίου / Εισήγησης Section 2.2.2 correctly identifies the sequencing that most national AI programmes get wrong. As drafted, however, the Strategy states the dependency in Chapter 2 and does not observe it thereafter. No delivery date is given for either instrument, while §1.5 places infrastructure deployment and pilot launches at 6 to 12 months and §5 commits to launching procurements for six transformational solutions within eight months. If the data framework is genuinely a prerequisite, then those milestones are conditional on a deliverable with no date, and the timeline cannot be relied upon. If it is not a prerequisite, the paragraph at §2.2.2 should be amended. Attaching the requirement to a control gate is the mechanism that makes the stated principle binding, since it is at the gate that a project either has governed data or does not. 8. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο Section 3.7 and 3.7.2 (printed pp. 38–39); Section 3.3.1.4, National AI Infrastructure Committee (printed p. 24). Σχόλιο / Εισήγηση The Strategy should specify the composition of the National AI Infrastructure Committee, including representation from universities and research organisations, and should clarify the intended treatment of existing publicly funded institutional research computing, whether it is to be consolidated, federated, or left in place with coordinated access. My opinion is that any infrastructure already in place should remain so, and there should be coordinated access to all, if needed and possible. The HPC at UCy has a research and Educational purpose, which cannot be ignored and cancelled. The body is called a Council at §3.3.1 and a Committee at §3.3.1.4; one term should be used. Αιτιολόγηση σχολίου / Εισήγησης Section 3.7.2 states that the National AI Infrastructure should not belong to ""any individual ministry, university, research organisation, or company,"" and §3.7 opens by characterising existing institutional resources as fragmented and duplicative. Read together, these imply a consolidation of resources that were competitively won and are currently committed to funded research programmes with contractual obligations to European funders. Consolidation and federation are both defensible, but they have very different consequences for existing projects, and the Strategy does not say which is intended. Section 3.7.2 also assigns oversight to ""an appropriate governance framework representing government, academia, research organisations, and industry,"" while §3.3.1.4 defines the Committee's functions without defining its membership. Since that body will set annual compute priorities, its composition determines whether the stated representation is real. 9. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο Section 5, item 2 (printed p. 50); Section 4.4, Incentive Mechanisms and AI ERC Bridge (printed p. 50); Annex C, Legal Services (printed p. 75); Annex F (printed p. 93). Σχόλιο / Εισήγηση The National AI Research Fund and the AI ERC Bridge should be given an administering body, an indicative multi-annual allocation and a first-call date. The Strategy should state the role of the Research and Innovation Foundation in the national AI research portfolio. Αιτιολόγηση σχολίου / Εισήγησης The National AI Research Fund is stated as a single line with an ambition: placing Cyprus among the top fifteen European nations for AI research excellence. However, there is no administering body, no allocation and no timeline. The AI ERC Bridge is a sub-bullet. Neither appears in the Annex F measurement framework. The Research and Innovation Foundation, which currently administers competitive national research funding, is named once in 101 pages, in the Legal Services annex, as a co-funder of compliance auditing rather than of research. Six research focus areas and a research excellence target cannot be delivered by instruments that have no owner, and the omission of the existing national funding agency from a national research strategy will be read either as an oversight or as a signal of institutional change. Either reading warrants clarification in the final text. 10. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο Section 1.4.2 and 1.4.10 (printed pp. 4, 6); Section 3.2.1 (printed p. 20); Annex A, Digital, Cybersecurity and Data Frameworks (printed p. 54); Annex C, Healthcare (printed p. 68) and Maritime (printed p. 83). Σχόλιο / Εισήγηση Add the Data Governance Act, the Data Act, the Open Data Directive and the European Health Data Space Regulation to the instruments listed at §1.4.10, and convert the single bullet at §3.2.1 into a stated participation plan: which Common European Data Spaces Cyprus intends to join, in what order, which national body acts as counterpart in each, whether Cyprus will designate data intermediation and data altruism organisations under the DGA and which authority will register and supervise them, and how the national Trusted Maritime Data Space and the GHS health sandbox will connect to their European counterparts rather than operate as isolated national constructs. Αιτιολόγηση σχολίου / Εισήγησης The Strategy positions Cyprus as a trusted jurisdiction and a bridge between the EU and neighbouring regions, and Objective 6 commits to interoperable data foundations. Neither claim is supported by the current text, which refers to European data spaces only in general terms and to the EHDS only as a source of principles. The Data Governance Act, which is the legal instrument that makes cross-border data sharing operable and which imposes designation obligations on Member States, is not mentioned anywhere in the document. Sectoral data spaces built to national specification and later retrofitted to European ones cost substantially more than spaces built to the European reference architecture from the outset, and the Strategy elsewhere identifies avoidance of retrofitting as a design principle under ""data by design."" Naming the instruments and the intended accession sequence is a drafting change with no cost that materially strengthens the interoperability commitment. 11. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο Section 1.4.2, fifth bullet (printed p. 4); Section 1.4.6 (printed p. 5); Section 3.2.1 (printed p. 20); Section 3.2.2 (printed p. 20); Section 3.7 and 3.7.2 (printed pp. 38–39). Σχόλιο / Εισήγηση Separate the compute commitment from the data commitment. The fifth bullet of §1.4.2 should be limited to data infrastructure — secure processing environments, sectoral data spaces, and the API fabric — with compute capacity moved to §1.4.6, where it is already addressed. The Strategy should also resolve whether the national data architecture is federated (§3.2.1) or consolidated onto a shared platform (§1.4.2, §3.7.2), since these are incompatible. Αιτιολόγηση σχολίου / Εισήγησης Data and compute are governed by different legal regimes and require different institutional arrangements. Compute governance concerns capacity allocation, procurement and energy. Data governance concerns lawful basis, controllership, sectoral custodianship and the accountability of named data owners that §3.2.2 establishes. Describing them as one platform implies that whoever operates the national compute becomes the custodian of the national datasets placed on it, which would displace the data-owner model set out in §3.2.2 and create GDPR controllership questions for health, tax and justice data that the Strategy does not address. The conflation also produces a direct contradiction: §3.2.1 commits to a federated architecture that avoids unnecessary centralisation of sensitive information, while §1.4.2 commits to replacing scattered resources with a single shared platform. Both statements cannot be implemented. 12. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο Section 1.5, success metrics (printed p. 6); Section 2.5.2 and 2.5.5 (printed pp. 16–17); Section 3.6.2 (printed p. 37); Annex C, Education and Human Capital Development — NASO and FutureAI CY (printed pp. 79–81); Annex F. Σχόλιο / Εισήγηση Add a tertiary capacity component to Objective 5 and to the Education pillar: a multi-annual programme of publicly funded additional undergraduate and postgraduate places in computer science, data science and artificial intelligence at the state universities, with the corresponding academic posts and laboratory capacity, and a funded doctoral scheme in the six research focus areas of Annex D. Enrolment and completion in these programmes should be a tracked indicator in Annex F, and NASO's forecasting should feed directly into the allocation of places rather than only into reporting. The Strategy should also separate the labour-demand figure at §2.5.2 from the workforce-supply figure at §2.5.5, since they are currently the same number describing different things. Αιτιολόγηση σχολίου / Εισήγησης The Strategy sets a target of approximately 3,000 AI professionals by 2032 and then names no mechanism capable of producing one. CALF addresses ages 6 to 18 and produces no graduates within the Strategy's horizon. FutureAI CY delivers micro-credentials of 5 to 15 ECTS to working adults, against 240 ECTS for a bachelor's degree; these are valuable for AI literacy and workforce augmentation but do not produce AI engineers or data scientists, which the target explicitly names. NASO measures the gap and the talent-attraction measures at §3.6.5 compete for a scarce international supply, but neither adds domestic capacity. The absence of the state universities from the supply plan is a structural gap: they are the only institutions in Cyprus that can produce degree-qualified AI engineers, and expanding their capacity requires funded places and academic posts committed years ahead of the graduation date. A target set for 2032 with no undergraduate intake decision before 2027 cannot be met by domestic supply, which leaves attraction as the only remaining route. This instrument contradicts the sovereignty that is a goal. 13. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο Section 2.2.3, second paragraph (printed p. 10); Section 1.4.7 (printed p. 5); Section 2.5.3 (printed p. 16); Section 3.8 (printed pp. 40–42); Annex D, Focus Area 6 — Foundational AI Research (printed pp. 89–90). Σχόλιο / Εισήγηση Amend the second paragraph of §2.2.3 so that the observation about research translation is retained without implying that research which does not produce an operational solution has failed. Suggested reframing:” links between research and deployment remain uneven, and mechanisms for translating applicable research into operational solutions require strengthening, alongside sustained support for foundational research, which produces the methods, tools and trained researchers on which applied work depends and whose returns are realised over longer horizons.” Correspondingly, the prioritisation language at §1.4.7 and §2.5.3 should be balanced so that it does not subordinate the foundational research that Annex D Focus Area 6 identifies as a national priority, and the National AI Research Fund at §5 should carry a stated allocation for foundational work. Αιτιολόγηση σχολίου / Εισήγησης The observation that translation is uneven is fair and worth keeping. The framing, however, treats every research output that does not become an operational solution as a shortfall, which is not how research systems function: foundational work produces methods, evaluation techniques, tooling and trained researchers whose value is realised through later applied work, often by other groups and after long intervals. A national system that funds only research with an identified operational endpoint imports its foundations from elsewhere and forfeits the capacity to evaluate what it imports, which sits directly against Objective 8 on sovereign capability, since sovereignty in AI means the ability to understand and assess systems, not only to deploy them. The Strategy is also inconsistent on this point. Annex D names Foundational AI Research as one of six national focus areas, listing privacy-preserving learning, resource-efficient AI and robust anomaly detection, while §1.4.7 and §2.5.3 direct prioritisation toward applied and impact-oriented research. A focus area that is named as a priority in an annex and deprioritised in the funding language of the main text will not be funded. Doctoral training is the concrete case: it is the principal mechanism by which foundational research produces the skilled workforce the Strategy targets at §2.5.5, and it appears in neither the research nor the talent provisions." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Uncommon People","CONTRIBUTION TO THE PUBLIC CONSULTATION ON THE DRAFT NATIONAL AI STRATEGY 2032 OF THE REPUBLIC OF CYPRUS Submitted by Uncommon People Consulting, Sociedad Limitada (Spain), ESB16469710. www.uncommonpeople.eu. 27 August 2026. COVER NOTE 1. We congratulate the National AI Taskforce and the Chief Scientist for Research, Innovation and Technology on a draft Strategy of unusual scope, and on its willingness to state the constraints as plainly as the ambitions. Four features are particularly welcome: the human-centred principle that runs through the document; the age-banded architecture of the Cyprus AI Literacy Framework; the teacher-mediated design of the Ethical Pedagogical Validation Layer; and, above all, the education pillar's declared ambition, that Cyprus become a leading European hub for AI in education by 2032. 2. This contribution is authored by an independent strategic practice that has studied seventeen national AI-in-education programmes on three continents, and the Cypriot education landscape in depth. It is filed in the public interest. It seeks no contract for the delivery work it proposes, and no exception and no preference of any kind; Comment 12 states plainly what we would and would not accept, and on what terms. 3. This contribution concentrates on a single question: deliverability. We comment on the education pillar alone. Page 4 names a shortage of specialised AI skills among the Strategy's structural weaknesses, and page 6 counts 3,000 or more AI professionals among its success metrics, beside modernised shipping, maritime, healthcare, tourism and professional services. The other pillars are where those people work; this is the pillar they come from. The education chapter itself warns that, without coordination, fragmented pilots will produce low impact and unequal access; every comment below is offered to strengthen the pillar's path from framework to classroom. Twelve comments follow in the requested format, in four groups matching the four questions on which delivery depends. Who delivers: comments 1 to 3. What is taught, and how safely: comments 4 to 6. Where trust is built and systems are proven: comments 7 and 8. And how the work is measured, funded, and kept honest: comments 9 to 12. 4. Where this contribution points to a provision of the draft Strategy, it gives the section, page, or figure, so the reference can be checked in minutes. Statements about other countries rest on the accompanying annex, where each programme carries named, dated sources and estimates are identified as estimates. No factual claim in this contribution asks to be taken on trust. We have also read the whole record of this consultation as it stood on the day of filing, and where another contributor reached shared ground first, the relevant comment says so and seconds them: convergence among independent contributors is evidence in its own right, and the final text is easiest to strengthen where the record already agrees. 5. We wish to be plain about what we offer, and in what spirit. We have undertaken substantial preparatory work: benchmarking across seventeen national programmes on three continents; a study of the Cypriot education landscape in depth; and a complete, costed delivery design for a pillar of this shape, phased over five years, with governance, phase gates that can stop the work as well as advance it, a risk register, an evaluation framework, partner-selection criteria and the strategy for applying them, and a financial model reconciled to the Union instruments named in our tenth comment, showing how every component would be paid for. The philanthropic and private participation our eleventh comment contemplates is mapped within that model. We stand ready to present that work in full to the National AI Taskforce and the competent ministries, on request, without charge and without condition. And should the Taskforce or the ministries wish to discuss any part of it, we are at their disposal: a request suffices. We add one thing in candour: a contribution of this scope inevitably shows how we work, and we are content to be judged by it. 6. All of this work is offered in support of, and never in substitution for, the work of the National AI Taskforce and the competent ministries, whose frameworks the comments below take as their foundation. 7. One further conviction informs every comment below: implementation should build Cypriot capability rather than import around it. This consultation itself demonstrates the depth of the island's ecosystem, with a ministry, statutory bodies, research figures, educators, technology firms, and AI vendors raising their hands in these very pages. Comment 12 turns that conviction into a mechanism the Republic can hold anyone to, including ourselves. COMMENT 1: A NAMED DELIVERY VEHICLE FOR THE EDUCATION PILLAR ARTICLE AND SECTION Annex C, Education and Human Capital Development (pages 77 to 81); Section 3.5, priority sector 6. COMMENT / SUGGESTION The education pillar defines three excellent national instruments (CALF, EPVL, NASO) and a governance architecture for oversight, but names no organisation whose daily work is delivery: recruiting and training the teacher corps, producing and maintaining classroom materials, running pilots, and reporting results. We respectfully suggest that the final Strategy recognise a dedicated, independent, non-profit delivery vehicle for the education pillar, established as a foundation under Cyprus law, constituted on five principles: (a) government seats on its board alongside academia, the teaching profession, parents, and industry; (b) any private founders holding a structural minority, with an independent Cypriot chair; (c) statutory anchoring so the programme survives electoral cycles; (d) published audited annual accounts and independently evaluated results; and (e) recognition of the vehicle against published qualification criteria, so that any candidate, whatever its provenance, is measured to the same public standard. JUSTIFICATION The two national programmes most relevant to Cyprus by scale and ambition both run on precisely this model, and both appear in the literature the National AI Taskforce itself reviewed. Estonia's AI Leap operates as a public-private partnership through a dedicated delivery organisation, with its pilot year supported by an investment of approximately EUR 4 million co-funded in equal parts by the Ministry of Education and Research and private partners; teachers were trained before students entered, and the programme launched nationally for upper-secondary grades in September 2025 with some 20,000 students and 3,000 teachers, expanding further in September 2026. Greece delivers national education programmes through the Onassis Foundation while the Ministry retains full ownership of policy and curriculum. The counter-examples are equally instructive: where national initiatives were run as procurement projects without a dedicated institution, notably the Republic of Korea's AI Digital Textbook programme and the Los Angeles Unified School District's device programme, they consumed public and private budgets measured in the hundreds of millions to billions of dollars and were reversed or abandoned within two years. The consistent lesson of these cases is that an institution, rather than a project, is what carries an eight-year target credibly. The pillar's own stated goal, replacing fragmented pilots with a scaled, trusted national approach, is an organisational outcome and requires an organisation. One further consideration strengthens the case: the draft establishes a considerable number of new institutional bodies, and none of them carries a stated budget or headcount. A delivery vehicle so recognised, arriving with funded capacity of its own, would be the exception that proves deliverability, an institution able to act from its first day. One caution now on the record deserves adoption alongside the recommendation itself. A contributor writing as chair of a statutory national committee has observed that a strategy document can establish advisory, assurance and control-gate arrangements, but should not imply that any body holds licensing, enforcement or adjudicative powers the law has not conferred. We agree without reservation, and the recommendation is built for exactly that boundary: recognition in the Strategy does the work a strategy can do, naming the function and the published criteria, while powers, duties and permanence are conferred where alone they can be conferred, in law. The caution states, from institutional experience, exactly why point (c) asks for statutory anchoring: an eight-year programme needs both layers, and neither substitutes for the other. A contribution to this consultation argues that the draft creates too many new bodies for an administration of this size, and sets a test for any that are created: demonstrate the capability gap, show why an existing institution cannot fill it, name the resources that will sustain it, and state how its contribution will be measured. We think that is the right test, and we would have this recommendation judged against it. The gap is the one this comment opens with. The reason an existing institution cannot fill it is the reason the international record gives: a ministry running this as a project, rather than an institution running it as its daily work, is what failed in Korea and in Los Angeles. The resources are private and philanthropic rather than a further call on the public payroll, so the vehicle adds delivery capacity without adding public administration, which is the concern the test exists to serve. The measurement is points (d) and (e) above. We would rather meet that test than argue with it. Should the Taskforce find drafted wording useful, one sentence in the pillar's implementation section would serve: 'Delivery of this pillar will be supported by a dedicated, independent, non-profit delivery vehicle, with government and public-interest seats on its board, any private founders in a structural minority under an independent Cypriot chair, published audited accounts and independently evaluated results, recognised against published qualification criteria open to any candidate, and anchored in law.' COMMENT 2: MAKING THE CERTIFIED-EDUCATORS COMMITMENT MEASURABLE ARTICLE AND SECTION Annex C, Education and Human Capital Development; Figure 10 (certified educators as an expected deliverable and KPI). COMMENT / SUGGESTION Figure 10 correctly lists certified educators among the pillar's expected deliverables, and it is the only place in the pillar where that deliverable is named: the phrase appears nowhere in the chapter's text. The chapter specifies no training volumes, no sequencing, and no certification body relationship beyond the committee structure. We recommend that the final Strategy commit to: (a) a numerical teacher-training target with dates, sized against the roughly 17,300 teachers serving at all levels of the Republic's education system (17,298 in the Education Survey 2023/2024 of the Statistical Service of the Republic of Cyprus, the latest published); (b) an explicit sequencing rule that a first tranche of no fewer than 1,500 teachers is trained and certified before any classroom deployment of AI tools; (c) annual recertification so the corps keeps pace with the technology; and (d) that the deliverable be carried in the pillar's text and not in a graphic alone, so that it survives the figure reconciliation proposed in our ninth comment. JUSTIFICATION Teacher readiness is the single strongest predictor of success or failure across national programmes. Estonia trained its teacher cohort before students entered the programme, and in its first year 94% of participating teachers used AI in their work, with 63% incorporating it into their teaching. The Republic of Korea deployed AI Digital Textbooks to classrooms in March 2025 ahead of teacher readiness; classroom adoption halved within a single term, from 37% to 19% of schools, and in August 2025 the National Assembly revoked the books' textbook status, after a public commitment of roughly USD 850 million and private publisher investment reported at some KRW 800 billion, roughly USD 570 million, with teacher and parent unpreparedness cited among the leading causes. Finland's Elements of AI and the United Kingdom's National Centre for Computing Education both demonstrate that a certified educator pipeline is buildable at national scale within one to two school years when it is planned first. A deliverable that appears only in an infographic is also a deliverable that escapes text search, and therefore the one most likely to be lost in an editorial pass or overlooked by the ministries implementing the pillar; writing it into the chapter costs a sentence and secures the commitment. Attaching a numerical target here is precisely the kind of strengthening this consultation invites. The record of this consultation now carries an educator's proposal for a national teacher training and certification programme built around a levelled Cyprus AI Educator Certificate, kept current as the technology moves, and, from a second contributor, a call for a structured national professional development programme for teachers and academic staff carrying measurable participation and competency targets. We second both with enthusiasm, and they complete one another: the certificate gives the commitment its instrument, the competency targets give it a standard, and the volumes and dates above give both their scale, their sequence and their cadence. Adopted together, they would leave Figure 10's certified-educators deliverable with a name, a standard, a volume, an order and a renewal cycle: everything a deliverable needs in order to be delivered. COMMENT 3: PILOT BEFORE SCALE, WITH PUBLISHED GATES ARTICLE AND SECTION Annex C, Education and Human Capital Development (implementation); Annex B, AI Use Case Lifecycle and Control Gates. COMMENT / SUGGESTION The draft's Annex B establishes a disciplined lifecycle with control gates for AI use cases across government. We suggest the education pillar apply that same discipline to itself, explicitly: (a) a named pilot phase of 25 to 30 schools selected by published criteria across urban, rural, and disadvantaged catchments; (b) a published review at the end of the pilot year, with pass criteria defined in advance; and (c) explicit authority at each gate to stop, extend, or redesign before national scale-up. The pilot's evaluation should be independent and its results published regardless of outcome. JUSTIFICATION The most expensive education-technology failures of the last decade share one feature: scale preceded evidence. The Los Angeles Unified School District committed approximately USD 1.3 billion to a district-wide device deployment before its curriculum was complete; the programme collapsed within two years and ended in litigation. The Republic of Korea scaled nationally in a single step, with the outcome described in the previous comment. By contrast, the United Arab Emirates piloted, embedded, and then scaled, and its programme endures; Estonia began with two grade cohorts and published its adoption data, favourable and unfavourable alike. Cyprus's size is a strategic advantage here: a 25 to 30 school pilot is a meaningful sample of the entire system, something no large country can say, and the draft Strategy elsewhere recognises exactly this rapid-validation advantage in its research annex. The failure mode has a name in the Strategy itself. Page 4 lists among its structural weaknesses a risk of ""AI theatre"", many experiments and little impact, and page 63 answers that warning for the Government pillar with an explicit discipline of outcome-led selection focused on measurable results. The education pillar is given no equivalent, and published gates are how that discipline reaches the classroom. Publishing the gates in advance also protects the Strategy itself: pausing a pilot against published criteria reads as prudence, while pausing a national rollout is a far harder story for any government to tell. The record of this consultation asks for the same discipline from several directions, entry and exit criteria for pilots and clearer tests for the passage from pilot to production among them; what this comment adds is the education pillar's own version: the named pilot, the published criteria, the independent evaluation, and the authority to stop. COMMENT 4: EMBED AI LITERACY RATHER THAN ADD IT, AND PILOT THE CALF RUBRICS WITH TEACHERS ARTICLE AND SECTION Section 3.6.1 (AI literacy and awareness); Annex C (Cyprus AI Literacy Framework). COMMENT / SUGGESTION We warmly endorse CALF's four developmental bands and their alignment with the Key Competences for Lifelong Learning and the UNESCO and OECD competency frameworks. Three suggestions to strengthen implementation: (a) pilot the classroom-ready assessment rubrics jointly with the first teacher-training wave, so the instrument and its users are validated together rather than sequentially; (b) state explicitly that CALF outcomes are delivered by embedding within existing subjects (mathematics, science, languages, design and technology) rather than through new standalone timetable hours; and (c) specify accessible-by-design outcomes in the rubrics, so that learners who use assistive technology are inside the framework rather than exempted from it. JUSTIFICATION Joint piloting halves the calendar and surfaces the real failure modes: a rubric that works in a specification but not in a classroom is discovered only when trained teachers use it with real students. On embedding: the United Arab Emirates reached national coverage in months by placing AI content inside existing subjects, where there was nothing to displace and therefore nothing to negotiate. Reforms built on new timetable hours face the opposite arithmetic: an hour must be taken from something, and whatever it is taken from has a constituency. The Strategy states the embedding principle in mandatory terms twice, on consecutive pages. Page 25: ""AI initiatives shall be embedded within existing policy, operational and accountability structures and shall not be treated as standalone or experimental activities."" Page 26 repeats it in slightly different words. Both provisions address how ministries adopt AI rather than how a curriculum is built, but the logic is identical, and the education pillar does not apply it. Embedding also reaches every learner rather than only those who elect a new subject, which serves the pillar's own inclusion commitments. One further point belongs with the rubrics. On page 77 the pillar states that all learners, including vulnerable groups, should benefit from inclusive, accessible design, and on page 79 it gives the Pedagogical and AI Safety Committee, the body that maintains the CALF rubrics, the further task of validating accessibility checks. CALF's outcomes, however, are banded by age alone, so that committee is asked to validate accessibility against a framework which does not express it. Specifying accessible-by-design outcomes within the existing bands would give the commitment its instrument, and would place the learners who use assistive technology, whether captioning, text-to-speech, reading support or communication aids, inside the framework rather than beside it. COMMENT 5: EPVL: SPECIFY THE SAFETY INSTRUMENT BEFORE ANY CLASSROOM DEPLOYMENT ARTICLE AND SECTION Annex C, Education and Human Capital Development (EPVL, including the provision that it ""will be specified in a separate technical and pedagogical annex""). COMMENT / SUGGESTION The Ethical Pedagogical Validation Layer is, in our reading, the pillar's most important safety commitment: teacher-mediated, age-aware, culturally respectful, and auditable. Because the draft defers its specification to a future annex, we would ask the final Strategy to add four commitments, three of sequence and one of content: (a) the EPVL technical and pedagogical annex is published for consultation before any classroom deployment of AI tools; (b) EPVL validation is operational for a tool before that tool reaches students, without exception; (c) EPVL is piloted alongside the first teacher-training wave so its audit and mediation workflows are shaped by practising teachers; and (d) the annex names child-specific protections explicitly: exclusion of engagement-maximising, addictive, manipulative and deceptive design patterns, prohibition of commercial profiling of minors' data, age-appropriate design standards for every interface a student touches, and confirmation that no deployed system infers emotions from biometric data, which Union law already prohibits in education institutions. JUSTIFICATION Deploying classroom AI before its validation layer exists would invert the pillar's own logic and create avoidable exposure under Union law: AI systems in education fall within the high-risk regime of the Artificial Intelligence Act, whose education obligations apply from 2 December 2027 following Regulation (EU) 2026/1744. An operational EPVL is very close to a ready-made conformity and human-oversight architecture for that regime; sequenced correctly, Cyprus would arrive at the compliance deadline with an instrument other member states will still be designing. Sequenced incorrectly, the Republic would be retrofitting safety onto systems already in front of children, which is the costliest order of operations in both money and trust. The fourth ask closes a gap that runs wider than this pillar. The draft's only provision touching minors is EPVL's check on age appropriateness, which asks whether material suits a child, not whether a system is built to exploit one; addictive design, the commercial profiling of minors' data, and age-appropriate design standards appear nowhere in the document, though children are the Strategy's youngest and least defended users. The EPVL annex is the natural home for those protections, and a single annex can close the gap for the entire document. The record of this consultation shows other contributors pressing the same protections, and we second them gladly; what this comment adds is the sequence and the home: the protections named inside the EPVL annex, and the annex operational before any tool reaches a student. Should the Taskforce wish to draft the protections now, one paragraph would serve, the last of its four requirements restating a prohibition already in force rather than proposing a new one: 'Every AI system deployed in classrooms shall exclude engagement-maximising, addictive, manipulative and deceptive design patterns; shall not profile minors for commercial purposes nor permit reuse of their data for such profiling; shall conform to age-appropriate design standards for every interface a student touches; and shall not infer emotions from biometric data, which Article 5 of the Artificial Intelligence Act already prohibits in education institutions. EPVL validation verifies each requirement, per tool, before deployment; its findings are auditable; and a teacher, parent or student has a named route to report a suspected breach after deployment.' COMMENT 6: PAIR AI LITERACY WITH ROBOTICS: THE MIND AND THE BODY OF THE MACHINE ARTICLE AND SECTION Annex C, Education and Human Capital Development; Annex D, Focus Area 2 (Autonomous Systems); Section 3.8.5 (National Testbeds); Section 5 (Autonomous Systems Park). COMMENT / SUGGESTION Robotics is present in the draft's research agenda (Annex D names robotic perception, human-robot interaction, and swarm systems) and in its innovation infrastructure (the planned Autonomous Systems Park), yet it is absent from the education chapter. We suggest that the final Strategy: (a) pair AI literacy with robotics and physical computing as one curriculum strand, built on programmable microcontroller hardware of the micro:bit or Arduino class, at tens of euros per learner rather than thousands per room, so that learners meet both the reasoning of the machine and its physical expression, and so that the strand reaches every school on operating budgets without waiting on a capital programme; (b) connect the education pillar explicitly to the Autonomous Systems Park, giving schools a national venue for applied robotics, and provide that, where learners are present, the ""clearly defined operational, legal, safety, and ethical boundaries"" the draft already promises for its testbeds gain a pedagogical limb: teacher-mediated access and human-in-the-loop supervision of the kind EPVL establishes for classroom AI, extended to physical systems, since the safety case for a child beside an autonomous vehicle is not the safety case for a child at a screen; and (c) establish a national student robotics competition structure, with regional leagues feeding an annual final. JUSTIFICATION The case is practical before it is cultural, and inexpensive before it is either. Physical computing is not an enrichment of AI literacy but its completion: a learner who has only ever seen a model's answer on a screen has not met the point at which code acquires consequences, and that is precisely the point at which autonomous systems are engineered. Screen-based literacy alone also loses the learners who learn by building, among them many of the engineers a national strategy most needs, and a programmable board costing tens of euros gives exactly those learners their way in. The deployment arithmetic follows: a strand built on hardware at that price is a recurring operating line rather than a capital programme, so it can begin in the pilot schools and reach the network without waiting for buildings. The engagement evidence is international and durable, with competition circuits such as FIRST and the World Robot Olympiad sustaining participation at national scale across income levels. The draft itself supplies the remaining pieces of the argument. Annex D observes that Cyprus's scale supports rapid validation cycles and practical pilots, and names human-robot interaction ""to ensure safe, trusted collaboration"" among its research priorities: the education pillar is where that research meets its youngest subjects. The Autonomous Systems Park is a capital investment in drones, autonomous vehicles and robotics whose return depends on people who can build, operate and maintain them, and a park without a domestic pipeline staffs itself by import. That pipeline can only begin in schools and runs on a decade's lead time: the cohort that meets its first microcontroller in gymnasio is the cohort that staffs the Park in the 2030s. A generation that has built and programmed machines by the age of eighteen is the surest route to the Strategy's own target of 3,000 or more AI professionals, and the cheapest. And there is a cultural claim waiting to be made: the first imagined humanoid machine in world literature, Talos, guarded the shores of Crete, an island of the same sea. Pairing the mind and the body of the machine in Cypriot classrooms is not an import but a homecoming. COMMENT 7: A PUBLIC VENUE WHERE THE STRATEGY MEETS ITS PUBLIC ARTICLE AND SECTION Annex C, Education and Human Capital Development (national ambition and trust); Section 3.5 (public-private collaboration principle). COMMENT / SUGGESTION We propose the addition of a public engagement dimension to the education pillar: a flagship public venue for AI and robotics learning, open to families and visitors as well as schools. Without specifying any site, scale, or design, the venue's uses can be named now, because each answers a commitment the pillar has already made: for schools, curriculum-linked visit programmes that extend the classroom rather than interrupt it; for teachers, a permanent home for certification days, training cohorts, and the shared practice a dispersed profession otherwise never develops; for families, exhibitions and community days where parents watch their children programme a moving machine; for adults, short reskilling courses run with the training institutions the Republic already funds; for students, a national stage for the robotics leagues proposed in our sixth comment; and for the Republic, a place where the Strategy can be seen: the venue that hosts the delegations, the student finals, and the annual summit its international ambitions deserve. Curriculum reform is, by its nature, invisible to the public that funds it; a place with those uses converts an administrative programme into a national story, and public trust, which the pillar itself identifies as a condition of success, is built far faster in person than on paper. JUSTIFICATION The European science-centre evidence is long-standing and quantified. Estonia's AHHAA centre in Tartu attracts in the order of a quarter of a million visitors a year (246,434 in 2023, as published by the centre) in a city of roughly 97,000 inhabitants, and centres of its class typically recover a substantial share of operating costs through admissions, programmes, and events, limiting the long-term call on public operating budgets. The capital is a separate question with a separate answer: a venue of this kind is the sort of investment Union cohesion instruments exist to co-finance, alongside the co-funded partnerships the pillar's own public-private collaboration principle already contemplates. The obvious follow-up deserves a direct answer too: why not use what exists. The island's universities and research centres are designed for researchers and enrolled students, and their opening hours, safety regimes and layouts follow from that purpose; none is built for a class of thirty on a Tuesday morning or a family on a Saturday afternoon. A public venue is a different instrument, and the two are complements rather than alternatives: the venue draws its content, its demonstrations and much of its expertise from those institutions, and gives them a public face they were never built to provide. A venue of this kind also carries a value the pillar's text does not yet name: international visibility. A national centre hosting ministerial delegations, international student competitions, and an annual regional summit places the Republic's education initiative in front of the world's press and policy community on a recurring calendar, coverage of a kind small states rarely obtain and never at this cost. It also gives the pillar's other instruments a home: teacher certification days, CALF assessment pilots, student competitions, and public demonstrations of exactly the human-centred AI the Strategy promises. Neutral ground may be its quietest value: the one floor where more than one provider's systems can stand side by side, under the same roof and the same rules, compared in public rather than chosen in private. Several contributions to this consultation warn against dependence on any single provider; a place built for plurality is that warning heeded in architecture, and it changes the Republic's position in every negotiation that follows, because a state that can compare is a customer every provider must court. Nor need that plurality be left to hope: the timing favours the Republic for reasons set out later in this contribution, and the preparatory work behind it addresses how such participation would be assembled and on what safeguards; the detail travels with the rest of our work, on request. No square metre or site need be specified in the Strategy; recognising the venue dimension as part of the pillar is sufficient to enable it. If the Taskforce wishes to make that recognition operative, one sentence would do so: tasking the pillar's implementation phase with a feasibility assessment of such a venue, drawing on the European science-centre model, converts recognition into a datable, ownable action while committing the Republic to nothing beyond the study itself. COMMENT 8: SCOPE A NATIONAL REGULATORY SANDBOX TO EDUCATION ARTICLE AND SECTION Section 3, subsection headed ""Enabling Responsible Experimentation""; Section 5, Immediate Steps (industry sandboxes programme); Annex B. COMMENT / SUGGESTION We would encourage the Taskforce to name education explicitly as a domain of the planned national sandbox architecture. Under Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, every member state must have at least one national AI regulatory sandbox operational by 2 August 2027, and the same instrument applies the high-risk regime to education systems from 2 December 2027. Scoping a sandbox to education converts a compliance obligation into the pillar's own testing infrastructure: classroom AI tools, the EPVL validation layer, and teacher-facing systems could each be validated under supervision before deployment. JUSTIFICATION Education combines the Strategy's most sensitive user population, children, with its hardest Union-law deadline, which argues for the most structured testing environment the state can offer. A named education sandbox would also be an early-mover position in the Union: few member states have scoped their sandbox obligations by sector, and the first to run classroom AI through a supervised sandbox would be well placed to shape the practice others follow. The draft's Annex B control-gate lifecycle supplies a ready-made evaluation framework; the sandbox gives those gates a home. COMMENT 9: RECONCILING THE STRATEGY'S TARGETS, DATES AND FIGURES BEFORE ADOPTION ARTICLE AND SECTION Annex C pages 77 to 81 (education pillar, including Figure 10); Figures 5, 7 and 11 (pages 64, 71 and 85); Section 3.5, Healthcare (pages 33 to 34) with Annex C page 68; Section 1.5; Section 2.2.1. COMMENT / SUGGESTION In the spirit of strengthening the final text, we note the following for the editorial pass. These notes begin in the education pillar and end in a pattern that affects the document as a whole. (a) The education pillar's 2032 adoption target reads 75% in the priority-sector summary and in the pillar table on page 81, but 50% in the Figure 10 infographic printed immediately beneath that table on the same page; the final text may wish to reconcile the two. A related reconciliation would strengthen the whole document: 75% appears as a target in three different scopes, industry adoption by 2030 (Section 5, Immediate Steps, under ""Accelerating Adoption and Industry Readiness"", page 51), overall adoption by 2032 in the Government pillar (cited as in line with the Digital Decade target, whose own form is 75% of enterprises by 2030), and education and labour by 2032 in Annex C. Stating each pillar's target once, with its own scope and date, would remove any doubt about what is promised, to whom, by when. (b) The pillar's baseline, 13% adoption across education and labour, carries no stated source and no metric definition: it is not specified as a share of teachers, students, schools, workers, or enterprises. The document itself shows the form the figure needs: the enterprise-adoption baseline of 9.27% in Section 2.2.1 is defined, given a trend (an annual progression of 17.3% since 2024) and set against a comparator (the EU average of 19.95%), and giving the 13% the same three-part treatment would let the pillar's headline target be measured with the same confidence. The subsection headed ""Strategic objectives and 2032 target"" would also benefit from stating the target as a number. (c) Page 79 twice renders the Deputy Ministry's name as the Deputy Ministry of Digital Policy, Research and Innovation; the official form, used elsewhere in the Strategy including on page 80 of the same annex, is the Deputy Ministry of Research, Innovation and Digital Policy. (d) The Figure 10 variance does not appear to be isolated. Because the pillar infographics are images, their content escapes text-based checking, and reading them figure by figure against the surrounding text shows the same pattern in three further pillars: Figure 5 (Government, page 64) gives 75% adoption ""by 2030"", the 40% reduction in citizen waiting times ""by 2030"", and intelligent governance ""by 2035"", where the pillar text gives 2032 for all three; Figure 7 (Healthcare, page 71) gives virtual human twins ""by 2035"", agreeing with the pillar's deliverables table on page 70, while the pillar's text on page 68 gives 2032 for the same deliverable; and Figure 11 (Shipping, page 85) gives the Intelligent Maritime Orchestrator ambition and its capability KPI ""by 2035"", where the pillar text gives 2032. We would respectfully suggest a figure-by-figure reconciliation pass before adoption, so that the final Strategy states each of its targets once, identically, in text and graphic alike. (e) The same reconciliation is needed where the body text dates its own deliverables. On page 33, the Secure National Health Data Repository initiative states that its governance arrangements ""will be elaborated in the dedicated AI healthcare strategy, to be developed by December 2027""; on page 34, the same chapter closes by stating that ""a full-scale AI healthcare strategy is recommended for development by 2028""; and the Annex C healthcare pillar repeats the 2028 form on page 68. As drafted, the same instrument appears to carry two dates and two statuses, a commitment on one page and a recommendation on the next; and because a named initiative expressly defers its governance detail to that strategy, the strategy's date and status deserve to be stated once. If two distinct documents are intended, saying so expressly would serve the same end. (f) In Section 1.5, the three relative implementation windows (0 to 8, 6 to 12, and 12 to 24 months) carry no stated start date, and two of the seven success metrics are prefaced ""Recommended""; anchoring the windows to a date and firming the verbs would strengthen the scorecard against which the Strategy will be measured. (g) The certified-educators deliverable would benefit from the numerical targets suggested in our second comment. JUSTIFICATION These notes are offered with genuine appreciation for the scale of drafting the Taskforce has undertaken; documents of this breadth inevitably accumulate small variances, and this one carries remarkably few in its text. Other contributors have noticed some of the same variances: one asks that the final text distinguish committed targets from strategic ambitions and scenario estimates, which is the point made at (f) above approached from another direction, and another asks that every indicator carry a definition, baseline, data source and named owner, which is the general form of the point made at (b) above; all three strengthen the case for one reconciliation pass before adoption rather than corrections piecemeal. The graphics deserve particular attention for exactly that reason: because figure text cannot be searched, variances there are the likeliest to survive into the adopted Strategy, and those noted above were found only by reading every pillar figure against its surrounding text. The stakes are practical rather than editorial: points (d) and (e) in particular bear on measurement rather than wording, and may merit the attention of those who own the targets as well as of the editorial pass. Foundational numbers and dates are inherited downstream by procurement documents, KPI dashboards, and ministry work plans, and no pillar can be delivered against a target the document states two different ways. All of this is easiest to align while the text is still open. COMMENT 10: A FUNDING ARCHITECTURE FOR THE EDUCATION PILLAR ARTICLE AND SECTION Section 3.10 (sustainability and economic model); Section 1.4.9; Annex C (Education and Human Capital Development). COMMENT / SUGGESTION We recommend that the final Strategy attach a funding architecture to the education pillar: at minimum, a mapping of the Union instruments available to it, and ideally an indicative envelope. The instruments are substantial and already aligned with the pillar's components: Erasmus+ Teacher Academies for the certified-educator pipeline; Digital Europe Programme skills actions for advanced digital capability; Horizon Europe, including the Teaming instrument that Cyprus has used successfully before, for the research dimension; and the Thalia 2021-2027 cohesion programme for physical infrastructure. JUSTIFICATION Every expected deliverable of the education pillar depends on sustained funding, yet the pillar carries no financial reference of any kind, a silence it shares with the Government, Healthcare, and Tourism pillars, in a document whose only programme-level financial figures are the EUR 5,000 threshold of the AI Judge capability and the EUR 1 million per round of the investment-matching fund. The education pillar is where that silence costs most, because its deliverables are recurring rather than one-off: teachers must be trained and recertified every year, content maintained, and evaluations published for as long as the pillar lives. The benchmark evidence should encourage rather than daunt: Estonia runs its pilot year on approximately EUR 4 million, co-funded in equal parts by the state and private partners, achieved by sequencing teachers first and adapting existing tools rather than commissioning new platforms. Naming the available instruments costs the Republic nothing, signals seriousness to the Union bodies that co-fund such work, and answers in advance the first question every implementing ministry will ask: who pays. Other contributions to this consultation have remarked on the same silence; this comment differs in offering the remedy, the instruments named and the mapping made. COMMENT 11: WELCOMING CO-FUNDED DELIVERY PARTNERSHIPS ARTICLE AND SECTION Annex C (Education and Human Capital Development); Section 3.5 (public-private collaboration principle). COMMENT / SUGGESTION Finally, we invite the Taskforce to consider one enabling sentence in the education pillar: 'The Republic welcomes co-funded delivery partnerships, including philanthropic participation, for the implementation of this pillar, under public governance safeguards and the compliance framework this Strategy establishes.' Should the Taskforce wish to make that welcome operative, a second sentence would do so: 'The implementation phase will convene prospective co-funders, philanthropic and corporate, under the same safeguards.' Together they give interest a named public doorway and the Republic the convening seat. JUSTIFICATION The draft already embraces public-private collaboration as an adoption principle; this suggestion simply extends that principle explicitly to the education pillar, where the international precedents are strongest. Estonia's programme is co-funded in equal parts by the state and private partners through a dedicated delivery organisation; Greece's most significant national education programmes are delivered with philanthropic institutions under ministry policy control. Demand for such partnerships will not need to be manufactured: the Union's classroom-AI obligations take effect on 2 December 2027, and providers will need demonstrably compliant national deployments inside an EU jurisdiction before that date. An explicit welcome in the final text gives any future partner, and the Republic itself, a clear and orderly doorway, with the state holding the keys; and a pillar that admits more than one partner under identical terms and independent evaluation keeps the Republic permanently in the stronger position. One further observation belongs here, because the record of this consultation will be read by more than its addressees. The architecture the draft already contains, public governance, independent evaluation, control gates that can stop work, and published results, is precisely the architecture serious philanthropy requires before it commits; the draft has, perhaps without intending it, already written the assurance side of a co-funding agreement. What is missing is only the invitation. Foundations do not volunteer into silence. An explicit welcome in the adopted text is how both kinds of participation become proposable in Cyprus: the mission philanthropy that funds national education delivery in Greece, and the private co-funding that carries half of Estonia's. We would discuss either kind with the Republic gladly, whenever asked. COMMENT 12: OPEN PROCUREMENT FOR THE PILLAR'S RECURRING DELIVERY WORK, AND A DECLARATION OF INTEREST ARTICLE AND SECTION Section 3.3.2, Control Framework (approval gates before procurement; approved and certified delivery and implementation partners); Annex C, Education and Human Capital Development; Annex F (national KPIs and measurement framework). COMMENT / SUGGESTION We recommend that the final Strategy commit the education pillar's recurring delivery work, systems integration, content production, training logistics, and platform operations, to open, competitive procurement, and that Annex F carry an indicator reporting annually the share of that contract value awarded to Cyprus-resident suppliers. A declaration of interest belongs beside that recommendation, so that it binds its proposer first. We are an independent practice, not a candidate delivery vehicle, and we hold no interest in any body that is, as at the date of this contribution; should that change, we would say so. We have prepared, at our own cost, a complete implementation plan of the kind these comments describe, and we would wish to see such a programme built, by whichever body the Republic's published criteria select. That plan is offered to the Republic without charge and without condition. We seek no exception and no preference: if we were ever engaged in connection with this pillar, whether by the Republic or by a body funding the work, that engagement would come either through open competition or on ordinary commercial terms openly stated, on the same footing as any other candidate. The division of labour we advocate binds us first: the recurring delivery work this comment commits to open procurement, the systems, the content, the logistics and the operations, belongs to the market, Cypriot firms foremost, and we would take no part in it; designing how an institution is to work and operating it are different trades, and we do only the first, save for one bridge between them which the list below names and bounds. Our own part in this pillar is strategy, and if the Republic or a funder ever sought that work from us it would be strategic work of the kinds this contribution has already required: assembling and sequencing the applications to the Union instruments named in our tenth comment, with the case-building each one needs; keeping the design current as Ministry data arrives, as Union law moves and as the international evidence changes; transitional programme coordination until the delivery body's own leadership is in post, which is that bridge: work someone must do before the institution exists to do it itself, ending on an appointment we do not make; the design of that body's operating model and of the performance framework it reports against; and supporting the Republic in convening the international participation described above, the Republic holding the convening seat throughout. None of that is delivery work and none of it is the delivery role itself, and any of it would be commercially negotiated on the terms just stated. We would not evaluate what we designed: the independent evaluation our third comment asks for must be independent of us too. We state this plainly rather than leave it to be discovered. JUSTIFICATION The draft returns to small and medium-sized enterprises throughout, more than twenty times across its chapters, and the commitment is unmistakable. What the text does not yet carry is the machinery that would deliver it: lot design, reserved participation, and an indicator tracking the share of contract value that remains with Cyprus-resident firms. The education pillar is a natural place to begin, because its delivery work recurs by nature, and spend that is procured openly circulates through the island's own technology sector year after year, strengthening the ecosystem the Strategy sets out to grow. We note with agreement that other contributions to this consultation have proposed kindred machinery: reserved procurement lanes for Cyprus-resident SMEs, with express indicators for the AI contract value awarded to them. The placement is this comment's addition: an indicator carried in Annex F, which the record elsewhere also asks to hold outcome indicators of other kinds. One such contributor, a Cypriot vendor, stated its own interest as plainly as we state ours; we simply stand on the other side of the same disclosure, a Spanish practice proposing an indicator that counts a category which cannot include us. A mechanism urged both by those it would include and by those it cannot include arrives corroborated on the only ground that matters. The declaration above is offered in the same spirit: we would rather be held to it than believed. A practice that asks for open procurement, states its own interest plainly, and accepts for itself the criteria it proposes for others, gives the Republic something it can check. ANNEX: WHAT SEVENTEEN NATIONAL PROGRAMMES TEACH This annex summarises publicly documented outcomes of national AI-in-education and related digital-education programmes reviewed for this contribution: Croatia, Estonia, Finland, France, Greece, Malta, the United Kingdom, the United Arab Emirates, Qatar, Saudi Arabia, Israel, Singapore, South Korea, Japan, China, India, and the United States. All figures are as publicly reported at the date of filing; sources are named for each programme, and where a figure is an estimate the text says so. A. DELIVERY MODELS THAT WORKED, AND WHY THEY WORKED Estonia. The AI Leap programme launched nationally on 1 September 2025 for upper-secondary grades, with some 20,000 students and 3,000 teachers, and expands in September 2026 to vocational schools and new cohorts, adding roughly 38,000 further students. It operates as a public-private partnership through a dedicated delivery organisation; the pilot year is supported by approximately EUR 4 million co-funded equally by the Ministry of Education and Research and private partners including Telia, Skaala, and the Smart Future Fund. Teachers were trained first, and the effect shows in the first-year results: 94% of participating teachers used AI in their work and 63% incorporated it into their teaching. Estonia also publishes its adoption data candidly, including the less flattering weekly-use figures, and adjusts accordingly; that habit of published honesty is itself part of the model. A country of comparable size to Cyprus, spending in the low single millions, is now the reference point for an entire continent. Sources: Ministry of Education and Research announcement of the AI Leap programme (hm.ee, February 2025); TI-Hüpe programme site and first-year results (tihupe.ee, 2026), which also name the co-funding partners. Greece. National-scale education delivery in partnership with the Onassis Foundation, with the Ministry retaining full ownership of policy and curriculum; separately, a national agreement bringing AI tools into schools. The significance of the model is what it removes: no procurement friction, no political ownership battles, and delivery capacity that does not depend on the electoral cycle, all while the state keeps every decision that belongs to the state. Sources: Ministry of Education of Greece; Onassis Foundation. United Arab Emirates. AI content embedded within existing subjects, enabling nationwide coverage within months rather than years, scaled after piloting, and still operating and deepening today across all school grades. The demonstration that speed and durability are compatible when the sequencing is right. Sources: UAE Ministry of Education announcements. Finland. Elements of AI, a university-led open course, made AI literacy a mass phenomenon, reaching, as publicly reported, more than a million learners across dozens of countries from a standing start, and proving that well-designed content, not expensive platforms, is the scarce ingredient. Sources: University of Helsinki and MinnaLearn, Elements of AI enrolment reporting (elementsofai.com). United Kingdom. The National Centre for Computing Education built a national teacher-certification pipeline for computing through a network of hubs and subject-knowledge certificates, upskilling teachers by the tens of thousands: the closest operational template in Europe for a certified-educators KPI with real numbers attached. Sources: National Centre for Computing Education impact reporting (teachcomputing.org); Department for Education. Singapore. Sustained, incremental integration of AI into schooling under successive national masterplans, with teacher capability treated openly as the binding constraint and adaptive learning systems introduced only as that capability matured. Sources: Ministry of Education of Singapore. B. CAUTIONARY EVIDENCE: HOW NATIONAL PROGRAMMES FAIL South Korea. The chronology deserves attention because it is recent and complete. The AI Digital Textbook plan was announced in June 2023; 76 textbook titles were approved in September 2024; the books entered classrooms with the school year in March 2025, ahead of teacher readiness and without a gated pilot. Classroom adoption fell from 37% of schools in the first semester to 19% in the second, and in early August 2025 the National Assembly amended the law to strip the books of textbook status, reclassifying them as supplementary materials and ending their funding mandate. The public commitment is reported at roughly USD 850 million, participating publishers invested a reported KRW 800 billion, roughly USD 570 million, and the 2026 digital-education budget was subsequently cut to roughly one sixth of its prior level. One of the most digitally advanced school systems on earth, with resources few nations can match, lost its programme not to technology but to sequence. Sources: Korea Herald, ""South Korea pulls plug on AI textbooks"" (August 2025); Rest of World, ""South Korea's AI textbooks fail after rushed rollout"" (2025); Ministry of Education of Korea announcements and National Assembly proceedings, 2023 to 2025. United States (Los Angeles). A district-wide device programme of approximately USD 1.3 billion, launched in 2013 before its curriculum was complete, collapsed within two years amid procurement failures and a December 2014 federal investigation, and Pearson settled with the district for USD 6.45 million in October 2015. A single school district outspent most national education budgets, and its experience is now part of the evidence every later programme can draw on. Sources: contemporaneous United States reporting, 2013 to 2015; the federal investigation of December 2014 and the Pearson settlement of October 2015 are matters of public record. China and Japan. Large-scale national pushes illustrate both the productivity potential of AI in learning analytics and the governance questions raised by classroom surveillance applications; the human-centred boundary the draft Strategy sets is the correct one, and worth defending explicitly as deployments scale. Sources: national policy documents; OECD reviews. The warning these cases carry is specific, not general. Korea's reversal is barely a year old. Both failures occurred in systems with far greater resources than any small state commands, and in both cases the missing elements were exactly those the draft's education pillar currently leaves unspecified: teacher volumes, pilot gates, a delivery institution, and a funding architecture. The comments in this contribution ask for nothing more than the insertion of those elements while the text is still open, because every one of them has already been paid for, expensively, by someone else. C. INVESTMENT CONTEXT Israel, Qatar, Saudi Arabia, France, India, Malta. Each is investing systematically in AI skills through national strategies, dedicated institutes, or school programmes, confirming that the education-AI race is global and that windows of distinction close quickly. Croatia's BrAIn programme, listed above and reviewed on the same basis, run by the CARNET network under the Ministry of Science, Education and Youth with EUR 16 million of funding, 85% of it from the European Social Fund Plus, brings AI curricula into schools as elective and extracurricular subjects from the 2025/2026 school year: the nearest EU signal that first-mover room inside the Union is finite. Sources: CARNET BrAIn project documentation (carnet.hr); national AI strategies; EU monitoring. D. THE PATTERN, IN ONE PARAGRAPH Across seventeen programmes the pattern is stable: initiatives succeed when teachers precede students, pilots precede scale, content precedes hardware, delivery has an institution rather than a project office, and evaluation is independent and published. They fail, at costs measured in the hundreds of millions to billions, when any of those orders is reversed. Cyprus's draft Strategy already contains the principles; the comments above ask only that the final text bind them to the education pillar with numbers, sequence, and a named delivery function, qualified against published criteria." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","ΔΙΕΥΘΥΝΣΗ ΝΟΣΗΛΕΥΤΙΚΩΝ ΥΠΗΡΕΣΙΩΝ","Σχόλια Διεύθυνσης Νοσηλευτικών Υπηρεσιών Υπουργείου Υγείας Η Διεύθυνση Νοσηλευτικών Υπηρεσιών του Υπουργείου Υγείας αναγνωρίζει ότι η Τεχνητή Νοημοσύνη (ΤΝ) αναμένεται να διαδραματίσει καθοριστικό ρόλο και στον ψηφιακό μετασχηματισμό του Συστήματος Υγείας, συμβάλλοντας στη βελτίωση της ποιότητας των παρεχόμενων υπηρεσιών. Ως εκ τούτου είναι σημαντικό στην Εθνική Στρατηγική Τεχνητής Νοημοσύνης να συμπεριληφθούν ή και να αναφέρονται τα ακόλουθα: 1. Αναγκαιότητα ανάπτυξης ενός ολοκληρωμένου πλαισίου ενίσχυσης των δεξιοτήτων του ανθρώπινου δυναμικού στον τομέα της Τεχνητής Νοημοσύνης στην Υγεία. Η επιτυχής ενσωμάτωση εφαρμογών ΤΝ προϋποθέτει την κατάλληλη εκπαίδευση και συνεχή επιμόρφωση των επαγγελματιών υγείας, των διοικητικών στελεχών και του λοιπού προσωπικού, ώστε να μπορούν να αξιοποιούν τις νέες τεχνολογίες με ασφάλεια, υπευθυνότητα και αποτελεσματικότητα. 2. Η αξιοποίηση της Τεχνητής Νοημοσύνης έχει αποκλειστικά υποστηρικτικό χαρακτήρα και δεν υποκαθιστά σε καμία περίπτωση την επιστημονική κρίση, την επαγγελματική ευθύνη και τη λήψη αποφάσεων από τους επαγγελματίες υγείας. 3. Η αξιοποίηση εφαρμογών Τεχνητής Νοημοσύνης στον τομέα της Υγείας πραγματοποιείται στο πλαίσιο αυστηρών προδιαγραφών προστασίας των προσωπικών δεδομένων και ιδιαίτερα των δεδομένων υγείας. Απαιτείται η εφαρμογή κατάλληλων μηχανισμών ασφάλειας, διαφάνειας και ελέγχου όσον αφορά τη συλλογή, επεξεργασία, αποθήκευση και αξιοποίηση των δεδομένων από συστήματα ΤΝ. 4. Ενεργός συμμετοχή των επαγγελματιών υγείας και ιδιαίτερα των νοσηλευτών και μαιών στον σχεδιασμό και την εφαρμογή λύσεων ΤΝ. Η ανάπτυξη και εισαγωγή εφαρμογών ΤΝ στο Σύστημα Υγείας πραγματοποιείται με ουσιαστική συμμετοχή των επαγγελματιών που θα τις χρησιμοποιούν στην καθημερινή πρακτική. Ειδικότερα, η συμμετοχή νοσηλευτών και μαιών είναι σημαντική, δεδομένου του άμεσου και συνεχούς ρόλου τους στην παροχή φροντίδας και στην επικοινωνία με τους ασθενείς. 5. Αξιοποίηση της ΤΝ για μείωση του διοικητικού φόρτου των επαγγελματιών υγείας. Ιδιαίτερη έμφαση θα μπορούσε να δοθεί σε εφαρμογές που αυτοματοποιούν ή υποστηρίζουν διοικητικές και επαναλαμβανόμενες εργασίες, χωρίς να επηρεάζουν την ασφάλεια της φροντίδας, με στόχο την εξοικονόμηση χρόνου και τη δυνατότητα των επαγγελματιών υγείας να αφιερώνουν περισσότερο χρόνο στην άμεση φροντίδα των ασθενών." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",pjdoolan1,"Closing comments from the German Medical Institute. Offer of contribution We offer the following without charge: • Our clinical AI deployment lifecycle and local validation protocol, including the chest X-ray evaluation methodology and the Greek-language reference-standard problem and how we addressed it, as a candidate template for a national validation protocol. • Participation in the drafting of the dedicated AI healthcare strategy and in the design of the healthcare regulatory sandbox, including the regulatory classification and conformity assessment questions raised in Comments 1 and 2. • Our membership of the European Network of AI-Powered Advanced Screening Centres as a channel for exchange between the national programme and current European deployment practice. If the Republic procures validation, conformity or advisory services in this area, we would tender for that work on the same terms as any other provider, and we distinguish that clearly from the contributions offered above. We thank the National AI Taskforce and the Chief Scientist for the substantial document, and for a consultation process that invites this kind of detail. Our comments are offered in support of the Strategy’s direction and its ambition for Cyprus to be a credible and fast route to the European market for trustworthy health AI. We would welcome the opportunity to discuss any of them." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",pjdoolan1,"Comment 8 of 8 from the German Medical Institute Comment 8: Define the workforce target and accredit clinical AI training through the professional bodies Article / paragraph: Section 3.5, Priority Sector 3 (“By 2032, Cyprus aims for 50% of its medical workforce to be trained in AI-enabled practices”); Section 3.6.2 (Advanced and Sector-Specific Skills); Annex C, Healthcare and Life Sciences; Annex C, Education and Human Capital Development (FutureAI CY); Annex F. Comment / Suggestion: Amend the workforce provisions to: (a) define ""medical workforce"" so that the 50% target is extended beyond physicians to the wider clinical workforce, including medical physicists, radiographers, nurses and laboratory scientists; (b) accredit clinical AI training as continuing professional development through the Cyprus Medical Association and the relevant professional bodies, so it carries professional recognition; and (c) structure it in three tiers: general clinical AI literacy for the whole workforce, a smaller cohort with deployment and evaluation competence, and a designated clinical AI lead in each institution. Justification: As drafted the target cannot be measured, because the term “medical workforce” is not fully defined and because “trained in AI-enabled practices” has no stated competence standard. The AI Act requires meaningful human oversight of high-risk systems, but this only applies when the overseeing clinician is competent to disagree with the system. They need to know its failure modes, to recognise when a case is outside its validated distribution, and to have the confidence to override it. That is a different competence from knowing how to use a tool, and it is what local validation, drift monitoring and post-deployment surveillance all require. A national programme that trains 50% of the workforce to use AI tools, without producing the smaller cohort that can evaluate and govern them, will have satisfied the target and not the underlying requirement. We would add that the clinical workforce in AI-enabled care is not only physicians. In our own deployments, medical physicists and radiographers carry much of the evaluation and quality assurance work." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",pjdoolan1,"Comment 7 of 8 from the German Medical Institute Comment 7: Specify a health-designated secure processing environment within the National AI Infrastructure Article / paragraph: Section 3.7 (Infrastructure, Compute and Digital Sovereignty), particularly 3.7.2, 3.7.3 and 3.7.4; Section 3.7.5 (Integration with EuroHPC and the European AI Factory Ecosystem); Annex C, Healthcare and Life Sciences. Comment / Suggestion: State that the National AI Infrastructure will include a health-designated secure processing environment, operating on the European Health Data Space model where data does not leave the environment and only results are exported. The infrastructure should be suitably sized for medical imaging, and available to hospitals, researchers and validation programmes under the Data Access Committee governance the Strategy already describes. Justification: Health data cannot be served by a general-purpose allocation policy alone: it requires environments where the access controls, audit trails, residency guarantees and export restrictions are fundamental properties of the infrastructure. Sovereignty for health data is not a question of scale, but rather in which environment the data sits and who governs access." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",pjdoolan1,"Comment 6 of 8 from the German Medical Institute Comment 6: Make interoperable digitalisation a dated obligation for all providers contracted to the General Healthcare System Article / paragraph: Section 3.2.4 (Data by Design in Public Systems); Section 3.5, Priority Sector 3 (Secure National Health Data Repository); Annex C, Healthcare and Life Sciences; Section 5, item 3. Comment / Suggestion: Introduce an explicit obligation, with a stated date and a phased schedule by provider size, for all healthcare providers contracted to the General Healthcare System (both public and private) to: (i) maintain structured electronic health records conforming to the European Electronic Health Record Exchange Format; and (ii) to transmit a defined minimum dataset to the National Health Data Repository. GHS contracting could be used as the enforcement mechanism. Justification: The Strategy describes a Secure National Health Data Repository that consolidates data from hospitals and laboratories, but places no obligation on the institutions that hold this data. Contribution will therefore be provided by hospitals that are willing to do so, and the national repository will only represent whoever choses to participate. Any AI system trained or validated on it will inherit that bias." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",pjdoolan1,"Comment 5 of 8 from the German Medical Institute Comment 5: Name disease registries as first deliverables of the National Health Data Repository Article / paragraph: Section 3.5, Priority Sector 3 (Secure National Health Data Repository); Annex C, Healthcare and Life Sciences, ""Implementation, evidence and compliance""; Section 3.2.1 (sectoral data spaces); Section 5, item 3. Comment / Suggestion: Specify a national cancer registry and a national rare disease registry as first outputs of the Secure National Health Data Repository. Each registry should have an identified responsible body and alignment to the corresponding European standards and infrastructures. Justification: The Secure National Health Data Repository is currently described by the data types it will consolidate (primary care, hospitals, laboratories, imaging, prescriptions) and not by any clinical product it will deliver. Disease registries are the natural first deliverable. They have a defined scope, an identifiable clinical owner, and an existing European reference framework. They are also where health AI development starts, because a curated registry with outcome data is a usable training and validation asset." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",pjdoolan1,"Comment 4 of 8 from the German Medical Institute Comment 4: Recognise the European Network of AI-Powered Advanced Screening Centres in the international alignment provisions Article / paragraph: Annex C, Healthcare and Life Sciences, ""International alignment"". Comment / Suggestion: Name the European Network of AI-Powered Advanced Screening Centres among the European initiatives in which Cyprus participates. Justification: Section 3.12.2 commits Cyprus to active participation in European initiatives, and the Healthcare pillar’s international alignment section in Annex C refers to WHO guidance and European principles. It would be good to mention the European Commission’s network on AI-Powered Advanced Screening Centres, which is the country’s most concrete existing operational link into European health AI practice and in which three Cypriot organisations are already members. The network is where deployment experience, evaluation methods and failure modes are exchanged between the hospitals doing this work within Europe." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",pjdoolan1,"Comment 3 of 8 from the German Medical Institute Comment 3: Establish a national clinical AI validation function and require local performance verification before deployment Article / paragraph: Section 2.3.4 (Strengthening the International Position); Section 3.7.4 (Deployment Environments); Section 3.8.5 (National Testbeds); Annex C, Healthcare and Life Sciences, ""Implementation, evidence and compliance""; Annex C, Entrepreneurship and Innovation (GHS health data sandbox). Comment / Suggestion: Add to the Healthcare pillar a requirement that no AI system be deployed in a publicly funded Cyprus clinical setting without a documented local performance evaluation. This should be conducted on local patient data and assessed against local clinicians’ reports. This should be repeated at defined intervals thereafter. Designate a national clinical AI validation function to publish the protocol, maintain the evidence base and make results available across the health system. CE marking is necessary for deployment but is insufficient alone. Justification: GMI can recommend this based on our own experience. In our chest X-ray programme we shortlisted candidate tools against published performance figures, then evaluated them on a consecutive sample of 731 local cases, using our radiologists’ original reports as the reference standard. Vendor-quoted metrics, obtained on the vendors’ test datasets, are not a reliable predictor of performance on a given hospital’s case mix. The evaluation changed which tool we selected. It is the single highest-value step in our deployment lifecycle and it cannot be substituted for with a CE mark. The CE mark certifies that a device meets its own intended-purpose claims, not that it performs on a particular population. There is a specific Cypriot obstacle that all hospitals wanting to perform local validation will encounter. The clinicians’ reports are in Greek and the AI outputs are in English, so local validation first requires translation before the reports could be used as the ground truth. Every Cypriot institution deploying diagnostic AI will meet the same problem and solving it once nationally is cheaper than solving it repeatedly for each centre." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",pjdoolan1,"Comment 2 of 8 from the German Medical Institute Comment 2: Correct the compliance timeline and bring the regulatory components of the healthcare AI strategy forward to 2027 Article / paragraph: Section 3.5, Priority Sector 3 (""A full-scale AI healthcare strategy is recommended for development by 2028""); Annex C, Healthcare and Life Sciences; Section 3.8.5 (National Testbeds); Section 5 (Immediate Steps); Annex A. Comment / Suggestion: Bring forward the regulatory, validation and conformity components of the dedicated AI healthcare strategy from 2028 to 2027. In parallel, state in Section 3.8.5 that Cyprus will satisfy its obligation under Article 57 of the AI Act to have at least one AI regulatory sandbox operational - this could be a healthcare sandbox. The responsible body and the date should be named. Justification: Since the Strategy was drafted, the dates for compliance have changed. Following adoption of the Digital Omnibus on AI by the European Parliament in June 2026 and the Council on 29 June 2026, the relevant dates are: Article 50 transparency obligations from 2 August 2026 (already in force); high-risk obligations for standalone Annex III systems from 2 December 2027; and high-risk obligations for AI embedded in regulated products from 2 August 2028. Separately, Member States must have at least one national AI regulatory sandbox in place by 2 August 2027. We also add that the European Health Data Space Regulation (EU) 2025/327 applies from 26 March 2027, with cross-border exchange of imaging, laboratory results and discharge reports required by March 2031. It also requires each Member State to designate a national digital health authority and a health data access body. These obligations should be included in the Strategy’s timeline." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",pjdoolan1,"Comment 1 of 8 from the German Medical Institute Comment 1: Name the Medical Device Regulation in the Healthcare pillar and in the European alignment provisions Article / paragraph: Section 3.5, Priority Sector 3 (Healthcare and Life Sciences); Annex C, Healthcare and Life Sciences, ""National frameworks and governance"" and ""International alignment""; Section 3.3.2 (Control Framework); Annex A (Alignment with European Legal and Policy Frameworks). Comment / Suggestion: Add Regulation (EU) 2017/745 on medical devices (MDR) and Regulation (EU) 2017/746 on in vitro diagnostic medical devices (IVDR) to Annex A and to the Healthcare pillar’s governance provisions. State explicitly that AI intended for diagnosis, triage, treatment decision support or patient risk stratification is regulated as a medical device, that CE marking under the MDR is a precondition of clinical deployment, and that EU AI Act obligations attach on top of that classification (and not in place of it). Require that every AI initiative in the Healthcare pillar carries a documented regulatory classification at the point it enters the national portfolio. If medical device are introduced, there should be clear documentation about its class and conformity assessment route. Justification: Under Rule 11 of Annex VIII to the MDR, software intended to provide information used to take decisions for diagnostic or therapeutic purposes is (at minimum) Class IIa. This rises to Class IIb where the decision may cause serious deterioration or require surgical intervention, and reaches Class III where it may cause death or irreversible deterioration. Applying that rule to the Strategy’s own intended infrastructures: (i) Intelligent Patient Triage and Care Navigation, which routes patients to care pathways including emergency services on the basis of clinical urgency, is not a low class device; (ii) Virtual AI Patient Orchestrator, which performs symptom reporting, risk alerts and referral, is also a medical device; (iii) the Socratic scaffolding will also be designing medical device diagnostic AI. Medical devices of Class IIa and above cannot be placed on the market without a notified body (self-declaration is not possible)." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",pjdoolan1,"SUBMISSION TO THE PUBLIC CONSULTATION ON THE NATIONAL AI STRATEGY OF THE REPUBLIC OF CYPRUS 2032 Comments on the Healthcare and Life Sciences pillar Submitted by: German Medical Institute (GMI), Limassol, Cyprus Date: 27/08/2026 About the submitter The German Medical Institute is a hospital in Limassol and one of three Cypriot member organisations of the European Network of AI-Powered Advanced Screening Centres, convened by the Artificial Intelligence in Health and Life Sciences unit of the European Commission's DG CNECT, alongside the State Health Services Organisation with the University of Cyprus, and the Bank of Cyprus Oncology Centre. On 11 May 2026 we presented our clinical AI deployment methodology to that network. We set out the following because several of the comments below rest on it: • GMI completed full hospital digitisation at the end of 2026. • Eight AI tools are in routine clinical use across radiotherapy, MRI, X-ray, nuclear medicine, dermatology and clinical document workflows, with further deployments in progress. • Every deployment follows a structured lifecycle that includes a local retrospective evaluation on our own patients, our own images and our own clinicians’ reports before any clinical use. • GMI is a partner in EU-funded work on the European Electronic Health Record Exchange Format (EEHRxF) and on cancer research data infrastructure under Horizon Mission Cancer. Declaration of interest. Through the GMI Innovation Centre we provide clinical validation and EU market-entry pathway support to international health-AI developers. This currently spans six programmes with developers in India, the United States, France and South Korea. We would therefore have an interest in national work of this kind, and several recommendations below, if adopted, would create opportunities for which we and other Cypriot institutions would be candidates. We make them because we consider the underlying gaps material, and we have stated at the end of this submission what we are offering without charge and what we are not. General remarks The Healthcare and Life Sciences pillar identifies the problems well: fragmented data, capacity pressure, and the need for clinical decision support that augments rather than displaces clinical judgement. The commitments to HL7 FHIR, SNOMED CT and ICD, to European Health Data Space principles, to independent Data Access Committees, and to monitoring for bias and model drift are the correct foundations. Our comments address one structural gap and seven consequences of it. The gap is that the Strategy governs healthcare AI almost entirely through the lens of the EU AI Act, which is mentioned throughout, and does not mention the Medical Device Regulation. For clinical AI, the Medical Device Regulation is the first step and the AI Act applies on top of it, not instead of it. Most of the flagship initiatives described in the Healthcare pillar are medical devices and thus the national programme should account for this." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","George Melillos","ΣΧΟΛΙΑ ΕΠΙ ΤΗΣ ΕΘΝΙΚΗΣ ΣΤΡΑΤΗΓΙΚΗΣ ΤΕΧΝΗΤΗΣ ΝΟΗΜΟΣΥΝΗΣ 2032 1. Τεχνική ανακρίβεια στο ISO/IEC 42001 Σε δύο τουλάχιστον σημεία (ενότητες 3.13.1 και 3.11.2), η Στρατηγική παρουσιάζει το ISO/IEC 42001 ως πρότυπο διαχείρισης κινδύνου (risk management). Δεν είναι. Το ISO/IEC 42001 αφορά το Σύστημα Διαχείρισης ΤΝ (AI Management System – AIMS), ενώ το ISO/IEC 23894 παρέχει καθοδήγηση ειδικά για τη διαχείριση κινδύνων ΤΝ (AI risk management). Η διάκριση είναι σημαντική και θα πρέπει να αποτυπωθεί σωστά στην τελική Στρατηγική. 2. Η ήδη υπάρχουσα ΤΝ παραμένει αόρατη Ο AI Use Case Lifecycle (Annex B) και το AIREG δίνουν έμφαση κυρίως στη διακυβέρνηση και καταγραφή νέων ή υπό ανάπτυξη συστημάτων. Χρειάζεται όμως σαφέστερη πρόβλεψη και για την ΤΝ που ήδη χρησιμοποιείται, συχνά ενσωματωμένη σε ERP, CRM, SaaS ή διαδικασίες αυτοματοποιημένης λήψης αποφάσεων. Προτείνεται ένα συνεχώς ενημερωμένο μητρώο για όλα τα συστήματα ΤΝ στον δημόσιο τομέα, περιλαμβανομένων third-party και embedded AI, με σαφή καταγραφή του υπεύθυνου, του σκοπού χρήσης, του provider/model και του επιπέδου κινδύνου και αυτονομίας. Διαφορετικά, υπάρχει κίνδυνος να δημιουργήσουμε ένα ισχυρό πλαίσιο για το AI που έρχεται, χωρίς πλήρη εικόνα του AI που ήδη χρησιμοποιείται. 3. Το Agentic AI χρειάζεται δικό του governance layer Η Στρατηγική αναφέρεται σε agentic AI, multi-agent systems, A2A, MCP και OASF, χωρίς όμως να ορίζει επαρκώς τι επιτρέπεται να κάνει ένα τέτοιο σύστημα. Χρειάζονται σαφείς κανόνες για permissions, tool access, memory, logging, human override και safe termination. Το Control Framework (Annex B) χρειάζεται να επεκταθεί ώστε να καλύπτει συστήματα που αναθέτουν υπο-εργασίες και εκτελούν ενέργειες αυτόνομα. Σε εφαρμογές όπως AI Judge, Virtual Patient Orchestrator ή agentic copilots στη ναυτιλία, το κρίσιμο ερώτημα δεν είναι μόνο «τι παράγει το σύστημα», αλλά «τι του επιτρέπεται να κάνει». 4. Ο AI Officer δεν μπορεί να είναι ταυτόχρονα υλοποιητής και ελεγκτής Το Annex E αναθέτει στον AI Officer αρμοδιότητες τόσο στην υλοποίηση όσο και στη διαχείριση κινδύνου. Αυτό δημιουργεί πιθανή σύγκρουση ρόλων. Η υλοποίηση και η ανεξάρτητη αξιολόγηση ενός συστήματος θα πρέπει να παραμένουν διακριτές λειτουργίες, ώστε να αποφεύγεται πιθανή σύγκρουση συμφερόντων. Παράλληλα, η αναφορά ότι «deep technical expertise is not always required» χρειάζεται επανεξέταση, ιδιαίτερα για συστήματα υψηλού κινδύνου κατά το EU AI Act. Χρειάζεται ελάχιστο competency framework ανά επίπεδο κινδύνου, διαφανής διαδικασία επιλογής και, όπου υπάρχει ήδη η απαιτούμενη τεχνογνωσία στον δημόσιο τομέα, αξιοποίηση υφιστάμενου προσωπικού χωρίς κατ' ανάγκη δημιουργία νέων θέσεων. 5. Το human oversight χρειάζεται ορισμό στην πράξη και ανεξάρτητο έλεγχο για κρίσιμα συστήματα Η Στρατηγική δίνει σωστά έμφαση στο human oversight, χωρίς όμως να ορίζει πότε αυτό είναι ουσιαστικό στην πράξη. Ο άνθρωπος που φέρει την ευθύνη πρέπει να έχει τη γνώση, την πληροφόρηση, τον χρόνο και κυρίως την εξουσία να αμφισβητήσει, να ανατρέψει ή να σταματήσει μια ενέργεια του συστήματος. Διαφορετικά, το oversight κινδυνεύει να παραμείνει τυπικό. Για critical ή high-impact συστήματα, θα πρέπει επίσης να προβλέπεται ανεξάρτητη αξιολόγηση, ώστε ο έλεγχος να μην εξαρτάται αποκλειστικά από τον προμηθευτή ή τον φορέα υλοποίησης. 6. Ετοιμότητα για σημαντικά πιο προηγμένα συστήματα ΤΝ στον ορίζοντα του 2032 Η ενότητα 3.13.4 αναφέρεται σε «mechanisms to adapt», χωρίς όμως να καθορίζει συγκεκριμένους μηχανισμούς για σημαντικές αλλαγές στις δυνατότητες της ΤΝ. Δεν χρειάζεται η Στρατηγική να προβλέψει αν ή πότε θα υπάρξει AGI. Με ορίζοντα όμως το 2032, χρειάζεται να είναι έτοιμη για σημαντικά πιο ικανά ή αυτόνομα συστήματα. Προτείνεται capability-triggered review, με προκαθορισμένα thresholds που θα ενεργοποιούν αναθεώρηση όταν μεταβάλλονται ουσιαστικά οι δυνατότητες ή η αυτονομία των συστημάτων, όταν συμβαίνει σοβαρό AI incident ή όταν αλλάζει σημαντικά το regulatory environment. Ένας μόνο προγραμματισμένος κύκλος αναθεώρησης δεν αρκεί για μια τεχνολογία που εξελίσσεται με αυτή την ταχύτητα. 7. Εκπαίδευση: από τη χρήση της ΤΝ στην ανθρώπινη κρίση Το CALF, το EPVL και το Socratic Scaffolding κινούνται στη σωστή κατεύθυνση. Θα έδινα όμως μεγαλύτερη έμφαση στην ανθρώπινη αυτενέργεια (Human Agency). Δεν αρκεί ο μαθητής να γνωρίζει πώς να χρησιμοποιεί την ΤΝ ή να υπάρχει ένας εκπαιδευτικός ως φίλτρο. Πρέπει σταδιακά να μάθει ο ίδιος να ορίζει τον σκοπό, να καθοδηγεί το σύστημα, να ζητά τεκμήρια, να επαληθεύει πηγές, να αναγνωρίζει αβεβαιότητα και να αμφισβητεί ακόμη και μια πολύ πειστική απάντηση. Όσο καλύτερα γίνονται τα συστήματα ΤΝ, τόσο σημαντικότερη γίνεται αυτή η ικανότητα. Ο στόχος δεν πρέπει να είναι μόνο Human-in-the-loop, αλλά Human-in-command: ο μαθητής να μπορεί να χρησιμοποιεί την ΤΝ χωρίς να της παραδίδει την κρίση του. Αυτή είναι δεξιότητα που θα παραμείνει σημαντική ανεξάρτητα από τα μοντέλα και τις τεχνολογίες που θα υπάρχουν το 2032. 8. Τα KPIs δεν μπορούν να παραμείνουν «sample» Το Annex F χαρακτηρίζει το πλαίσιο των KPIs ως «sample». Αυτό χρειάζεται αλλαγή. Όταν η Στρατηγική θέτει συγκεκριμένους στόχους, όπως 75% AI adoption ή 10–20% μείωση κατανάλωσης καυσίμων στη ναυτιλία, πρέπει να είναι εξίσου συγκεκριμένος και ο τρόπος μέτρησής τους. Κάθε βασικό KPI χρειάζεται baseline, σαφή μεθοδολογία μέτρησης, υπεύθυνο φορέα και ετήσια δημόσια αναφορά προόδου. Διαφορετικά, στο τέλος θα γνωρίζουμε τους στόχους που τέθηκαν, αλλά όχι με αντικειμενικό τρόπο αν επιτεύχθηκαν. Η ευελιξία είναι χρήσιμη στην υλοποίηση, όχι στη λογοδοσία. 9. Vendor lock-in και digital sovereignty Η Στρατηγική μιλά για digital sovereignty. Στην πράξη, όμως, το Δημόσιο πρέπει να μπορεί να αλλάξει AI provider χωρίς να εγκλωβίζεται σε μία εταιρεία ή πλατφόρμα. Χρειάζονται σαφείς απαιτήσεις για portability, interoperability και vendor exit, ώστε δεδομένα, μοντέλα και κρίσιμες λειτουργίες να μπορούν, όπου είναι τεχνικά εφικτό, να μεταφερθούν σε άλλον πάροχο. Για μια μικρή αγορά, η εξάρτηση από έναν πάροχο χωρίς πρακτική δυνατότητα εξόδου αποτελεί στρατηγικό κίνδυνο. 10. Το «augment, not replace» πρέπει να μπορεί να μετρηθεί Η αρχή «augment, not replace» είναι σωστή ως κατεύθυνση, αλλά χρειάζεται μηχανισμό παρακολούθησης. Θα πρέπει να καταγράφεται ανά τομέα ποιες θέσεις ή καθήκοντα επηρεάζονται από την ΤΝ και πόσοι εργαζόμενοι επανακαταρτίζονται (re-skilling) ή μετακινούνται σε νέους ρόλους. Δεν αρκεί να λέμε ότι η ΤΝ θα ενισχύσει τον άνθρωπο. Πρέπει να μπορούμε και να το αποδεικνύουμε. 11. Κάθε δημόσιος οργανισμός που χρησιμοποιεί ΤΝ πρέπει να έχει δική του AI Policy Η Στρατηγική θα ήταν χρήσιμο να προβλέπει ότι κάθε δημόσιος οργανισμός που αναπτύσσει ή χρησιμοποιεί ΤΝ διαθέτει γραπτή AI Policy. Η πολιτική αυτή πρέπει να καθορίζει τουλάχιστον πού και για ποιο σκοπό επιτρέπεται η χρήση ΤΝ, ποια είναι τα όρια, ποιος έχει την ευθύνη και ποιος λογοδοτεί. Αυτό συνδέεται και με το ISO/IEC 42001, το οποίο η ίδια η Στρατηγική επικαλείται και προβλέπει documented AI Policy στο πλαίσιο ενός AI Management System. Χωρίς σαφή πολιτική σε επίπεδο οργανισμού, οι υπόλοιποι μηχανισμοί governance δεν έχουν κοινή βάση εφαρμογής. 12. Η ικανότητα κατεύθυνσης της ΤΝ χρειάζεται να ενταχθεί στις δεξιότητες Η Στρατηγική προβλέπει agentic AI, multi-agent systems και σύνθετες εφαρμογές ΤΝ σε κρίσιμους τομείς. Δεν δίνεται όμως αντίστοιχη έμφαση στην ικανότητα του ανθρώπου να κατευθύνει αποτελεσματικά αυτά τα συστήματα: να ορίζει σκοπό, να παρέχει το κατάλληλο context, να θέτει περιορισμούς και να αξιολογεί αν το αποτέλεσμα ανταποκρίνεται στην πρόθεσή του. Δεξιότητες όπως prompt engineering και context engineering, ανεξάρτητα από το πώς θα ονομάζονται στο μέλλον, θα πρέπει να ενταχθούν στα σχετικά εκπαιδευτικά και επαγγελματικά πλαίσια. Όσο πιο ικανά γίνονται τα συστήματα ΤΝ, τόσο πιο σημαντική γίνεται η ικανότητα του ανθρώπου να τους δίνει σωστή κατεύθυνση. 13. Η κυβερνοασφάλεια πρέπει να ενσωματωθεί στον κύκλο ζωής κάθε συστήματος ΤΝ Η Στρατηγική δίνει σημαντική έμφαση στην κυβερνοασφάλεια, αλλά χρειάζεται σαφέστερη σύνδεσή της με τον AI Use Case Lifecycle (Annex B). Κάθε σύστημα ΤΝ, ιδιαίτερα σε κρίσιμες λειτουργίες, θα πρέπει να περνά υποχρεωτικό security assessment πριν τεθεί σε παραγωγική λειτουργία και να επανελέγχεται όταν αλλάζει ουσιαστικά. Ιδιαίτερη πρόβλεψη χρειάζεται για agentic AI, όπου εμφανίζονται νέοι κίνδυνοι όπως prompt injection, tool poisoning και memory manipulation. Η κυβερνοασφάλεια δεν πρέπει να λειτουργεί παράλληλα με το AI governance, αλλά να αποτελεί μέρος του ίδιου του κύκλου ζωής του συστήματος." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",mtziakouris,"This comprehensive, cohesive, and ambitious strategic document captures the vision for the development, utilization, and responsible governance of Artificial Intelligence in Cyprus, aligning with European developments to establish a strong framework for digital transformation and public service upgrading. With the aim of further enhancing the effectiveness, implementability, and long-term sustainability of the Strategy with regard to the healthcare pillar, the following observations are submitted: The healthcare pillar should explicitly include the use of AI for fraud, waste and abuse detection, including anomalous claims identification, provider behavioural analytics, prescription abuse detection, organised fraud networks, and real-time risk scoring. These capabilities contribute directly to the financial sustainability of the healthcare system and the efficient use of public funds. The healthcare pillar should also be expanded to explicitly include AI for population health management, disease prevention, and healthcare system sustainability, including the identification of at-risk populations, healthcare demand forecasting, chronic disease management, and population health analytics. While the Strategy focuses on clinical care and research, AI can also play a significant role in improving population health outcomes, supporting evidence-based policymaking, and ensuring the long-term sustainability of the General Healthcare System through preventive and proactive interventions." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Minos Georgakis","The National AI Strategy sets an ambitious vision for Cyprus. To strengthen it further, the strategy should move from a vision-led document to an execution-led national programme. This means clearly defining how the vision will be achieved, who will execute it, how progress will be measured, what budget is required, and how public and private adoption will be stimulated. The most important enhancement is to separate the long-term 2032 ambition from the implementation plan. For AI, a static long-term execution plan is likely to become outdated quickly. A more appropriate approach is a three-year execution cycle for 2026-2028, refreshed annually and then formally renewed for the next cycle. The strategy should also include a measurable KPI scorecard, a clear delivery roadmap, a RACI-style ownership model, an indicative funding model, and explicit alignment with Cyprus’s Digital Decade and DESI-related performance indicators. 1. Section 1.5, “Implementation Timeline and Success Metrics” Suggestion: Introduce a rolling three-year implementation roadmap, supported by annual reviews and formal refresh points. Retain 2032 as the long-term national ambition, but divide implementation into shorter execution cycles. Each cycle should identify priority programmes, milestones, responsible entities, funding requirements, dependencies, expected benefits and measurable outcomes. The first cycle should concentrate on establishing governance, baseline indicators, procurement arrangements, enabling infrastructure, first-wave use cases and talent programmes. Justification: The strategy currently combines short implementation periods with a broad 2026 to 2032 national rollout. A fixed long-term plan may not provide sufficient flexibility for a field experiencing rapid technological, regulatory and market change. A rolling approach would allow Cyprus to adjust priorities based on implementation experience, emerging technologies, EU requirements, available funding and demonstrated use-case value. It would also provide clearer short-term accountability while maintaining continuity with the 2032 vision. The enhanced recommendation note similarly proposes a three-year execution cycle with annual refreshes rather than treating the full period as a static implementation plan 2. Section 3.3, “Governance and Controls” Suggestion: Include a detailed RACI and decision-rights model for the strategy’s governance and delivery bodies. For each major programme and control gate, the strategy should specify who is responsible for execution, accountable for the outcome, consulted before decisions and informed of progress. The model should cover the National AI Authority, the competent Deputy Ministry, the Interministerial AI Council, specialised committees, delivery bodies, ministries, regulators, municipalities, research institutions and private-sector participants. Justification: The strategy establishes a three-tier governance model and identifies the National AI Authority, Interministerial AI Council and specialised committees. A complementary RACI would clarify how these bodies interact in practice, particularly where policy, technology, funding, regulation and service ownership overlap. It would reduce ambiguous ownership, duplicated activity and delayed decisions. It would also make escalation arrangements clearer and enable authorities to hold specific entities accountable for milestones, risks, expenditure and benefits. 3. Section 3.4, “AI Adoption Across Government” Suggestion: Introduce a National AI Procurement Framework for all public-sector AI acquisitions and partnerships. The framework should contain model procurement documents, common technical and functional requirements, risk-based procurement routes, supplier evaluation criteria and standard clauses addressing data access, data residency, model transparency, auditability, cybersecurity, intellectual property, performance, portability, exit rights and vendor lock-in. It should also require relevant AI impact, data protection, security and value assessments before procurement approval. Justification: The strategy embeds compliance from the earliest stages of design, procurement and operation and calls for AI systems to be explainable, auditable, secure and resilient. A common procurement framework would apply these principles consistently across ministries and agencies rather than requiring each organisation to develop requirements independently. The previous recommendation note specifically identifies procurement discipline as important to avoiding fragmented, vendor-led adoption and inconsistent risk allocation. Standardisation would shorten preparation time, improve comparability of supplier proposals, strengthen contractual protection and support more consistent compliance across the public sector. 4. Section 3.4.4, “Shared Capabilities and Reuse” Suggestion: Create a Sovereign AI Marketplace for approved and reusable AI assets. The marketplace should operate as a controlled catalogue containing reusable AI models, agents, prompts, APIs, data products, reference architectures, procurement clauses, testing methods, compliance templates and assurance evidence. Each asset should have a named owner, approved use conditions, risk classification, version history, support model and maintenance responsibilities. Justification: The strategy promotes shared national capability, interoperability and reusable foundations, but an explicit marketplace would provide the mechanism through which reuse takes place. A controlled catalogue would support a “build once, reuse where appropriate” model, allowing ministries and potentially municipalities to adopt validated components rather than repeatedly procuring or developing similar solutions. The existing recommendation note proposes linking marketplace assets to the AI registry and compliance framework. This would reduce duplication, accelerate deployment, improve consistency and increase the return generated from public investment in AI components. 5. Section 3.11 and Annex F, “Measuring Impact and National KPIs” Suggestion: Convert the KPI framework into a National AI Performance Scorecard with complete measurement governance. Every KPI should contain a definition, baseline, annual target, data source, responsible owner, reporting frequency, calculation method, dependencies and escalation threshold. The scorecard should distinguish activity indicators, such as training delivered or pilots launched, from outcome indicators, such as service improvement, productivity, adoption, trust, investment and realised financial or societal benefits. Justification: The strategy identifies national impact, government and sector adoption, talent, trust and compliance as measurement areas and calls for regular monitoring and continuous improvement. The stated outcome metrics include productivity, GDP-related impact, professionals in the market and FDI attraction. A fully governed scorecard would make these indicators auditable and actionable. Clear baselines and ownership would show whether progress reflects actual improvement, while escalation thresholds would allow governance bodies to intervene when programmes are off track. 6. Section 5, “Immediate Steps for the Strategy Launch” Suggestion: Add an explicit funding envelope and benefits-realisation model to the launch actions. The Government should define indicative funding by programme category, expected funding sources, responsible budget holders, project-level business-case requirements and arrangements for EU and private co-investment where appropriate. Every major initiative should identify expected financial, service, productivity, resilience or societal benefits and explain how these will be measured after deployment. Justification: The strategy calls for multi-year investment with clear return-on-investment tracking and includes ambitious national outcomes. However, an explicit portfolio funding and benefits model would strengthen confidence that the ambition is financially and operationally deliverable. The supplementary recommendation note proposes identifying national-budget, EU co-funding and private co-investment opportunities and creating a benefits-realisation capability to track productivity, service quality and fiscal outcomes. This would support transparent prioritisation and allow funding to be directed to initiatives that demonstrate value. 7, Annex C, “Priority Sectors for Leadership” Suggestion: Include Local Government as a distinct AI adoption and citizen-impact stream. The stream should cover municipal service requests, local-language citizen assistance, urban planning, waste and resource management, infrastructure maintenance, licensing and smart-city services. Municipalities should receive common guidance, access to reusable marketplace assets, implementation support and a controlled pilot-to-scale pathway. Justification: Annex C concentrates on national priority sectors, while local authorities represent an important citizen-facing delivery layer. The existing recommendation note observes that municipalities can produce visible service improvements and proposes reusable solutions and selected pilots before wider scaling. A dedicated stream would reduce the likelihood of fragmented municipal procurements and unequal access to capability. It would also create opportunities to test practical, lower-complexity use cases close to citizens before considering broader adoption. 8. Sections 2.5.2, 2.5.3 and 3.5, “Productivity, Ecosystem and Priority Sectors” Suggestion: Define sector-specific private-sector AI adoption targets and introduce practical adoption incentives. Targets should reflect the maturity and circumstances of tourism, professional services, shipping, healthcare, financial services and other priority areas. Supporting measures could include adoption vouchers, grants, test-before-invest facilities, regulatory sandboxes, advisory support, compute credits and skills subsidies, with simplified pathways for SMEs. Justification: The strategy aims to increase national productivity and build an inclusive ecosystem in which SMEs and non-technology organisations can access AI capabilities, infrastructure and guidance. Explicit targets and incentives would convert this ambition into an investable adoption programme and make private-sector contribution to national outcomes measurable. The enhanced recommendation note specifically proposes grants, vouchers, tax incentives, sandboxes, advisory support, compute credits and skills subsidies. This would help address affordability, expertise and regulatory-readiness barriers, particularly for smaller organisations." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",yiannadanidou,"Η Στρατηγική συνολικά έιναι ένα αρκετά συνεκτικό και φιλόδοξο κείμενο, το οποίο καλύπτει ένα ευρύ φάσμα τομέων και πυλώνων. Το γεγονός ότι περιλαμβάνει πολλαπλές θεματικές διαστάσεις και επιχειρεί να συνδέσει την τεχνολογική ανάπτυξη με ζητήματα διακυβέρνησης, δεξιοτήτων, εκπαίδευσης, ασφάλειας, καινοτομίας και κοινωνικής διάστασης είναι θετικό στοιχείο. Ένα γενικό σχόλιο που θα μπορούσε να ληφθεί υπόψη, αφορά τη συνοχή ως προς τον τρόπο συγγραφής και παρουσίασης των επιμέρους ενοτήτων. Παρατηρείται ότι ορισμένες ενότητες βασίζονται σε μεγάλο βαθμό σε εκτεταμένα bullet points και πιο συνοπτική παράθεση θέσεων, ενώ άλλες είναι γραμμένες με περισσότερο αναλυτικό, επαγγελματικό και ακαδημαϊκά τεκμηριωμένο τρόπο. Θα ήταν σωστό, να υπάρξει μεγαλύτερη ομοιομορφία σε ολόκληρο το κείμενο και να υιοθετηθεί ως βασική προσέγγιση το δεύτερο στυλ, δηλαδή η πιο αναλυτική, συνεκτική και τεκμηριωμένη παρουσίαση. Αυτό θα ενίσχυε τη συνολική ποιότητα, την αναγνωσιμότητα και την αξιοπιστία της Στρατηγικής και θα της προσέδιδε πιο ενιαίο και επαγγελματικό χαρακτήρα. Τα ειδικότερα σχόλια και οι εισηγήσεις που ακολουθούν αφορούν κυρίως τις θεματικές της Εκπαίδευσης και της Ασφάλειας / Κυβερνοασφάλειας. Για λόγους συνέπειας με το ίδιο το κείμενο της Εθνικής Στρατηγικής, τα σχόλια παρατίθενται στην αγγλική γλώσσα, όπως είναι γραμμένη και η Στρατηγική. Section 3.6 – Talent, Skills and Workforce Transformation and Annex C – Education and Human Capital Development Comment / Suggestion: Introduce a dedicated framework for the responsible adoption and use of AI in Higher Education. The framework should address teaching and learning, assessment redesign, academic integrity, AI-assisted research, student data protection, institutional governance, and the professional development of academic staff. Justification of Comment / Suggestion: Although the Strategy refers to lifelong AI learning extending from early schooling to higher education and professional life, the more detailed educational framework focuses mainly on school-age learners, particularly through CALF, which is structured around the age groups 6–8, 9–12, 13–15 and 16–18. Higher Education Institutions face distinct challenges related to generative AI, including assessment validity, academic integrity, research practices, institutional governance, staff competencies and student data protection. A specific Higher Education component would therefore strengthen the completeness of the national education framework. Symeou, L., Louca, L., Kavadella, A., Mackay, J., Danidou, Y., & Raffay, V. (2025). Development of Evidence-Based Guidelines for the Integration of Generative AI in University Education Through a Multidisciplinary, Consensus-Based Approach. European Journal of Dental Education, 29(2), 285–303. https://doi.org/10.1111/EJE.13069 Annex C – Education and Human Capital Development – National Frameworks and Governance / CALF / EPVL Comment / Suggestion: Include specific provisions on assessment transformation and academic integrity in the age of generative AI. National guidance should address acceptable AI use in student work, disclosure of AI assistance, authorship, AI-supported assignments, authentic assessment, oral assessment, and mechanisms for maintaining academic integrity. Justification of Comment / Suggestion: The Strategy provides substantial guidance on AI literacy and teacher-mediated use of AI through CALF and EPVL, but does not sufficiently address how widespread generative AI use affects the validity and reliability of traditional assessment methods. Since assessment is a core component of educational quality assurance, national guidance would assist educational institutions in adapting assessment practices while enabling transparent and responsible AI use. Section 3.6 – Talent, Skills and Workforce Transformation and Annex C – Education and Human Capital Development Comment / Suggestion: Establish a structured national AI professional development programme for teachers and academic staff with measurable participation and competency targets. Training should include pedagogical integration of AI, critical evaluation of AI-generated outputs, bias and misinformation detection, data protection, cybersecurity, assessment redesign, accessibility, ethics and responsible AI use. Justification of Comment / Suggestion: The Strategy recognises educators as key actors in the responsible integration of AI and places teachers at the centre of the proposed EPVL model. However, successful implementation requires systematic and continuous professional development rather than general AI awareness alone. Measurable training targets and competency requirements would support consistent implementation across the education system. Section 3.6 – Talent, Skills and Workforce Transformation and Annex C – Education and Human Capital Development Comment / Suggestion: Clarify and strengthen the strategic role of universities and research organisations in the implementation of the education pillar. Their role could include contributing to CALF development, educator training, professional certification, evaluation of pilot initiatives, development of educational AI sandboxes, responsible AI research and independent assessment of educational outcomes. Justification of Comment / Suggestion: The Strategy promotes collaboration between government, academia and industry and recognises universities as part of the wider AI ecosystem. However, their operational role in the Education and Human Capital Development pillar could be defined more explicitly. Universities can provide research capacity, educational expertise, independent evaluation and specialised training, thereby supporting evidence-based implementation and continuous improvement. Annex C – Education and Human Capital Development – Cyprus AI Literacy Framework (CALF) Comment / Suggestion: Explicitly integrate AI-related cybersecurity and digital safety competencies into CALF across all age groups. These should include, at age-appropriate levels, AI-enabled phishing, social engineering, deepfakes, voice cloning, misinformation, synthetic media manipulation, protection of personal and sensitive information, safe prompting and responsible use of generative AI systems. Justification of Comment / Suggestion: CALF already incorporates safe use, bias awareness, verification habits, data rights and responsible experimentation across different age groups. However, AI-related cybersecurity threats are becoming increasingly relevant to children, young people and educators. Explicit inclusion of these competencies would create a stronger link between AI literacy, digital literacy and cybersecurity awareness and would better prepare learners to recognise and respond to AI-enabled threats. Annex C – Education and Human Capital Development – 2032 Adoption Target / KPIs Comment / Suggestion: Complement the proposed AI adoption target with outcome-based educational indicators. Suggested indicators include student AI literacy, educator AI competence, learning effectiveness, accessibility and inclusion, responsible AI use, number of AI-related misuse or safety incidents, equitable access and stakeholder trust. Justification of Comment / Suggestion: The Strategy proposes increasing AI adoption across education and labour to 75% by 2032. Adoption rates alone, however, do not demonstrate educational quality or positive learning outcomes. A broader KPI framework would ensure that increased use of AI is accompanied by measurable improvements in knowledge, skills, inclusion, safety and educational effectiveness. Section 3.13 – Risk Management, Resilience and Adaptation, particularly Section 3.13.3 – Security and Threat Management Comment / Suggestion: Develop a unified National AI Security Framework consolidating minimum technical and organisational cybersecurity requirements across the AI lifecycle. The framework should apply from design and procurement through development, deployment, operation, monitoring and decommissioning. Justification of Comment / Suggestion: The Strategy already addresses cybersecurity, secure system design, access controls, continuous monitoring, threat intelligence and incident response. However, relevant security provisions are distributed across several sections of the Strategy. A consolidated framework would provide organisations with a clear baseline of minimum security requirements and support consistent implementation across public and private sectors. Section 3.13.3 – Security and Threat Management and National AI Cybersecurity Centre of Excellence provisions Comment / Suggestion: Expand the AI threat model to explicitly address AI-specific cybersecurity threats. The Strategy could explicitly reference prompt injection, data poisoning, model poisoning, adversarial manipulation, model extraction, sensitive information leakage, insecure integrations, compromised AI supply chains and risks associated with autonomous or agentic AI systems. Justification of Comment / Suggestion: The Strategy appropriately recognises cyber threats, data breaches and model manipulation. Nevertheless, AI systems introduce attack vectors that differ from those affecting conventional information systems. Explicit recognition of these threats would enable more targeted security controls, testing requirements, incident-response capabilities and cybersecurity training. Danidou, Y. (2025). ChatGPT, a Life-Changing Phenomenon with Cyber-Security Implications. EU Digital Law in the AI Era, 263–291. https://doi.org/10.1007/978-3-031-96743-6_14 Section 3.3.2 – Control Framework and Section 3.13 – Risk Management, Resilience and Adaptation Comment / Suggestion: Introduce mandatory AI security testing for high-risk and critical AI systems before deployment and periodically thereafter. Such testing could include adversarial testing, AI red teaming, vulnerability assessment, penetration testing of the wider AI-enabled environment and documented remediation of identified weaknesses. Justification of Comment / Suggestion: The Strategy already establishes risk-based controls, approval gates, ongoing monitoring, security guardrails, incident reporting and remediation. Explicitly requiring security testing and red teaming for high-risk or critical AI systems would operationalise the Strategy’s security-by-design principle and provide stronger assurance before systems are deployed in sensitive environments. Section 3.12 – International Cooperation and EU Alignment, Section 3.13 – Risk Management, and relevant compliance provisions Comment / Suggestion: Strengthen the operational integration between the EU AI Act and cybersecurity-related regulatory frameworks, particularly NIS2, DORA and the Cyber Resilience Act. The Strategy could promote common mechanisms for risk assessment, incident management, assurance, governance and reporting where organisations are subject to multiple regulatory frameworks. Justification of Comment / Suggestion: The Strategy explicitly references the EU AI Act, GDPR, NIS2 and DORA. However, organisations in regulated and critical sectors may need to comply simultaneously with several frameworks. Greater operational alignment would reduce duplication, support regulatory consistency and help organisations establish integrated governance and compliance mechanisms. This should be addressed with the cooperation of the Digital Security Authority (DSA) of Cyprus and professionals in the cybersecurity/ NIS2/ DORA area. Section 3.7 – Infrastructure, Compute and Digital Sovereignty, Section 3.3.2 – Control Framework, and procurement-related provisions Comment / Suggestion: Introduce a dedicated third-party and AI supply-chain risk management approach. Requirements should cover foundation models, cloud AI services, APIs, open-source components and external AI providers, including supplier security assurance, data location, access to logs, vulnerability disclosure, incident notification, model changes and updates, portability and exit strategies. Justification of Comment / Suggestion: National AI adoption will inevitably depend to some extent on external technologies, cloud providers, foundation models and software components. These dependencies create security, resilience, sovereignty and continuity risks. A specific third-party AI risk framework would complement the Strategy’s emphasis on sovereign capability and secure infrastructure and would strengthen procurement and lifecycle governance. Section 3.11.2 – National Key Performance Indicators Comment / Suggestion: Include specific national AI cybersecurity KPIs in addition to general compliance and trust indicators. These could include the percentage of high-risk AI systems security-assessed before deployment, the percentage of critical AI systems subjected to red teaming, the number and severity of AI-related security incidents, mean detection and response times, the percentage of critical AI suppliers security-assessed, and the number of professionals trained or certified in AI cybersecurity. Justification of Comment / Suggestion: The Strategy already provides national KPIs covering adoption, productivity, skills, compliance, trust and public confidence and recommends ISO 42001/ISO 27001 for relevant systems. However, cybersecurity maturity cannot be adequately measured solely through general compliance indicators. Dedicated cybersecurity KPIs would allow progress to be monitored objectively and would support evidence-based improvement of national AI security capabilities. Section 3.6 – Talent, Skills and Workforce Transformation, Annex C – Education and Human Capital Development, and Section 3.13 – Risk Management, Resilience and Adaptation Comment / Suggestion: Strengthen the intersection between Education and Cybersecurity by establishing AI security literacy as a horizontal national competence. Citizens, students, educators, public servants and professionals should be equipped not only to use AI effectively and ethically, but also to recognise and respond to AI-enabled cyber threats, deepfakes, social engineering, misinformation, privacy risks and unsafe handling of sensitive information. Justification of Comment / Suggestion: The Strategy develops strong but largely parallel provisions for AI literacy and AI cybersecurity. Connecting these areas more explicitly would strengthen societal resilience and ensure that the expansion of AI adoption is accompanied by corresponding growth in the population’s ability to use AI securely and responsibly. This would also support the Strategy’s broader objectives relating to trust, resilience, human-centred AI and responsible adoption." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",gmmilis,"General Comments I would like to acknowledge the considerable work that has gone into preparing the draft Cyprus National AI Strategy 2032. The Strategy is ambitious and, importantly, recognises that successful AI adoption depends not only on technology, but on the data, institutional, governance and human capabilities required to deploy AI responsibly and at scale. Several elements are particularly strong. The emphasis on data as a strategic national asset, interoperability, secure data sharing and reusable digital infrastructure provides the right foundation for scaled adoption. The principles of “build once, reuse everywhere”, the need for measurable value, and scaling only where impact is demonstrated are also important, particularly given the Strategy’s own recognition of the risk of fragmented pilots and “AI theatre”. The Strategy also rightly recognises the need for AI adoption with productivity, public-sector transformation, skills, research, innovation and responsible governance, rather than treating AI as a standalone technology policy. The main challenge for the final Strategy is therefore not to add further ambition, but to translate the existing ambition into a smaller number of clearly prioritised and sequenced actions, with defined ownership, dependencies, potential funding sources, implementation milestones and practically measurable outcomes. For Cyprus, this is particularly important. Its advantage is unlikely to come from competing with larger economies on the scale of AI investment or compute capacity. It can, however, benefit from its relatively compact ecosystem to coordinate quickly, improve interoperability, test solutions in real operating environments and scale successful applications more rapidly. The following comments therefore focus primarily on prioritisation, implementation readiness, measurability and governance, with the objective of strengthening the Strategy’s ability to move from ambition to sustained execution. 1. Prioritise national foundations and critical domains before broader international positioning Article / Section: Sections 1.3 “Priority Sectors for Leadership”, 1.4 “The Strategic Gap and the Implementation Approach”, 1.6 “A Narrow Window”, 2.3 “The Strategic Choice Alignment for the Way Forward”, 2.4 “The Vision: Where Cyprus Will Lead”, and 2.4.1 “Priority Sectors for Leadership” Comment / Suggestion The Strategy would benefit from a clearer hierarchy and sequencing of priorities. In the first phase of implementation, priority should be given to establishing the fundamental capabilities required for effective AI adoption in Cyprus, particularly data quality and governance, interoperability, appropriate digital infrastructure, organisational capability, skills, procurement and effective implementation mechanisms. At the same time, the definition of “priority sectors” should be reconsidered. The current approach appears to place significant emphasis on contribution to GDP and exposure to AI-driven productivity gains. These are important criteria, but they should not be the only determinants of national priority. The Strategy should distinguish more clearly between: 1. foundational and nationally critical domains, where resilience and effective operation are prerequisites for the wider economy and society, 2. sectors where AI adoption can generate significant productivity, service-quality or societal improvements, and 3. a smaller number of areas where Cyprus has a credible basis for developing internationally competitive and exportable AI capabilities. Under the first category, consideration should be given to areas such as water, energy and electricity, transport and mobility, and the built environment/critical infrastructure. Their importance should not be assessed primarily through their direct contribution to GDP, as their effective functioning underpins economic activity, resilience, quality of life and the operation of virtually every other priority sector. Similarly, the ambition for Cyprus to become a trusted regional AI hub can provide useful long-term direction, but should be treated primarily as a potential outcome of successful implementation, rather than as a near-term objective that drives resource allocation. A possible sequencing principle would therefore be: foundations and critical national needs first → proven adoption and scaling second → international positioning and specialisation third. Progression should be based on demonstrated readiness and measurable results rather than ambition alone. If the concept of Cyprus as a “trusted regional AI hub” remains a central strategic ambition, the final Strategy should also define what this means in practical and measurable terms. The relevant capabilities and indicators may already be reflected across different parts of the Strategy, but they are not sufficiently consolidated around this central ambition. A limited set of characteristics and measurable outcomes should therefore define what would constitute success and, importantly, what would differentiate Cyprus from other European and regional jurisdictions. Such differentiation is more likely to arise from Cyprus's ability to provide a fast, trusted and well-coordinated environment for AI adoption, validation and deployment than from competing with larger economies on absolute scale of compute, hardware or capital. Justification The Strategy itself identifies important structural gaps that currently constrain AI adoption: fragmented institutional data and compute resources, immature data governance, limited AI-grade compute, shortages of specialised AI skills and limited applied AI experience within ministries and regulators. It also explicitly identifies the risk of “AI theatre”, where significant experimentation produces limited operational impact. These observations suggest that Cyprus's immediate strategic challenge is primarily one of building foundations, execution readiness and institutional capability. At the same time, the Strategy identifies priority sectors largely on the basis of their contribution to national GDP and exposure to AI-driven transformation and productivity gains. The resulting list includes Government, Financial Services, Healthcare, Tourism, Legal Services, Education, Shipping and Entrepreneurship and Innovation. While these are clearly important areas for AI adoption, economic contribution alone does not capture national criticality or systemic dependency. For example, water, electricity and energy systems, transport and other critical infrastructures may not necessarily be selected on the basis of their direct GDP contribution, yet weaknesses in these systems can constrain the entire economy and the wider AI ecosystem. The Strategy itself recognises, for example, that access to competitive and sustainable energy resources is important for Cyprus's attractiveness for digital infrastructure investment. There is also an important distinction between national priority and international leadership. A domain may be strategically important because AI can materially improve Cyprus's resilience, productivity or quality of public services without implying that Cyprus should seek to become an international AI leader in that domain. Conversely, international specialisation should be pursued selectively where Cyprus can demonstrate a credible comparative advantage. Against this background, statements such as that the “only strategic choice” is for Cyprus to become an Eastern Mediterranean AI hub appear stronger than the underlying analysis currently supports. Becoming a recognised regional AI hub would be a welcome consequence of successful implementation, but the more immediate objective should be to make AI work effectively for Cyprus, address critical national needs and demonstrate measurable economic and societal value. For a country of Cyprus's scale, disciplined sequencing can itself become a competitive advantage: establish the foundations, demonstrate successful applications, scale what works, and build international positioning on the basis of proven capability and results. 2. Strengthen prioritisation, sequencing and timeline realism through a single implementation roadmap Article / Section: Section 1.5 “Implementation Timeline and Success Metrics”, Chapter 3 “Strategic Implementation Approach”, Chapter 4 “AI Adoption and Strategic Enablers”, and Chapter 5 “Immediate Steps for the Strategy Launch” Comment / Suggestion The Strategy should be complemented by a consolidated implementation roadmap that identifies, for each major initiative: accountable owner; implementation period; dependencies; indicative implementation and recurring cost; funding source; baseline; measurable target outcome; interim milestones; and criteria for continuation, redesign, scaling or termination. The proposed implementation timeline should also be reviewed for feasibility. The use of broad phases such as 0-6 months, 6-12 months and subsequent periods provides useful direction, but several actions depend on institutional, procurement, data, infrastructure, legislative or capability prerequisites that may themselves require significant time to establish. The timeline should therefore be based on realistic delivery estimates and explicit dependencies, rather than on uniform implementation windows. The roadmap should clearly distinguish between foundational capabilities, such as data governance, interoperability, infrastructure, procurement capability and workforce readiness, and value-generating applications. Dependencies should be explicit so that initiatives are undertaken in the correct sequence. Justification The Strategy includes a substantial number of proposed actions across infrastructure, governance, Centres of Excellence, data, skills, innovation, compliance mechanisms and sectoral programmes. This breadth creates execution risk if initiatives are launched concurrently without sufficient consideration of implementation capacity and critical-path dependencies. In particular, some actions presented within relatively short implementation windows may require prior decisions on governance, staffing and funding; procurement or contracting; access to and preparation of data; integration with existing systems; development of standards; or coordination across multiple public bodies. A six-month target may therefore be realistic for initiating or designing an intervention, but not necessarily for establishing it as an operational and effective national capability. The roadmap should therefore distinguish, where appropriate, between decision/design, establishment, pilot, operational deployment and scale-up, rather than treating an initiative as a single milestone. A consolidated and realistically phased implementation roadmap would provide the bridge between Strategy and execution and allow leadership to understand which actions are critical-path dependencies, which can proceed in parallel and which should only commence once the necessary foundations have been demonstrated. 3. Make the National Strategic Objectives more specific and measurable Article / Section: Sections 1.2 “The National Strategic Objectives and Priority Sectors”, 2.5 “National Strategic Objectives”, 3.11 “Measuring Impact and National KPIs”, Annex C and Annex F Comment / Suggestion The eight National Strategic Objectives are generally broad and directional rather than specific and measurable objectives. Concepts such as a “trusted jurisdiction”, “strong and inclusive AI ecosystem” or “sovereign capability” provide strategic direction, but do not by themselves define what success should look like by 2032. The Strategy does provide considerably more detail elsewhere, particularly through the sector-specific initiatives and KPIs in Annex C and the measurement framework in Annex F. However, the link back to each National Strategic Objective is not always clear. It is suggested that each objective be linked directly to a small number of defined 2032 outcomes, intermediate milestones, key initiatives, measurable KPIs and accountable owners, for example: Strategic Objective → 2032 Outcome → Key Initiatives → Milestones → KPIs → Owner This would not require adding further initiatives, but rather organising and, where necessary, completing the existing information into a clear delivery framework. Justification The National Strategic Objectives are intended to provide a common reference point for policy, investment and delivery. For this purpose, they should be sufficiently specific to allow progress and accountability to be assessed. While Annex C provides further sector-level detail and Annex F introduces an outcomes-focused measurement framework, Annex F itself is described as indicative and adaptive. The Strategy therefore contains many of the necessary components, but the roadmap connecting the high-level objectives to concrete delivery and measurable results is not sufficiently explicit. Strengthening this connection would make the Strategy more actionable and make it easier to determine, throughout implementation, whether each National Strategic Objective is actually being achieved. 4. Strengthen the KPI framework and distinguish measurable targets from ambitions and scenarios Article / Section: Section 1.5 “Implementation Timeline and Success Metrics”, Section 2.5 “National Strategic Objectives”, Section 3.11 “Measuring Impact and National KPIs”, Annex C and Annex F “National KPIs and Measurement Framework” Comment / Suggestion The Strategy rightly places strong emphasis on measurable outcomes. However, the KPI framework should be strengthened to ensure that the measures presented as targets are specific, measurable and supported by a credible implementation pathway. Each core KPI should, as a minimum, specify: baseline → target → measurement methodology/data source → accountable owner → reporting frequency → target date. At Strategy level, priority should be given to a limited number of outcome and impact KPIs, rather than primarily measuring activities or outputs. The final Strategy should also distinguish clearly between: • committed and measurable targets, • strategic ambitions, and • scenario-based estimates or potential impacts. Where a baseline, measurement methodology or credible attribution to the Strategy cannot yet be established, the figure should not be presented as a committed KPI. Justification The Strategy itself states that AI should deliver “demonstrable public and economic value, rather than activity without outcomes” and that national KPIs should be clear, comparable and actionable. This is a strong principle. At the same time, the Strategy contains ambitious quantitative statements relating, among others, to productivity improvement, AI adoption, high-skilled employment, workforce positioning and reductions in citizen waiting times. Some may be appropriate targets; others may be better understood as ambitions or potential scenarios. The distinction is important. For example, a national productivity target requires a defined baseline, measurement methodology, expected sectoral contributions and a credible link between the interventions under the Strategy and the resulting productivity improvement. Without this, it will be difficult to determine how much of any observed change can reasonably be attributed to the Strategy. This creates a significant implementation and accountability risk: if success is not defined and measured consistently from the outset, progress may ultimately be assessed on activity rather than results, despite the Strategy's stated intention to do the opposite. A smaller number of robust, measurable and defensible KPIs would therefore provide a stronger basis for implementation and accountability than a larger set of ambitious but difficult-to-measure targets. 5. Significantly simplify the governance model and build implementation capacity within existing structures Article / Section: Sections 1.4.3 “Governance and Accountability”, 3.3 “Governance and Controls”, particularly 3.3.1 “Governance Structure”, and Annex E “AI Officers” Comment / Suggestion The proposed governance architecture should be significantly simplified, taking into account the size of Cyprus and the need for fast and accountable implementation. Rather than establishing multiple new permanent governance and delivery structures, consideration should be given to a leaner model centred on: • DMRID, with a properly resourced and highly skilled central AI team responsible for coordinating implementation, monitoring progress, establishing common standards and capabilities, and reporting against the Strategy; • the National AI Taskforce, continuing to provide expert strategic and technical advice and challenge; • a clearly designated and appropriately skilled AI focal point/officer within each Ministry and major public organisation, responsible for local implementation and coordination with the central team; and • existing competent regulatory and specialist authorities retaining responsibility within their established mandates. Additional committees or structures should be created only where there is a clearly demonstrated function that cannot be performed effectively within this model. The same principle should apply beyond governance bodies to the proposed Centres of Excellence, hubs, observatories, programmes and other new institutional mechanisms. Before establishing a new structure, the implementation plan should demonstrate the specific capability gap it addresses, why that function cannot be delivered through an existing institution or programme, the resources required to sustain it, and how its contribution to the Strategy will be measured. The objective should be to build capability, rather than institutional complexity. Justification The Strategy currently envisages a National AI Authority, Interministerial AI Council, National AI Taskforce, National AI Infrastructure Council, National Ethics and Values Committee, National AI Misinformation and Security Council, National AI Skills Observatory, Government Innovation Hub, Industrial Centre of Excellence, National AI Cybersecurity Centre of Excellence, AI Officers and AI Champions. While the functions addressed are individually relevant, the combined architecture appears disproportionately complex for the scale of the Cypriot public administration. There is a risk that the governance mechanism itself becomes an implementation challenge, creating overlapping mandates, additional interfaces, diffused accountability and slower decision-making. Moreover, the Strategy already provides much of the basis for a simpler model. It states that ministries and public bodies should retain responsibility for AI adoption and that initiatives should be embedded within existing policy, operational and accountability structures. The objective should therefore be to strengthen implementation capacity within existing institutional structures wherever possible, rather than create a parallel, potentially disconnected AI administration. For a small country, simplicity, clarity of ownership and speed of decision-making should themselves be considered governance design principles. 6. Prioritise practical public-sector capability and reusable foundations before advanced or “moonshot” use cases Article / Section: Sections 3.4 “AI Adoption Across Government”, 4.2 “AI Infrastructure Enablers”, 4.4 “AI Adoption Enablers”, and relevant use cases in Annex C Comment / Suggestion The public-sector AI programme should initially concentrate on a small number of high-value, feasible and reusable applications, supported by common data and technology foundations, before progressing to more advanced or speculative applications. Priority should be given to use cases that: address a clearly defined existing problem; use data that is already available or can realistically be made available; can demonstrate measurable improvements in cost, processing time, service quality or productivity; have manageable implementation and regulatory risk; and create capabilities that can subsequently be reused across government. Advanced “moonshots” should remain part of the longer-term innovation pipeline but should not compete for implementation resources with the foundational transformation required first. Justification The Strategy already contains the very strong principles of “Build Once, Reuse Everywhere” and a “Value-First Portfolio”, and proposes selecting six moonshots from sixteen flagship transformation programmes. These principles should be applied even more rigorously. Given the uneven level of organisational and data maturity identified elsewhere in the Strategy, early success is likely to come from solving concrete operational problems and creating reusable capabilities rather than pursuing the most technologically sophisticated applications first. The objective during the initial implementation period should be to demonstrate that AI can deliver tangible, measurable improvements in actual government operations. Successful solutions can then be scaled and more ambitious use cases pursued as the underlying capability matures. This would also provide practical evidence, institutional experience and public confidence upon which the Strategy's longer-term ambitions can be built. 7. Use needs-based terminology for vulnerable groups rather than demographic proxies Article / Section: Relevant references in the Strategy to pensioners, older persons or other demographic groups in the context of digital inclusion, AI literacy, accessibility and citizen services; Section 3.6 “Talent, Skills and Workforce Transformation” where applicable. Comment / Suggestion Where the Strategy seeks to identify citizens who may require additional support to access AI-enabled or digital services, it is suggested that it consistently use terminology such as “vulnerable groups”, “persons at risk of digital exclusion” or “persons requiring additional accessibility or digital support”, rather than referring to pensioners or people with disabilities alone. Where useful, the Strategy can identify specific factors contributing to vulnerability or exclusion, such as digital literacy, disability, socioeconomic circumstances, language barriers or limited access to technology. Justification Age or pensioner status does not, by itself, determine digital capability or vulnerability. Conversely, people in younger age groups may face significant barriers to accessing digital or AI-enabled services. A needs-based definition is therefore more accurate, inclusive and useful for policy design. Indeed, the Strategy itself already uses the broader formulation “citizens in vulnerable or disadvantaged circumstances” in the FutureAI CY programme. Applying this approach consistently would avoid unnecessary demographic assumptions and allow interventions to be targeted according to actual need. It would also reinforce an important principle for the digitalisation of public services: AI-enabled channels should improve accessibility and inclusion, while appropriate alternative channels and support should remain available for people who require them." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Demetris Kyriacou","### 1. Εθνική AI Literacy για όλους τους φοιτητές και φοιτήτριες **Αριθμός άρθρου/εδαφίου αναφοράς:** *Education and Human Capital Development – Context and ambition / Strategic objectives and 2032 target*, σελ. 77–78. Ειδικότερα, η Στρατηγική αναφέρει ως βασική κατεύθυνση τη δημιουργία μιας «AI-literate» Κύπρου, καθώς και τη δια βίου εκπαίδευση στην AI από την πρωτοβάθμια εκπαίδευση μέχρι την ανώτατη εκπαίδευση και την επαγγελματική ζωή. **Εισήγηση:** Προτείνω τη δημιουργία ενός εθνικού πλαισίου βασικής AI Literacy για όλους τους φοιτητές και τις φοιτήτριες των κυπριακών πανεπιστημίων, ανεξαρτήτως κλάδου σπουδών. Η AI δεν θα πρέπει να αντιμετωπίζεται ως δεξιότητα που αφορά αποκλειστικά τους φοιτητές Πληροφορικής, αλλά ως βασική οριζόντια δεξιότητα για κάθε νέο επιστήμονα και επαγγελματία. Το πλαίσιο θα μπορούσε να υλοποιείται μέσω ενός σύντομου πιστοποιημένου μαθήματος ή micro-credential και να περιλαμβάνει πρακτική χρήση Generative AI, prompting, αξιολόγηση της αξιοπιστίας των απαντήσεων, hallucinations, προστασία προσωπικών δεδομένων, copyright, ακαδημαϊκή ακεραιότητα, AI Act και υπεύθυνη χρήση της AI. Ως πανεπιστημιακός που διδάσκω κάθε χρόνο το μάθημα *Introduction to Generative AI* σε φοιτητές και φοιτήτριες, διαπιστώνω στην πράξη ότι η ανάγκη δεν είναι απλώς να μάθουν να χρησιμοποιούν εργαλεία όπως το ChatGPT, αλλά να μάθουν να τα χρησιμοποιούν **κριτικά, υπεύθυνα και παραγωγικά**. **Αιτιολόγηση σχολίου / Εισήγησης:** Η Στρατηγική θέτει ως στόχο μια AI-literate Κύπρο και τη δημιουργία δεξιοτήτων σε όλο το εκπαιδευτικό και επαγγελματικό οικοσύστημα. Η πρόταση μετατρέπει αυτή τη γενική κατεύθυνση σε μια συγκεκριμένη και άμεσα εφαρμόσιμη δράση στην ανώτατη εκπαίδευση, διασφαλίζοντας ότι κάθε νέος απόφοιτος θα διαθέτει ένα ελάχιστο κοινό επίπεδο AI γνώσεων. --- ### 2. Εθνικό Πρόγραμμα AI Εκπαίδευσης και Πιστοποίησης Εκπαιδευτικών **Αριθμός άρθρου/εδαφίου αναφοράς:** *Education and Human Capital Development – National frameworks and governance / EPVL (Ethical, Pedagogical Validation Layer)*, σελ. 78–79. Η Στρατηγική προβλέπει teacher-mediated χρήση της AI, δηλαδή η τεχνολογία να υποστηρίζει τον εκπαιδευτικό και όχι να τον αντικαθιστά, ενώ προβλέπει επίσης εθνικά μαθησιακά αποτελέσματα και πλαίσια για AI Literacy. **Εισήγηση:** Προτείνω τη δημιουργία ενός εθνικού προγράμματος επιμόρφωσης και πιστοποίησης εκπαιδευτικών στην AI, το οποίο θα καλύπτει εκπαιδευτικούς όλων των βαθμίδων. Η εκπαίδευση δεν θα πρέπει να περιορίζεται στη γνωριμία με το ChatGPT, αλλά να επικεντρώνεται στην πρακτική αξιοποίηση της Generative AI για δημιουργία και διαφοροποίηση εκπαιδευτικού υλικού, σχεδιασμό δραστηριοτήτων και αξιολογήσεων, εξατομικευμένη υποστήριξη μαθητών, παροχή feedback, εντοπισμό AI-generated εργασιών, αλλά και στην ασφαλή και υπεύθυνη χρήση της AI με σεβασμό στα προσωπικά δεδομένα, την ακαδημαϊκή ακεραιότητα και την ανθρώπινη κρίση. Θα μπορούσε να δημιουργηθεί ένα **Cyprus AI Educator Certificate**, με βασικό, ενδιάμεσο και προχωρημένο επίπεδο, το οποίο θα επικαιροποιείται τακτικά καθώς εξελίσσονται οι τεχνολογίες. **Αιτιολόγηση σχολίου / Εισήγησης:** Η ίδια η Στρατηγική αναγνωρίζει ότι η ασφαλής χρήση AI στην εκπαίδευση πρέπει να είναι **teacher-mediated** και να μην αντικαθιστά τον εκπαιδευτικό. Επομένως, πριν απαιτήσουμε από τους εκπαιδευτικούς να ενσωματώσουν την AI στην τάξη, πρέπει να τους δώσουμε οργανωμένη, πρακτική και πιστοποιημένη εκπαίδευση. Η προσωπική μου εμπειρία από τη διδασκαλία του *Introduction to Generative AI* σε φοιτητές επιβεβαιώνει ότι η αποτελεσματική χρήση της AI απαιτεί καθοδήγηση και όχι απλώς πρόσβαση στα εργαλεία. --- ### 3. Cyprus AI Student Passport – Πιστοποίηση πραγματικών AI δεξιοτήτων **Αριθμός άρθρου/εδαφίου αναφοράς:** *Education and Human Capital Development – Flagship programme: FutureAI CY* και *Education and Human Capital Development Pillar – What this pillar is expected to deliver*, σελ. 80–81. Η Στρατηγική προβλέπει stackable micro-credentials 5–15 ECTS, πρακτική εκπαίδευση μέσω workshops και sandboxed exercises, καθώς και πιστοποίηση δεξιοτήτων που συνδέεται με τις ανάγκες της αγοράς εργασίας. **Εισήγηση:** Προτείνω τη δημιουργία ενός **Cyprus AI Student Passport**, ενός ψηφιακού πιστοποιητικού δεξιοτήτων που θα συνοδεύει τον φοιτητή από το πανεπιστήμιο προς την αγορά εργασίας και θα καταγράφει όχι μόνο την παρακολούθηση μαθημάτων AI αλλά κυρίως τις πρακτικές δεξιότητες που έχει αποκτήσει. Το Passport θα μπορούσε να αποτελείται από διαφορετικά επίπεδα, όπως AI Literacy, AI Productivity, AI Data Analysis, AI Automation και Sector-Specific AI, και για την απόκτηση κάθε επιπέδου ο φοιτητής να ολοκληρώνει ένα πραγματικό πρακτικό project. Με αυτόν τον τρόπο ένας απόφοιτος δεν θα δηλώνει απλώς ότι «έχει παρακολουθήσει μάθημα AI», αλλά θα μπορεί να αποδεικνύει συγκεκριμένες AI δεξιότητες και εφαρμογές που είναι χρήσιμες στον κλάδο εργασίας του. **Αιτιολόγηση σχολίου / Εισήγησης:** Η Στρατηγική ήδη προτείνει micro-credentials, πρακτική εκπαίδευση, sandboxed exercises και σύνδεση των δεξιοτήτων με τις ανάγκες της αγοράς εργασίας. Η εισήγηση επεκτείνει αυτή τη λογική ειδικά για τους φοιτητές, δημιουργώντας μια **μεταφέρσιμη και αποδείξιμη πιστοποίηση AI skills**. Παράλληλα, μεταφέρει την έμφαση από το «παρακολούθησα ένα σεμινάριο» στο «μπορώ να αποδείξω ότι μπορώ να χρησιμοποιήσω την AI για να λύσω ένα πραγματικό πρόβλημα»." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Constantinos N. Phellas","Possible Ethical and Bioethical Additions to the Cyprus National AI Strategy 2032, Constantinos N. Phellas, Chair of the Cyprus National Bioethics Committee 1. Possible locations for the additions: Section 1.4.8, immediately after “Responsible Deployment” (printed pp. 5-6), Suggestion for consideration: Add a short paragraph linking the existing principles to necessity, proportionality, public interest and additional safeguards for people who may be particularly vulnerable Why it may be useful: This could give the Executive Summary a clearer ethical test without making it too technical. Section 3.3.1.5, National Ethics and Values Committee (printed p. 24) Suggestion for consideration: Expand the current one-sentence description to clarify the Committee's advisory role, membership, independence, transparency and relationship with existing authorities. Why it may be useful: The Strategy already names the Committee, but a little more detail may make its function easier to understand and implement. Immediately after Section 3.3.1.5 Suggestion for consideration: Add a separate paragraph outlining a possible consultative role for the Cyprus National Bioethics Committee within health, biomedical research and related areas. Why it may be useful: Keeping this role separate may help preserve the Committee's statutory identity and avoid suggesting that it is responsible for ethics across every AI sector. New Section 3.9.7, after “AI Social Contract Principles” (printed pp. 43-44) Suggestion for consideration: Consider an Ethical and Fundamental Rights Impact Assessment for higher-risk or materially rights-affecting public-sector systems, together with consultation, publication and redress provisions. Why it may be useful: This would connect the ethics chapter more directly to practical decision-making and public accountability. Annex B, Stage 2 and Control Gate 2 (printed pp. 58-59) Suggestion for consideration: Refer to the ethical assessment, and where relevant specialist bioethical advice, as part of the evidence considered at Control Gate 2. Why it may be useful: This may be the clearest place to show that ethics is part of implementation rather than a separate statement of principle. Annex F, Trust, Ethics and Compliance Indicators (printed pp. 93-94) Suggestion for consideration: Add a small set of outcome-focused ethics and trust indicators Why it may be useful: This could help measure whether people can understand and challenge decisions, whether unequal outcomes persist and whether concerns are addressed. 2. Suggested wording for consideration 2.1 Possible addition to Section 1.4.8: Ethics, Trust and Responsible AI Placement: after the existing bullet “Responsible Deployment: Continuous monitoring and withdrawal criteria.” Suggested wording for consideration Ethical governance under this Strategy should not be understood as being exhausted by legal compliance. Alongside applicable legal requirements, AI initiatives should pursue a legitimate public or organisational purpose and should be assessed for necessity, proportionality and compatibility with human dignity, individual autonomy, equality, solidarity, democratic values and the public interest. Where reasonably possible, decision-makers should consider whether the objective could be achieved through a less intrusive or non-AI alternative and should identify how benefits and risks are distributed, including whether the system could deepen existing social, economic, health or digital inequalities. Additional safeguards should be considered where AI affects children, patients, persons with disabilities, older persons, migrants, employees or others who may face vulnerability or unequal power. Ethical acceptability should be revisited when there are material changes in the data, model, intended purpose or deployment context. Where evidence of benefit remains uncertain and the potential harm is serious or irreversible, appropriate measures may include controlled testing, restricted deployment, temporary suspension or withdrawal. 2.2 Possible replacement text for Section 3.3.1.5: National Ethics and Values Committee Placement: replace the current single sentence under Section 3.3.1.5. Suggested wording for consideration The National Ethics and Values Committee should serve as a multidisciplinary and pluralistic advisory body supporting the ethical implementation of this Strategy. Its membership could include expertise in ethics and philosophy, bioethics, law and human rights, data protection, social sciences, AI and engineering, cybersecurity, accessibility and disability, labour and education, together with appropriate civil-society and stakeholder representation. Appointments should be transparent, and members should declare relevant conflicts of interest. The Committee could develop or recommend a common ethical framework and an Ethical and Fundamental Rights Impact Assessment methodology; advise on novel, high-impact or socially contested uses; identify where additional safeguards, restricted deployment, further consultation or withdrawal may need to be considered; and review ethical issues that cut across sectors. To support public trust, it could publish non-confidential opinions, periodic guidance and an annual account of its work. The Committee should complement rather than replace the National AI Authority, the competent authorities under the EU AI Act, the Commissioner for Personal Data Protection, sector regulators or the courts. Its recommendations would be submitted to the National AI Taskforce. Where a serious ethical concern about a proposed public-sector deployment remains unresolved, the matter could be referred to the National AI Authority and, where appropriate, the Interministerial AI Council before the relevant control gate is passed. 2.3 Possible new paragraph: Role of the Cyprus National Bioethics Committee Placement: immediately after the revised Section 3.3.1.5, with a cross-reference in the Healthcare and Life Sciences pillar. Suggested wording for consideration One possible approach would be to give the Cyprus National Bioethics Committee a standing consultative role within this governance structure, for example through a nominated representative and a formal consultation protocol. The Committee would remain institutionally independent and would offer specialised advice within its statutory remit where AI is used in healthcare, biomedical research, genetics or genomics, pharmaceuticals, human biological material, clinical decision support, health-data reuse or other applications that may affect bodily integrity, patient autonomy or the clinician-patient relationship. Consultation could be considered for nationally significant or high-impact initiatives such as the National Health Data Repository, intelligent triage, the Virtual AI Patient Orchestrator, digital or virtual human twins, AI-enabled medical devices and health research using sensitive or linked datasets. Its contribution might include guidance on consent, secondary use, vulnerability, proportionality, uncertainty and acceptable risk; support for public deliberation; and advice to the National Ethics and Values Committee or relevant Data Access Committees. The role should be designed so that it does not duplicate conformity assessment, data-protection supervision or clinical regulation. Any extension beyond the Committee's current legal remit would require appropriate legal and institutional consideration. 2.4 Possible new Section 3.9.7: Ethical and Fundamental Rights Impact Assessment Placement: after Section 3.9.6 “AI Social Contract Principles” and before the Strategic Outcome. Suggested wording for consideration For higher-risk or materially rights-affecting AI systems procured, piloted or deployed by or on behalf of a public authority, the responsible body should complete an integrated Ethical and Fundamental Rights Impact Assessment (E-FRIA), incorporating the fundamental-rights impact assessment required by the EU AI Act where applicable and coordinated with any Data Protection Impact Assessment. The assessment could cover the system's purpose, necessity and proportionality; the people likely to be affected; foreseeable benefits and harms; data provenance and representativeness; risks of discrimination or exclusion; accessibility; human oversight; explainability and contestability; cybersecurity; environmental and workforce effects; possible misuse or expansion beyond the original purpose; residual risk; and review or withdrawal criteria. Where the likely impact is material, consultation should include relevant stakeholders, particularly affected groups, frontline professionals and those who may be vulnerable. A non-confidential summary could normally be published before deployment, subject to justified legal or security exceptions. The assessment should be revisited following a substantial modification, material model or data drift, a serious incident or a significant change in context. Citizen-facing systems should provide clear notice of AI use, an accessible route to human review and an identifiable public body responsible for responding to concerns and providing redress. 2.5 Possible addition to Annex B: Stage 2 and Control Gate 2 Suggested wording for consideration At Stage 2, the E-FRIA should be initiated and proportionate stakeholder engagement undertaken. Before Control Gate 2 is passed, the responsible authority should be satisfied that the use is necessary and proportionate, that less intrusive alternatives have been considered where appropriate, that safeguards and human oversight are workable, and that the remaining risks are justified and manageable. For health and biomedical systems within the Cyprus National Bioethics Committee's remit, evidence of appropriate bioethical consultation could form part of the gate documentation. Where evidence remains limited, approval could be time-limited and linked to clear review, suspension and decommissioning triggers. 2.6 Possible addition to Annex F: Trust, Ethics and Compliance Indicators Suggested wording for consideration Ethics and trust KPIs could focus on how safeguards work in practice rather than only on whether policies exist. Possible indicators include the proportion of relevant systems completing and publishing an E-FRIA before deployment; the number, type and resolution time of complaints and requests for human review; reversal and override rates; differences in outcomes across protected or vulnerable groups; serious incidents and time to remediation; systems suspended or withdrawn following ethical concerns; stakeholder participation; accessibility compliance; and public trust, with appropriate demographic and socioeconomic disaggregation. Care should be taken not to discourage transparent incident reporting; early identification and correction of problems should be treated as evidence of responsible governance. 3. Why a limited role for the Cyprus National Bioethics Committee may be helpful Existing institutional basis. The Cyprus National Bioethics Committee is already established by law as an independent body concerned with ethical, social, humanitarian and legal questions arising from developments in biotechnology, biology, medicine, genetics and pharmaceuticals. This existing institutional basis may offer continuity and public legitimacy, particularly in areas where AI is closely connected to health or biomedical innovation. Relevant bioethical perspective. Healthcare AI may affect informed consent, bodily integrity, allocation of treatment, diagnostic responsibility, confidentiality and the clinician-patient relationship. These questions are not fully answered by technical accuracy, cybersecurity or data-protection compliance alone. A bioethical perspective can help examine autonomy, benefit and harm, justice, vulnerability, solidarity and the fair treatment of uncertainty. Opportunity to build on existing capacity. The Committee already works with bioethical advice, public information and research-ethics structures. Drawing on that experience may be more coherent than establishing a separate health-ethics body solely for AI. It may also help connect AI governance with existing practices in clinical and biomedical research. A point requiring legal and institutional review: The Strategy may be able to establish advisory, assurance and control-gate arrangements for public bodies, but it should not imply that a committee has licensing, enforcement or adjudicative powers unless those powers are provided by law. The same caution applies to the Cyprus National Bioethics Committee: its contribution should remain within its statutory remit unless any wider role is supported by an appropriate legal or formal inter-institutional arrangement." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","MARIA SAVVA","Ενότητα 3.3.2 «Control Framework», Ενότητα 3.4 «AI Adoption Across Government», Ενότητα 4.4 «AI Adoption Enablers» και Παράρτημα Β «AI Use Case Lifecycle and Control Gates». Σχόλιο / Εισήγηση: Γίνεται εισήγηση όπως, στο πλαίσιο της εφαρμογής της Εθνικής Στρατηγικής ΤΝ, ετοιμαστεί ένας πρακτικός οδηγός, ο οποίος να μπορεί να χρησιμοποιείται από Υπουργεία και δημόσιους οργανισμούς κατά την υλοποίηση εφαρμογών ΤΝ. Ο οδηγός θα ήταν χρήσιμο να περιλαμβάνει βασικά πρότυπα και διαδικασίες για την καταγραφή και αξιολόγηση ενός AI use case, τον έλεγχο της διαθεσιμότητας και καταλληλότητας των δεδομένων, την αξιολόγηση κινδύνων και συμμόρφωσης, τον καθορισμό αρμοδιοτήτων, την πιλοτική εφαρμογή, καθώς και τον τρόπο με τον οποίο θα αξιολογείται το αποτέλεσμα πριν από την πλήρη εφαρμογή μιας λύσης. Αιτιολόγηση σχολίου / Εισήγησης: Η Στρατηγική καθορίζει τα βασικά στάδια που πρέπει να ακολουθούνται κατά τον κύκλο ζωής μιας εφαρμογής ΤΝ, καθώς και τους σχετικούς μηχανισμούς ελέγχου. Ωστόσο, πιστεύω ότι η ύπαρξη ενός πιο πρακτικού οδηγού εφαρμογής θα διευκόλυνε τους οργανισμούς να μεταφέρουν τις πρόνοιες της Στρατηγικής στην καθημερινή λειτουργία τους. Παράλληλα, θα μπορούσε να συμβάλει στην εφαρμογή μιας πιο κοινής προσέγγισης μεταξύ των οργανισμών, ιδιαίτερα σε θέματα όπως η αξιολόγηση των προτεινόμενων εφαρμογών, η διαχείριση των κινδύνων, οι απαιτούμενες εγκρίσεις και η παρακολούθηση των αποτελεσμάτων. Με τον τρόπο αυτό θα περιοριζόταν και το ενδεχόμενο κάθε οργανισμός να αναπτύξει διαφορετικές διαδικασίες και πρότυπα για παρόμοια θέματα, ενώ θα διευκολυνόταν η εφαρμογή και η παρακολούθηση της Εθνικής Στρατηγικής σε πιο ομοιόμορφη βάση. Σημειώνεται επίσης ότι στο Παράρτημα Γ της Στρατηγικής προβλέπεται η κατάρτιση AI adoption plan από κάθε sizeable organisation, ενώ ειδική αναφορά γίνεται και στους ρυθμιζόμενους τομείς, μεταξύ των οποίων περιλαμβάνεται και ο τομέας της ενέργειας. Η πρόνοια αυτή ενισχύει την ανάγκη ύπαρξης ενός πρακτικού και ενιαίου οδηγού εφαρμογής, ώστε οι οργανισμοί που θα κληθούν να ετοιμάσουν και να εφαρμόσουν τα σχετικά σχέδια να έχουν κοινό σημείο αναφοράς ως προς τα στάδια, τις απαιτήσεις, τις εγκρίσεις, την αξιολόγηση κινδύνων και την παρακολούθηση των αποτελεσμάτων." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Menicos Mavrommatis","Pillar A — Data Security and Activity Monitoring R1 — Data Activity Monitoring Requirements The proposed solution must provide continuous, real-time monitoring of every data interaction — whether initiated by a human user or a non-human identity — across structured, semi-structured, and unstructured data stores. The solution must be capable of parsing database queries, capturing NoSQL and streaming protocols, and logging object-level access to file and document repositories, and must enforce sensitivity-aware policies with automated response capabilities that act before damage is done. Behavioural baselines must be established per identity and calibrated for machine-speed access patterns, such that anomalous agent behaviour — for example, the bulk reading of sensitive records within minutes under legitimate credentials — is detected where thresholds tuned for human query volumes would remain silent. The solution must provide end-to-end traceability when data crosses security boundaries, including cases where an agentic system combines data from multiple stores and writes derived outputs to downstream systems. Integration with national security operations tooling (SIEM/SOAR) and with the audit and assurance mechanisms of the Strategy's governance model is required. Deployment as a mandatory architectural layer of the National Data Layer and the API Fabric is expected. R2 — Data Discovery and Classification Requirements The proposed solution must provide automated discovery and classification of sensitive data across ministries and public bodies, supporting a single national classification scheme with mandatory labelling for datasets entering the National Data Layer, sectoral data spaces, or regulatory sandboxes. Classification must cover structured and unstructured sources, must recognise special-category data under GDPR, and must feed sensitivity-aware access, sharing, and monitoring policies. Classification coverage must be a measurable precondition for connecting any system to the API Fabric, and posture-management capabilities are expected to continuously identify unprotected, misplaced, or over-exposed sensitive data. Pillar B — Third-Party AI Risk R3 — Third-Party and Vendor AI Risk Requirements A defined assessment regime for AI vendors and foundation-model providers must be established, covering security posture, data handling and residency, model transparency and documentation, concentration risk, exit strategy, and ongoing monitoring obligations. The regime must generalise the third-party ICT risk discipline already imposed on the financial sector under DORA to all government AI procurement. Dependency concentration on non-EU model and platform providers must be tracked as a named sovereignty metric within the national KPI framework, and tooling that supports continuous third-party risk monitoring as the supplier landscape evolves is expected. Pillar C — Quantum Readiness R4 — Quantum-Safe Cryptography Requirements The proposed solution must incorporate quantum-safe cryptography capabilities that protect sensitive data and communications against both current and future threats posed by cryptographically relevant quantum computers. Post-quantum cryptographic (PQC) algorithms standardised by the National Institute of Standards and Technology (NIST) — including lattice-based, hash-based, and other quantum-resistant primitives — must be supported. The solution must include cryptographic discovery and inventory capabilities, identifying where classical algorithms such as RSA and ECC are in use across the enterprise, enabling the organisation to assess exposure and prioritise migration efforts. A hybrid cryptography approach must be supported, allowing classical and post-quantum algorithms to operate in tandem during transition periods to ensure backward compatibility without compromising security posture. The solution must be capable of integrating with existing PKI infrastructure, hardware security modules (HSMs), and key management systems at enterprise and government scale. Alignment with open industry standards and frameworks — including NIST PQC standards and ETSI/ISO quantum-safe guidance — is required. A quantum-safe roadmap and advisory services must be available to support the organisation through the full cryptographic migration lifecycle, from risk assessment and gap analysis through implementation and validation. Tooling that supports automation and continuous compliance monitoring as standards evolve is expected to be included as part of the overall offering. Long-lived sensitive data — national health, legal, and financial records with decades-long sensitivity — must be prioritised against “harvest now, decrypt later” exposure. R5 — Quantum Computing Requirements The solution must provide access to quantum computing resources and associated development tooling capable of supporting both current and emerging enterprise use cases, including optimisation, simulation, machine learning, and cryptographic research. Access to gate-based quantum hardware with a credible and published roadmap for qubit scaling, error mitigation, and fault tolerance is required. The solution must include a quantum software development environment that supports hybrid classical-quantum workflows, enabling development teams to build, test, and deploy quantum algorithms alongside existing classical workloads. Cloud-based access to quantum systems must be available, with flexible consumption models suitable for research, prototyping, and production-grade workloads. Support for an open, extensible SDK ecosystem — enabling portability and reducing vendor lock-in — is expected, along with access to a broader quantum computing community, curated algorithm libraries, and pre-built industry-specific applications to accelerate time to value." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","National eHealth Authority Cyprus","Πρόκειται για ένα ολοκληρωμένο, συνεκτικό και ιδιαίτερα φιλόδοξο στρατηγικό κείμενο, το οποίο αποτυπώνει με πληρότητα το όραμα και τις βασικές κατευθύνσεις για την ανάπτυξη, αξιοποίηση και υπεύθυνη διακυβέρνηση της Τεχνητής Νοημοσύνης στην Κυπριακή Δημοκρατία. Η Στρατηγική ευθυγραμμίζεται με τις ευρωπαϊκές εξελίξεις και διαμορφώνει ένα ισχυρό πλαίσιο για την προώθηση της καινοτομίας, του ψηφιακού μετασχηματισμού και της αναβάθμισης των δημόσιων υπηρεσιών. Με στόχο την περαιτέρω ενίσχυση της αποτελεσματικότητας, της εφαρμοσιμότητας και της μακροπρόθεσμης βιωσιμότητας της Στρατηγικής, υποβάλλονται οι ακόλουθες παρατηρήσεις: 1. Διακυβέρνηση και θεσμικός συντονισμός Προτείνεται να αποσαφηνιστούν περαιτέρω οι ρόλοι, οι αρμοδιότητες και οι ευθύνες των εμπλεκόμενων φορέων, καθώς και οι μηχανισμοί συντονισμού μεταξύ των εθνικών δομών διακυβέρνησης. Με τον τρόπο αυτό θα ενισχυθεί η αποτελεσματική συνεργασία μεταξύ των αρμόδιων φορέων, θα αποφεύγονται επικαλύψεις αρμοδιοτήτων και θα διασφαλίζεται η συνεκτική και αποτελεσματική εφαρμογή της Στρατηγικής. 2. Δεδομένα, διαλειτουργικότητα και ευρωπαϊκή διάσταση Προτείνεται να ενισχυθεί η αναφορά στη διακυβέρνηση δεδομένων υψηλής αξίας, στην εφαρμογή κοινών προτύπων διαλειτουργικότητας και στη συστηματική αξιοποίηση των ευρωπαϊκών υποδομών και πρωτοβουλιών. Παράλληλα, θα ήταν ωφέλιμο να δοθεί μεγαλύτερη έμφαση στη διασφάλιση της ποιότητας των δεδομένων, στη διακρατική συνεργασία και στην ασφαλή διασυνοριακή ανταλλαγή δεδομένων, ώστε να ενισχύεται η διαλειτουργικότητα, να διευκολύνεται η συνεργασία μεταξύ των κρατών μελών και να προάγεται η ανάπτυξη συμβατών και επαναχρησιμοποιήσιμων λύσεων, αποφεύγοντας παράλληλα αποσπασματικές ή μη συμβατές προσεγγίσεις. 3. Υλοποίηση και βιωσιμότητα Προτείνεται να προβλεφθούν σαφέστερα κριτήρια αξιολόγησης για τη μετάβαση από πιλοτικές εφαρμογές σε πλήρη παραγωγική λειτουργία, καθώς και διαδικασίες αξιολόγησης της επιχειρησιακής ωριμότητας και ετοιμότητας των έργων. Επιπλέον, θα ήταν χρήσιμο να ενισχυθεί η πρόβλεψη για την επαναχρησιμοποίηση κοινών υπηρεσιών, τεχνολογικών δομικών στοιχείων και υποδομών, ώστε να αποφεύγονται επικαλύψεις επενδύσεων και να επιτυγχάνονται οικονομίες κλίμακας. Παράλληλα, κρίνεται σημαντικό να δοθεί μεγαλύτερη έμφαση στη μακροχρόνια επιχειρησιακή και οικονομική βιωσιμότητα των λύσεων που θα αναπτυχθούν, περιλαμβανομένου του σχεδιασμού για τη συντήρηση, την αναβάθμιση, τη συνεχή παρακολούθηση και τη διασφάλιση της χρηματοδότησής τους μετά την ολοκλήρωση της αρχικής υλοποίησης. 4. Δείκτες παρακολούθησης και αξιολόγησης Πέραν των ποσοτικών δεικτών υιοθέτησης, προτείνεται να συμπεριληφθούν ποιοτικοί δείκτες που να αξιολογούν την ποιότητα των παρεχόμενων υπηρεσιών, τον βαθμό διαλειτουργικότητας μεταξύ πληροφοριακών συστημάτων, τον βαθμό πραγματικής αξιοποίησης των λύσεων Τεχνητής Νοημοσύνης, την επίδρασή τους στην αποδοτικότητα της δημόσιας διοίκησης, την προστιθέμενη αξία που δημιουργείται για τους πολίτες, τις επιχειρήσεις και τους δημόσιους οργανισμούς, καθώς και τον βαθμό ικανοποίησης των τελικών χρηστών. 5. Τομέας Υγείας Λαμβάνοντας υπόψη τη στρατηγική σημασία του τομέα της υγείας, προτείνεται να δοθεί μεγαλύτερη έμφαση στη διασυνοριακή ανταλλαγή δεδομένων υγείας, στην ασφαλή δευτερογενή αξιοποίηση δεδομένων υγείας για σκοπούς έρευνας, καινοτομίας και ανάπτυξης εφαρμογών Τεχνητής Νοημοσύνης, με παράλληλη διασφάλιση της ιδιωτικότητας, της κλινικής ασφάλειας και της συμμόρφωσης με το ισχύον κανονιστικό πλαίσιο. Επιπρόσθετα, προτείνεται η ενίσχυση των μηχανισμών διακυβέρνησης και προστασίας των δεδομένων υγείας, καθώς και η περαιτέρω ευθυγράμμιση με τις σχετικές ευρωπαϊκές πρωτοβουλίες, υποδομές, κανονιστικά πλαίσια και βέλτιστες πρακτικές. Πιο συγκεκριμένα, εισηγούμαστε την προσθήκη των ακόλουθων παραγράφων: Annex C – Priority Sectors for Leadership Healthcare and Life Sciences National frameworks and governance Implementation will be aligned with the European Health Data Space (EHDS), under the strategic leadership of the Ministry of Health and the operational coordination of the National eHealth Authority. Building on Cyprus’ operational participation in the MyHealth@EU infrastructure for the secure cross-border exchange of electronic health data for primary use, Cyprus will continue to expand cross-border digital health services while advancing the national implementation of the HealthData@EU infrastructure for the secure secondary use of health data, with full operational readiness targeted by the end of 2027. Together, these European infrastructures will provide the trusted digital foundation for AI-enabled healthcare services, clinical care, research, innovation, public health, and evidence-based policymaking, ensuring interoperability, security, and compliance with the EHDS, the AI Act, GDPR, and national legislation. International alignment Cyprus will promote the adoption and consistent implementation of internationally recognised semantic and technical interoperability standards, including HL7 FHIR, SNOMED CT, ICD, and the European Electronic Health Record Exchange Format (EEHRxF), enabling trusted cross-border health services, high-quality health data for research and innovation, and interoperable AI-enabled healthcare across Europe. Annex D – Research and Innovation Focus Area 3: Healthcare Εισηγούμαστε επίσης την προσθήκη της πιο κάτω βιβλιογραφικής αναφοράς, καθώς αποτελεί την πλέον πρόσφατη επίσημη μελέτη της Ευρωπαϊκής Επιτροπής για την ανάπτυξη και αξιοποίηση της Τεχνητής Νοημοσύνης στον τομέα της υγείας. Η μελέτη παρέχει τεκμηριωμένες κατευθύνσεις πολιτικής και βέλτιστες πρακτικές για την ασφαλή, αξιόπιστη και υπεύθυνη υιοθέτηση της Τεχνητής Νοημοσύνης στα εθνικά συστήματα υγείας, σε πλήρη ευθυγράμμιση με τις ευρωπαϊκές πολιτικές και προτεραιότητες. European Commission, Directorate-General for Health and Food Safety. Study on the Deployment of AI in Healthcare: Final Report. Publications Office of the European Union, Luxembourg (2025). DOI: 10.2875/2169577. Επιπρόσθετα, εισηγούμαστε την προσθήκη της ακόλουθης ερευνητικής προτεραιότητας, η οποία αντικατοπτρίζει τις βασικές συστάσεις της πιο πάνω μελέτης: • Trusted health data infrastructures, interoperability, and secure data sharing to enable the European Health Data Space (EHDS) and support explainable, trustworthy, and human-centred AI through robust validation, continuous evaluation, and regulatory compliance. Οι πιο πάνω παρατηρήσεις υποβάλλονται με γνώμονα την περαιτέρω ενίσχυση της εφαρμοσιμότητας, της αποτελεσματικότητας και της μακροπρόθεσμης βιωσιμότητας της Εθνικής Στρατηγικής Τεχνητής Νοημοσύνης. Η ενσωμάτωση των εισηγήσεων αυτών αναμένεται να ενισχύσει τον θεσμικό συντονισμό, να προωθήσει τη διαλειτουργικότητα και την αξιοποίηση κοινών υποδομών, να διευκολύνει την αποτελεσματική υλοποίηση των προβλεπόμενων δράσεων και να μεγιστοποιήσει τα οφέλη για τους πολίτες, τις επιχειρήσεις και τη δημόσια διοίκηση. Παράλληλα, θα συμβάλει στη διατήρηση της συνεχούς ευθυγράμμισης της Κυπριακής Δημοκρατίας με το ευρωπαϊκό κανονιστικό και τεχνολογικό περιβάλλον στον τομέα της Τεχνητής Νοημοσύνης." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Anastasia Kamenou","Παρατηρήσεις του Υπουργείου Εσωτερικών επί του Σχεδίου Εθνικής Στρατηγικής Τεχνητής Νοημοσύνης Κεφάλαιο 3.2 – Data as a Strategic National Asset Θέμα: Ψηφιακή ωριμότητα ως προϋπόθεση εφαρμογής της Τεχνητής Νοημοσύνης Το Υπουργείο Εσωτερικών υποστηρίζει πλήρως την προσέγγιση της Στρατηγικής όσον αφορά τη σημασία της διακυβέρνησης των δεδομένων, της διαλειτουργικότητας και της αρχής Data by Design.Προτείνεται, ωστόσο, να αναγνωριστεί ρητά ότι η αφετηρία των δημόσιων οργανισμών ως προς τον ψηφιακό μετασχηματισμό δεν είναι κοινή.Για Υπουργεία με μεγάλο εύρος υπηρεσιών προς τους πολίτες και σημαντικό αριθμό υφιστάμενων πληροφοριακών συστημάτων, όπως το Υπουργείο Εσωτερικών, η επιτυχής εφαρμογή της Τεχνητής Νοημοσύνης προϋποθέτει την προηγούμενη ή παράλληλη ενίσχυση των βασικών ψηφιακών υποδομών, τη βελτίωση της ποιότητας των δεδομένων, την επίτευξη διαλειτουργικότητας και την εφαρμογή ενιαίου πλαισίου διακυβέρνησης δεδομένων. Ως εκ τούτου, προτείνεται να προβλεφθεί σταδιακή εφαρμογή της Τεχνητής Νοημοσύνης, ανάλογα με τον βαθμό ψηφιακής ωριμότητας κάθε οργανισμού. Κεφάλαιο 3.3 – Governance and Accountability Θέμα: Έκδοση Οδηγού για την εκπόνηση Θεσμικών Στρατηγικών Τεχνητής Νοημοσύνης (Institutional AI Strategies) Η Στρατηγική προβλέπει ότι κάθε Υπουργείο και δημόσιος οργανισμός που θα αναπτύσσει ή θα χρησιμοποιεί εφαρμογές Τεχνητής Νοημοσύνης οφείλει να εκπονήσει τη δική του Institutional AI Strategy, ευθυγραμμισμένη με την Εθνική Στρατηγική και τον Κανονισμό AI Act. Προτείνεται να προβλεφθεί η έκδοση ενιαίου Οδηγού (Implementation Guide) για την εκπόνηση των Θεσμικών Στρατηγικών Τεχνητής Νοημοσύνης των Υπουργείων και των δημόσιων οργανισμών, ώστε να διασφαλιστεί κοινή μεθοδολογία και ομοιόμορφη εφαρμογή της Εθνικής Στρατηγικής. Επιπλέον, η στρατηγική κάθε Υπουργείου πιθανώς να επηρεαζεται από την στρατηγική άλλου Υπουργείου. Ποιος θα συντονίζει και θα ευθυγραμμίζει τη διαδικασία." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Marios Ioannides PhD","Αρ. Άρθρου και εδαφίου Annex C – Healthcare and Life Sciences (pages 67–70) National Health Data Repository Σχόλιο / Εισήγηση Expand the scope of the proposed National Health Data Repository to explicitly include AI-enabled capabilities that support precision medicine and clinical research, specifically: • AI-enabled longitudinal disease registries for rare diseases, cancer, cardiovascular, neurological and other high-impact conditions, including genomics where appropriate. • Continuous AI-assisted re-analysis of unresolved clinical and genomic cases as new validated scientific evidence becomes available, enabling healthcare professionals to identify cases requiring expert review. • AI-assisted identification of potentially eligible participants for ethically approved clinical research studies and clinical trials, while ensuring GDPR compliance, human oversight and patient privacy. • Interoperability, where appropriate, with the European Health Data Space (EHDS), European Reference Networks (ERNs) and relevant European disease registries to facilitate multinational research collaborations and clinical trials. Αιτιολόγηση σχολίου / Εισήγησης The Strategy already establishes a strong foundation through the proposed National Health Data Repository. However, it primarily focuses on secure data storage and interoperability and does not explicitly describe how AI can leverage these data to advance precision medicine and clinical research. The proposed enhancements would extend the functionality of the existing infrastructure without requiring new national systems. They would: • improve diagnosis and follow-up of patients with complex and rare diseases through continuous AI-assisted review of emerging evidence; • support evidence-based healthcare planning through longitudinal disease registries; • facilitate faster recruitment into approved clinical trials, improving patient access to innovative therapies; • strengthen Cyprus's participation in European research initiatives through interoperability with EHDS, European Reference Networks and relevant disease registries; and • enhance Cyprus's competitiveness in precision medicine, translational research and international clinical research, while remaining fully aligned with the Strategy's objectives on trusted AI, healthcare innovation and European integration." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",ianabolshakova,"Anro Technologies Limited (trading as AnroAgents), HE 439985, Cyprus. Comment 7 of 7. 7. OFFER OF PARTICIPATION Article / paragraph: Section 3.8 (Research, Innovation and Ecosystem Development); AI Industrial Centre of Excellence; industry sandboxes programme. Comment / Suggestion: We formally register our interest in participating in the AI Industrial Centre of Excellence working groups on agentic AI reference architectures and interoperability, and in the industry sandbox programme as a Cyprus-resident vendor of agentic customer-facing systems. Rationale: The Centre's mandate to publish interoperability roadmaps requires input from companies running agentic systems in production against real customers and real EU AI Act obligations, not only from research institutions and large integrators. We are a Cyprus-registered company doing precisely this, at SME scale, in the priority sectors the Strategy names — tourism, professional services, e-commerce and others — and we have already implemented the standards the roadmap will have to choose between, including the parts that turned out to be harder than the specifications suggest. To be precise about what is on offer: working-group participation, and the standards contributions described in comments 1 and 2, are offered without charge. Delivery work, if the Republic procures any, we would bid for on open terms like any other supplier. We would rather the national reference implementation be built once, publicly and correctly, than separately by each vendor that needs one. This is the last of our seven comments. They have been submitted here in sequence and also sent to the consultation officer as a single document, which sets them out in full with the same section references. We thank the National AI Taskforce for a substantive and distinguishingly candid document — in particular for stating the 9.27% adoption figure plainly rather than burying it. Our comments are offered in support of the Strategy's direction. Kind regards, Iana Bolshakova Co-Founder and CBDO @AnroAgents" "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",ianabolshakova,"Anro Technologies Limited (trading as AnroAgents), HE 439985, Cyprus. Comment 6 of 7. 6. RESERVE A LANE IN THE TRANSFORMATION-PROJECT PROCUREMENTS FOR CYPRUS-RESIDENT SMEs, AND FIX THE TARGETS THAT ANNEX F WILL MEASURE Article / paragraph: Section 3.4 — Value-First Portfolio, ""16 flagship transformation programmes""; Section 5, item 6 (AI Adoption Plan) — ""Launch of procurements for the first 6 transformational AI solutions within 8 months""; Section 3.4.4 (Shared Capabilities and Reuse); Objective 3 (inclusive ecosystem) and Objective 8 (Sovereign Capability through Partnerships); Annex F (National KPIs and Measurement Framework). Comment / Suggestion: Add to the procurement provisions: (a) division of the sixteen flagship transformation programmes, and of the first six transformational solutions to go to market, into lots sized so that a company of 10-50 people can bid for a lot; (b) a distinct ""quick wins"" procurement track with capped contract values and proportionate prequalification — turnover and reference requirements that a three-year-old Cypriot company can actually satisfy; (c) a reporting KPI in Annex F for the share of AI contract value awarded to Cyprus-resident SMEs. Rationale: Objective 8 seeks sovereign capability through partnerships, and Objective 3 an inclusive ecosystem — but procurement design, not strategy text, determines who wins. Standard prequalification thresholds (multi-year turnover, prior contracts of comparable size) mechanically exclude every Cypriot AI company, because none of them has previously delivered a national-scale AI programme; nobody has. The predictable outcome is that the entire portfolio goes to a small number of international integrators, the capability leaves the island with them at the end of each contract, and the AI Innovation Fund's stated ambition of growing Cypriot ventures is contradicted by the state's own spending. Lot-splitting costs the state nothing and is the only instrument here that actually builds domestic capability rather than describing it. Without an explicit KPI, this will not happen. Second point, on Annex F itself. We ask above for one more KPI, so we should say plainly that the targets Annex F is meant to measure do not currently reconcile. We count four: • 75% industry adoption by 2030 — Section 5, item 4, National AI Compliance Funding programme. • 50% across government and priority sectors — Section 3.4, AI Adoption Across Government. • 75% AI adoption by 2032, attributed to the Digital Decade target — Annex C, Government and Public Sector pillar. Two difficulties here: it states 75% for broadly the scope that Section 3.4 puts at 50%, and the Digital Decade target it invokes is 75% of enterprises by 2030, not 2032. • 13% to 75% across education and labour by 2032 — Section 3.5, Education, and Annex C. The second and third overlap in scope with different numbers, and the headline figure of 75% resolves to different bases and different dates depending on where it appears. Annex F will inherit whichever ambiguity is left unresolved, and a target that cannot be measured will not be managed. We suggest fixing one headline definition with an explicit base, scope and date, labelling the sectoral targets distinctly, and correcting the Digital Decade attribution. This is cheap to fix now and expensive to fix after Annex F is published." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",ianabolshakova,"Anro Technologies Limited (trading as AnroAgents), HE 439985, Cyprus. Comment 5 of 7. 5. FUND OPEN GREEK-LANGUAGE EVALUATION SETS FOR CONVERSATIONAL AGENTS THROUGH PHAROS-CY Article / paragraph: Section 3.5 (Priority Sectors) — Tourism, ""multilingual AI services""; Section 3.7.5 (Integration with EuroHPC and the European AI Factory Ecosystem); Section 3.8.6 (Pharos-CY as Cyprus's AI Factory Antenna); Section 3.5 — Legal Services, ""legal language model trained on Cyprus law"". Comment / Suggestion: Include in the Pharos-CY AI Factory Antenna mandate the creation and open publication of Greek-language evaluation datasets and benchmarks for conversational and agentic systems — covering Cypriot Greek usage, public-administration and tourism/hospitality terminology, and safety behaviours (refusal, escalation, hallucination on domain facts). Publish under an open licence with a public leaderboard. Rationale: The Strategy asks for multilingual public services and a Cypriot legal language model, but provides no way to tell whether any given system is actually good at Greek. Without shared benchmarks, ""supports Greek"" is a claim on a sales deck, procurement cannot discriminate between a competent system and a machine-translated one, and the state will buy the latter at the price of the former. Evaluation infrastructure is a classic public good: too expensive for any single vendor to build, cheap at national scale, and it disproportionately helps local suppliers, who are the ones with genuine Greek-language capability to demonstrate. It is also the least glamorous and most load-bearing item in this submission. We ship Greek in production today and would contribute test cases and vendor-side validation." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",ianabolshakova,"Anro Technologies Limited (trading as AnroAgents), HE 439985, Cyprus. Comment 4 of 7. 4. PUBLISH A PROPORTIONATE BASELINE FOR LIMITED-RISK CONVERSATIONAL AND AGENTIC SYSTEMS Article / paragraph: Section 3.3.2 (Control Framework), Section 3.9 (Ethics, Trust and Responsible AI), NAICF Comply. Comment / Suggestion: Commit to publishing, alongside NAICF, a short and concrete baseline for limited-risk conversational and agentic systems — the Article 50 transparency tier of the EU AI Act rather than the Chapter III high-risk regime. The baseline should be checkable and finite: disclosure that the user is interacting with an AI system; logging and retention of interactions; a guaranteed path to a human; data residency and sub-processor disclosure; scope limits on what actions the agent may take without confirmation. Vendors meeting the published baseline should receive a presumption of conformity for that tier, valid across the public sector and recognised in AdoptNAICF applications. Rationale: Most AI that an SME will ever deploy — a website assistant, a booking agent, an internal search tool — is limited-risk under the AI Act. Where no proportionate national baseline exists, the market fills the gap with a maximalist reading, and SMEs are advised that every customer-facing assistant requires a full high-risk conformity exercise. The practical result is not better protection; it is that the SME does nothing, and the adoption figure does not move. A published baseline is simultaneously the cheapest consumer protection measure in the Strategy and its single most effective adoption accelerator, because it replaces an open-ended legal unknown with a checklist. It also gives Cyprus a concrete, exportable artefact for the ""trusted jurisdiction"" claim: a compliance baseline that a foreign SME can read in ten minutes is a better advertisement than a certification scheme it cannot afford." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",ianabolshakova,"Anro Technologies Limited (trading as AnroAgents), HE 439985, Cyprus. Comment 3 of 7. 3. THE 75% INDUSTRY ADOPTION TARGET IS UNREACHABLE UNLESS THE FUNDING INSTRUMENT FUNDS RUNNING SOFTWARE Article / paragraph: Section 5, item 4 — National AI Compliance Funding programme, ""targeted interventions aimed at achieving 75% industry adoption of AI technologies in Cyprus by 2030""; Section 2.2 — the 9.27% baseline and the recorded rate of progression; Section 2.5.3 (Objective 3); Section 3.5 — ""Supporting Small and Medium-Sized Enterprises"" (AdoptNAICF and the Industrial AI Centre of Excellence). Comment / Suggestion: State in the Strategy that instruments intended to move industry adoption will fund the operation of production AI systems, not only advice about them. Concretely: AdoptNAICF support payable against twelve months of subscription and onboarding costs for a production AI product, disbursed to the vendor rather than reimbursed to the buyer; and a lower-friction track for micro-enterprises under ten employees, with a fixed sum and a one-page application. We note and support the earlier submission to this consultation raising subscription eligibility, and add to it the disbursement route and the micro-enterprise track. Rationale: The Strategy sets 75% industry adoption by 2030 and, in the same document, records the starting point: 9.27% in 2025, reached ""after an annual progression of 17.3% since 2024"". Those two numbers do not meet. Held at the recorded rate, 9.27% compounds to roughly 20.6% by 2030 — short of the target by a factor of about three and a half. Reaching 75% from 9.27% in five years requires sustained growth of roughly 52% a year, three times the rate the document itself observes. Extending the horizon to 2032 does not rescue the arithmetic; it moves the required rate to about 35% a year. A gap of that size is not an awareness gap, and no volume of advisory work closes it. For a Cypriot firm with eight employees, the barrier is a recurring line item of a few hundred euro a month against uncertain payback, plus the two weeks of someone's attention needed to configure the thing. An instrument that funds studies, assessments and pilots but not the running product yields a well-documented pipeline of abandoned proofs of concept — the ""AI theatre"" the Strategy itself names among its execution risks. Paying for the first year of live operation puts the system in front of real customers, where it either pays for itself and the firm renews unsubsidised, or it does not and the state has bought a cheap and honest answer. Either outcome is worth more than a report." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",ianabolshakova,"Anro Technologies Limited (trading as AnroAgents), HE 439985, Cyprus. Comment 2 of 7. Declaration of interest. We sell agentic AI to Cypriot SMEs and would tender for national work in this field. Some of our recommendations, if adopted, would benefit us — as they would any vendor in this market. 2. MAKE THE NATIONAL AI REGISTRY MACHINE-READABLE AND QUERYABLE BY AGENTS Article / paragraph: Section 5 (Immediate Steps), item 4 — ""National AI application and certification registry"" and ""Development of an AI Registry""; Section 3.5, Legal Services — AIREG. Comment / Suggestion: Specify that both registries will publish their non-confidential records through a documented public API in an open, machine-readable schema — and that this schema will be an existing agent capability description standard (OASF or equivalent), not a bespoke format. Every registered AI solution should be discoverable programmatically by capability, sector, risk classification, certification status, data residency and supported languages. Rationale: As drafted, the registries are pure compliance instruments — a cost imposed on vendors with no return. Making them machine-readable converts the same artefact into a distribution channel at effectively zero marginal cost. Concretely: a procurement officer's assistant, a foreign buyer's agent, or an SME looking for a compliant supplier could query ""certified, EU-resident, Greek-language customer-service agents operating in Cyprus"" and get a structured answer. This is the difference between a registry that vendors comply with reluctantly and one they compete to be listed in. It also gives substance to the claim in Objective 1 that Cyprus is a trusted jurisdiction — trust that cannot be verified programmatically does not travel across borders. This is not a theoretical ask. We already generate and publish OASF 1.0.0 records automatically for every agent on our platform and keep them current as agents change, so the marginal cost to a vendor already operating to the standard is close to zero — and the registry inherits a schema that has been tested against real deployments rather than designed in advance of them. We offer the schema mapping work to the Republic at no cost. Offer, with its limits stated. We will produce the mapping as a written deliverable: a field-by-field mapping of the registry's attributes onto OASF (sector to domains, capability to skills, endpoint to locators and modules); an explicit list of the regulatory attributes OASF does not currently accommodate — risk tier, conformity status, provider identity, data residency — together with a proposed extension to carry them, which we would submit upstream to the standard rather than leave as a Cyprus-local variant; a draft OpenAPI contract for the public query surface; and a version-drift policy. That last item is not hypothetical: OASF ships new schema versions, and a registry pinned to one of them decays silently. We run automated monitoring of exactly this drift in production and would contribute the policy alongside the mapping. Building, hosting or operating the registry endpoint itself is outside this free offer; if the Republic procures that work, we would tender for it on the same footing as any other supplier." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",ianabolshakova,"Submission to the Public Consultation on the National AI Strategy of the Republic of Cyprus 2032 Submitted by: Anro Technologies Limited (trading as AnroAgents), HE 439985, VAT CY10439985O, Cyprus. Contact: Iana Bolshakova, Co-Founder and CBDO — yana@anroit.com. This is comment 1 of 7; the full submission has also been sent to the consultation officer as a single document. About the submitter. Anro Technologies Limited is a Cyprus-registered company operating AnroAgents, a platform for deploying AI agents for small and medium-sized businesses (conversational sales and service agents, retrieval over a customer's own knowledge base, calendar and CRM integrations, Agen2Agent transactions and communication, directory of agents). The platform is deployed in tourism/hospitality, e-commerce, professional services, and other industries. Ships in six languages including Greek, and integrates with WordPress and Shopify — the two systems that carry the majority of Cypriot SME web presence. Relevant to the comments below, we operate the following in production, from Cyprus, today: • A node of the AGNTCY Agent Directory Service, live since June 2026 and joined to the public peer-to-peer directory network, with public gRPC and P2P endpoints. • Automated generation and publication of OASF 1.0.0 records for agents on our platform, including classification against the OASF skills and domains taxonomy, with records refreshed when an agent changes. • An A2A (Agent2Agent) gateway that makes directory-listed agents actually invokable agent-to-agent over JSON-RPC, with agent cards, rate limiting and per-agent isolation — that is, discovery and invocation, not discovery alone. • An MCP (Model Context Protocol) server, published as a public npm package. We state this not as a credential but because the recommendation below asks the Republic to commit to specific standards, and we think that request carries more weight from a party that has already implemented them and can describe what does and does not work. 1. NAME THE OPEN AGENT-INTEROPERABILITY STANDARDS THE STRATEGY WILL BUILD ON Article / paragraph: Section 2.5.6 (Objective 6), Section 3.2.3 (Interoperability and Secure Data Sharing), Section 3.7.3 (Digital Sovereignty and Strategic Autonomy), and the Government and Public Sectors flagship — AI Industrial Centre of Excellence, tasked to ""publish interoperability roadmaps and reference architectures"" for agentic AI. Comment / Suggestion: The Strategy commits repeatedly to interoperability, portability and vendor diversity for agentic AI, but does not name a single concrete standard. We propose that the Strategy state explicitly that Cyprus will adopt existing open, vendor-neutral agent interoperability standards as the national baseline rather than commission a national one. Specifically: • A2A (Agent2Agent) — under the Linux Foundation — for agent-to-agent task delegation; • MCP (Model Context Protocol) for agent-to-tool and agent-to-data-source connection; • OASF (Open Agentic Schema Framework) and the AGNTCY Agent Directory model for describing, publishing and discovering agent capabilities. The recommended wording for the Centre of Excellence mandate: ""reference architectures shall be based on open, vendor-neutral agent interoperability standards adopted by recognised open-source foundations, and shall not introduce Cyprus-specific protocol variants where an international standard exists."" Rationale: The Strategy's own risk analysis (Section 3.7.3) identifies vendor lock-in and supply-chain dependency as strategic threats. In agentic systems, lock-in does not happen at the model layer, which is easily swapped — it happens at the orchestration and capability-description layer, which is not. A national protocol variant, however well designed, would be the fastest possible route to the outcome the Strategy is trying to avoid: it would make Cypriot deployments incompatible with the European and global agent ecosystem, raise the integration cost of every foreign supplier entering Cyprus, and make every Cypriot vendor's product unexportable. Cyprus is too small a market to set a standard and large enough to be hurt by adopting the wrong one. Committing to the existing open standards costs nothing, is available today, and directly serves the ""bridge between the EU and neighbouring regions"" positioning: a bridge has to be built to a gauge both sides already use. Offer: we propose that the Centre of Excellence establish a national reference deployment and conformance testbed for agent interoperability — a live directory node against which any vendor, Cypriot or foreign, can validate that its agent publishes a well-formed capability record and answers a standards-compliant invocation. We already run such a node in production from Cyprus and offer it as the pilot instance, together with the conformance test cases, at no cost to the state. If the Republic prefers the reference deployment to sit with a public body — the Centre of Excellence, Pharos-CY or CyNet — we will contribute the implementation and the operational runbook rather than compete for the role. The point is that the capability should exist and be publicly testable; who hosts it matters less." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Athos Patsalides","Feedback on the Cyprus National AI Strategy 2032 On behalf of Smart Nautilus Ltd., I would like to congratulate the Government of Cyprus and the National AI Taskforce for preparing a comprehensive and forward-looking National AI Strategy. The Strategy establishes a strong foundation for the responsible adoption of Artificial Intelligence through governance, digital infrastructure, education, innovation and regulatory alignment. As Cyprus moves towards implementation, I believe greater emphasis should be placed on execution, commercialization and the development of globally competitive AI capabilities. To ensure that Cyprus continues to advance its vision and strengthen its capabilities within an increasingly competitive global landscape, the objectives and targets established under this strategic pillar should be realistic, measurable, and achievable. Their successful implementation should be supported by continuous monitoring, regular performance evaluation, and close collaboration between government, academia, industry, and other key stakeholders. Furthermore, the Strategy should remain adaptive and responsive to emerging technologies, evolving market demands, and international developments, ensuring that the national AI ecosystem continues to evolve through ongoing innovation, refinement, and sustainable development. In particular, I recommend that the Government considers the following before final implementation: 1. Establish National AI Flagship Projects The Strategy would benefit from a number of flagship national programmes demonstrating AI in practice. These should focus on sectors where Cyprus already has international competitive advantages, including maritime, ports, energy, water management, healthcare and public administration. 2. Expand the Maritime AI Vision Cyprus is one of the world’s leading maritime centres. The Strategy should include a dedicated roadmap for Maritime AI covering autonomous robotics, smart ports, underwater inspection, vessel performance optimisation, biofouling management, maritime cybersecurity, digital twins and environmental monitoring. This represents an opportunity for Cyprus to become an international leader rather than simply an adopter of AI technologies. 3. Create a National Maritime AI & Autonomous Systems Centre of Excellence A specialised Centre of Excellence bringing together government, universities and industry would accelerate research, certification, testing and commercial deployment of AI-powered maritime technologies while attracting international investment and talent. 4. Introduce Regulatory AI Sandboxes / Smart-box Innovation should be supported through controlled regulatory environments that allow companies to safely test AI applications before commercial deployment, particularly in maritime, healthcare, finance, defence and critical infrastructure. 5. Strengthen Public-Private Partnerships Successful implementation will depend on close collaboration between government, academia and industry. A structured national AI innovation consortium and industry advisory council would improve coordination and accelerate adoption. 6. Support Commercialisation and Export The Strategy should include clear measures to transform research into commercial success through support for patents, technology transfer, venture creation, scale-up financing and international market expansion. Success should be measured not only by AI adoption but also by the number of globally competitive AI companies created in Cyprus. 7. Modernise Public Procurement Public procurement should encourage innovation through pilot projects, outcome-based procurement and simplified procedures that enable startups and SMEs to participate in delivering AI solutions for the public sector. 8. Strengthen AI Security and Digital Sovereignty As AI becomes critical national infrastructure, additional focus should be placed on AI security, trusted data, model integrity, cyber resilience and protection of critical infrastructure to ensure long-term national resilience. 9. Define Measurable Sector-Specific KPIs Beyond national indicators, each priority sector should include measurable targets, implementation milestones and annual reporting mechanisms to ensure accountability and continuous improvement. Overall, the National AI Strategy 2032 provides an excellent foundation for Cyprus to become a trusted AI nation. By strengthening implementation mechanisms, promoting commercialization, investing in flagship projects and leveraging Cyprus’ strategic advantages, particularly in maritime innovation, the country can position itself not only as a user of Artificial Intelligence, but as a recognized developer and exporter of AI technologies. Smart Nautilus welcomes the opportunity to contribute its expertise in artificial intelligence, autonomous robotics, maritime digitalization and smart infrastructure to support the successful implementation of the National AI Strategy 2032. Smart Nautilus remain committed to support and enhance the capabilities of the cluster using expertise, knowledge and evidence based technologies to advance the future applications! With my very best regards Athos Patsalides Smart Nautilus" "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Yiannis Laouris","10. Γενική τοποθέτηση — Προσθήκη αυτοτελούς κεφαλαίου δημοκρατικής διακυβέρνησης Article / paragraph General comment on the Strategy as a whole, with particular reference to Sections 2.5.7, 3.3, 3.4, 3.9, 3.11, 3.13, Annex A, Annex B and Annex F. Proposed amendment / recommendation Να προστεθεί στην Εθνική Στρατηγική αυτοτελές κεφάλαιο με τίτλο: «Δημοκρατική διακυβέρνηση, κοινοβουλευτική εποπτεία, δικαιώματα του πολίτη και κοινωνική λογοδοσία της Τεχνητής Νοημοσύνης». Το κεφάλαιο να ενοποιεί και να καθιστά επιχειρησιακά εφαρμόσιμες τις πρόνοιες για: • κοινοβουλευτική και δημόσια εποπτεία, • δικαιώματα του πολίτη και ανθρώπινη επανεξέταση, • δημόσιο μητρώο κρατικών συστημάτων ΤΝ, • προστασία ανηλίκων και ευάλωτων ομάδων, • δημοκρατική και εκλογική ακεραιότητα, • διαφάνεια και έλεγχο δημόσιων προμηθειών, • συμμετοχική και πολυμετοχική διακυβέρνηση, • δίκαιη εργασιακή μετάβαση, • ανεξάρτητη αξιολόγηση, δημοσιοποίηση περιστατικών και δημόσια λογοδοσία. Να συνοδεύεται από συγκεκριμένο σχέδιο εφαρμογής, αρμόδιους φορείς, χρονοδιαγράμματα, δείκτες και ετήσια συζήτηση στη Βουλή. Justification Η Εθνική Στρατηγική περιλαμβάνει σημαντικές αρχές ανθρωποκεντρικής, αξιόπιστης και υπεύθυνης ΤΝ. Οι σχετικές πρόνοιες, όμως, είναι κατανεμημένες σε διαφορετικά κεφάλαια και παραρτήματα και κινδυνεύουν να παραμείνουν γενικές κατευθύνσεις χωρίς ενιαίο δημοκρατικό και δικαιωματικό πλαίσιο. Η Στρατηγική πρέπει να απαντά όχι μόνο στο πώς θα υιοθετήσει η Κύπρος την ΤΝ, αλλά και στα ακόλουθα: • Ποιος αποφασίζει πού και με ποιον τρόπο θα χρησιμοποιείται; • Ποιος ελέγχει τα συστήματα, τα δεδομένα και τις συμβάσεις; • Πώς προστατεύονται και ασκούνται στην πράξη τα δικαιώματα; • Πώς αμφισβητούνται οι αλγοριθμικά υποβοηθούμενες αποφάσεις; • Πώς προστατεύεται η δημοκρατική διαδικασία; • Πώς κατανέμονται δίκαια τα οφέλη και οι κίνδυνοι; Η επιτυχία της Στρατηγικής δεν πρέπει να κριθεί από τον αριθμό των εφαρμογών ΤΝ, αλλά από το κατά πόσο αυτές βελτιώνουν πραγματικά τη ζωή των πολιτών, μειώνουν τη γραφειοκρατία, προστατεύουν δικαιώματα, διατηρούν τον ανθρώπινο έλεγχο και ενισχύουν τη δημοκρατική λογοδοσία. Η Τεχνητή Νοημοσύνη πρέπει να υπηρετεί τον άνθρωπο, τη δημοκρατία και το δημόσιο συμφέρον. Η Κύπρος έχει την ευκαιρία να αποτελέσει όχι μόνο χώρα ταχείας υιοθέτησης της ΤΝ, αλλά πρότυπο μικρού, ευέλικτου και δημοκρατικά υπεύθυνου κράτους." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Yiannis Laouris","9. Μετρήσιμη εφαρμογή, δημόσια λογοδοσία και ανεξάρτητη αξιολόγηση Article / paragraph Sections 1.5 (Implementation Timeline and Success Metrics), 3.11 (Measuring Impact and National KPIs), particularly 3.11.1–3.11.4, 4.1.6 (Continuous Feedback Loop), 5 (Immediate Steps for the Strategy Launch), and Annex F (National KPIs and Measurement Framework). Proposed amendment / recommendation Κάθε στρατηγικός στόχος, πρόγραμμα και σημαντικό έργο να συνδέεται με: • σαφώς καθορισμένο υπεύθυνο φορέα και ονομαστικά καθορισμένη θεσμική ευθύνη, • συγκεκριμένο χρονοδιάγραμμα και ενδιάμεσα ορόσημα, • προβλεπόμενη χρηματοδότηση και συνολικό κόστος κύκλου ζωής, • αρχικές τιμές αναφοράς, ποσοτικούς στόχους και μεθοδολογία μέτρησης, • δείκτες εισροών, εκροών, αποτελεσμάτων και κοινωνικών επιπτώσεων, • ετήσια δημόσια έκθεση προόδου σε ανοικτή και μηχαναγνώσιμη μορφή, • ανεξάρτητη εξωτερική αξιολόγηση σε προκαθορισμένα χρονικά διαστήματα, • δημόσια παρουσίαση και συζήτηση των αποτελεσμάτων στη Βουλή, • μηχανισμό διορθωτικής δράσης όταν υπάρχουν αποκλίσεις ή ανεπαρκή αποτελέσματα. Να δημοσιεύονται επίσης: • σοβαρά περιστατικά αστοχίας, παραβίασης δεδομένων, διακρίσεων ή άλλων επιπτώσεων, • συστήματα που αναστέλλονται, τροποποιούνται ή αποσύρονται, • διορθωτικές ενέργειες και χρόνοι αποκατάστασης, • αποτελέσματα αξιολόγησης δημόσιας αξίας και ικανοποίησης πολιτών, • εκτιμήσεις κόστους-οφέλους και εξοικονόμησης διοικητικού κόστους. Οι εθνικοί δείκτες να περιλαμβάνουν, πέρα από ΑΕΠ, παραγωγικότητα, επενδύσεις και αριθμό επαγγελματιών, δείκτες δικαιωμάτων, εμπιστοσύνης, προσβασιμότητας, ισότητας, ποιότητας εργασίας, ενεργειακής επίπτωσης και επιτυχούς ανθρώπινης επανεξέτασης. Justification Η Στρατηγική ορθά δηλώνει ότι πρέπει να μετρώνται αποτελέσματα και όχι απλώς ο αριθμός έργων ή πιλοτικών εφαρμογών. Για να είναι αυτό εφαρμόσιμο, οι δείκτες πρέπει να συνδέονται με βάσεις αναφοράς, αρμόδιους φορείς, χρηματοδότηση και σαφείς συνέπειες όταν τα αποτελέσματα δεν επιτυγχάνονται. Η λογοδοσία πρέπει να αφορά όχι μόνο την οικονομική και διοικητική απόδοση, αλλά και τις επιπτώσεις στα δικαιώματα, στην κοινωνική συνοχή και στην εμπιστοσύνη. Η διαφάνεια πρέπει να καλύπτει τις επιτυχίες, αλλά και τα λάθη, τις αποτυχίες, τις αναστολές έργων και τα διορθωτικά μέτρα. Αυτό είναι απαραίτητο για πραγματική οργανωσιακή μάθηση και όχι απλώς για επικοινωνιακή παρουσίαση προόδου." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Yiannis Laouris","8. Συμμετοχική και πολυμετοχική διακυβέρνηση Article / paragraph Sections 3.3.1 (Governance Structure), 3.3.1.3 (National AI Taskforce), 3.3.1.5 (National Ethics and Values Committee), 3.3.1.6 (National AI Misinformation and Security Council), 4.1.6 (Continuous Feedback Loop), and 3.11.3–3.11.4. Proposed amendment / recommendation Να δημιουργηθεί μόνιμο Εθνικό Φόρουμ για την ΤΝ και την Ψηφιακή Δημοκρατία, με συμβουλευτικό, συμμετοχικό και αξιολογικό ρόλο στην εφαρμογή και περιοδική αναθεώρηση της Στρατηγικής. Στο Φόρουμ να συμμετέχουν: • η εκτελεστική και η νομοθετική εξουσία, • οι αρμόδιες ανεξάρτητες και ρυθμιστικές αρχές, • πανεπιστήμια, ερευνητικά κέντρα και επαγγελματικές επιστημονικές ενώσεις, • επιχειρήσεις, νεοφυείς εταιρείες και εκπρόσωποι μικρομεσαίων επιχειρήσεων, • εργαζόμενοι, συντεχνίες και επαγγελματικοί φορείς, • οργανώσεις ανθρωπίνων δικαιωμάτων και προστασίας καταναλωτών, • οργανώσεις παιδιών, γονέων, εκπαιδευτικών και νέων, • δημοσιογράφοι, φορείς fact-checking και εκπρόσωποι της κοινωνίας των πολιτών, • εκπρόσωποι ατόμων με αναπηρία, ηλικιωμένων και άλλων ευάλωτων ομάδων, • πολίτες που θα επιλέγονται μέσω δομημένων, αντιπροσωπευτικών διαβουλευτικών διαδικασιών. Το Φόρουμ να: • σχολιάζει το ετήσιο πρόγραμμα εφαρμογής και τις ετήσιες εκθέσεις, • προτείνει νέους δείκτες και τομείς προτεραιότητας, • αναδεικνύει αναδυόμενους κοινωνικούς κινδύνους, • οργανώνει δημόσιες ακροάσεις και θεματικούς διαλόγους, • δημοσιεύει ανεξάρτητη γνώμη πριν από κάθε ουσιώδη αναθεώρηση της Στρατηγικής. Η σύνθεσή του να αποτρέπει την κυριαρχία οποιασδήποτε μίας κατηγορίας συμφερόντων και να εφαρμόζονται κανόνες διαφάνειας και δήλωσης συγκρούσεων συμφερόντων. Justification Η προβλεπόμενη διακυβέρνηση στηρίζεται σε κυβερνητικά, τεχνοκρατικά και εξειδικευμένα σώματα. Αυτά είναι αναγκαία, αλλά δεν υποκαθιστούν τη συνεχή κοινωνική συμμετοχή. Η ΤΝ επηρεάζει διαφορετικές ομάδες με διαφορετικούς τρόπους. Η αναγνώριση κινδύνων, η αξιολόγηση δημόσιας αξίας και η διαμόρφωση κοινωνικής αποδοχής δεν μπορούν να επιτευχθούν μόνο μέσω τεχνικής εμπειρογνωμοσύνης. Η κοινωνία δεν πρέπει απλώς να ενημερώνεται μετά τη λήψη αποφάσεων. Πρέπει να συμμετέχει στον καθορισμό προτεραιοτήτων, στην αναγνώριση επιπτώσεων και στην αξιολόγηση των αποτελεσμάτων." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Yiannis Laouris","7. ΤΝ, εργασία και δίκαιη μετάβαση Article / paragraph Sections 2.5.2 (Objective 2: Responsible productivity), 2.5.5 (Objective 5: Skills and Talent), 3.3.1.7 (National AI Skills Observatory), 3.6 (Talent, Skills and Workforce Transformation), particularly 3.6.3 and 3.6.4, and Annex C – Education and Human Capital Development / FutureAI CY. Proposed amendment / recommendation Να δημιουργηθεί εθνικός μηχανισμός παρακολούθησης των επιπτώσεων της ΤΝ στην απασχόληση, στα επαγγελματικά καθήκοντα, στις συνθήκες εργασίας, στην ποιότητα των θέσεων εργασίας και στις μισθολογικές ανισότητες, με κεντρικό ρόλο του National AI Skills Observatory. Να προβλεφθούν: • έγκαιρη χαρτογράφηση επαγγελμάτων και καθηκόντων που επηρεάζονται, • task-impact assessments πριν από μεγάλης κλίμακας εισαγωγή ΤΝ, • προγράμματα επανακατάρτισης πριν από την απώλεια ή ουσιώδη μεταβολή θέσεων εργασίας, • συμμετοχή εργαζομένων και συντεχνιών στον σχεδιασμό και στην αξιολόγηση συστημάτων που επηρεάζουν την εργασία, • προστασία από αδιαφανή αλγοριθμική πρόσληψη, αξιολόγηση, επιτήρηση, πειθαρχία ή απόλυση, • δικαίωμα ενημέρωσης και ανθρώπινης επανεξέτασης αποφάσεων αλγοριθμικής διαχείρισης, • αξιολόγηση των επιπτώσεων στην ένταση της εργασίας, στην αυτονομία, στην επαγγελματική ευθύνη και στην ψυχική υγεία, • δίκαιη κατανομή των ωφελειών από την αυξημένη παραγωγικότητα, • ειδική υποστήριξη μικρών επιχειρήσεων, αυτοεργοδοτουμένων, μεγαλύτερων σε ηλικία εργαζομένων και ευάλωτων ομάδων, • ετήσια δημόσια έκθεση για μεταβολές στην αγορά εργασίας, συμμετοχή σε επανακατάρτιση και πραγματικά αποτελέσματα απασχόλησης. Οι δείκτες επιτυχίας να μετρούν όχι μόνο αριθμούς καταρτισθέντων ή νέων ειδικών, αλλά διατήρηση απασχόλησης, ποιότητα εργασίας, επαγγελματική κινητικότητα και κατανομή των παραγωγικών ωφελειών. Justification Η Στρατηγική δηλώνει ότι η ΤΝ θα χρησιμοποιείται για ενίσχυση και όχι αντικατάσταση της ανθρώπινης εργασίας και προβλέπει επανακατάρτιση. Χρειάζεται, όμως, σαφέστερος μηχανισμός πρόληψης, συμμετοχής και αξιολόγησης των πραγματικών συνεπειών. Η αύξηση της παραγωγικότητας δεν πρέπει να αποτελεί τον μοναδικό δείκτη επιτυχίας. Μπορεί να συνυπάρξει με εντατικοποίηση της εργασίας, αποδυνάμωση επαγγελματικής αυτονομίας, αδιαφανή επιτήρηση ή άνιση κατανομή των ωφελειών. Η δίκαιη μετάβαση απαιτεί έγκαιρη πρόβλεψη, κοινωνικό διάλογο και δυνατότητα παρέμβασης πριν οι επιπτώσεις καταστούν μη αναστρέψιμες." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Yiannis Laouris","6. Διαφανείς, ελέγξιμες και υπεύθυνες δημόσιες προμήθειες ΤΝ Article / paragraph Sections 2.5.7, 2.5.8 (Sovereign Capability through Partnerships), 3.1.2 (Design Principles), 3.3.2 (Control Framework), 3.4.1 (Priority Areas for Government Adoption and AI-first procurement), 3.6.3 (Public-Sector Capability), and Annex B. Proposed amendment / recommendation Να θεσπιστεί ειδικό, δεσμευτικό πλαίσιο για τις δημόσιες προμήθειες συστημάτων ΤΝ, το οποίο να υπερβαίνει τα συνήθη κριτήρια τιμής και βασικής τεχνικής επάρκειας. Κάθε σχετική σύμβαση να διασφαλίζει: • πρόσβαση του κράτους σε επαρκή τεχνική τεκμηρίωση, • δυνατότητα ανεξάρτητου τεχνικού, νομικού, δεοντολογικού και κυβερνοασφαλιστικού ελέγχου, • σαφείς όρους για την κυριότητα, τη χρήση, την επαναχρησιμοποίηση και τη διαγραφή δεδομένων, • δυνατότητα μεταφοράς δεδομένων, μοντέλων και υπηρεσιών σε άλλο προμηθευτή, • αποφυγή τεχνολογικού εγκλωβισμού και αδικαιολόγητης αποκλειστικότητας, • διαλειτουργικότητα, φορητότητα και χρήση ανοικτών προτύπων όπου είναι εφικτό, • τεκμηριωμένη απόδοση, ακρίβεια και καταλληλότητα για τον συγκεκριμένο σκοπό, • συνεχή παρακολούθηση αστοχιών, μεροληψίας και μεταβολής απόδοσης, • ρήτρες ευθύνης, διόρθωσης, αποζημίωσης, αναστολής και ασφαλούς τερματισμού, • πλήρη audit logs και διατήρηση αποδεικτικών στοιχείων, • δημοσιοποίηση του συνολικού κόστους κύκλου ζωής και των μετρήσιμων αποτελεσμάτων, • αξιολόγηση της ενεργειακής και περιβαλλοντικής επίπτωσης όπου αυτή είναι ουσιώδης. Να καθοριστούν πρότυπα τεύχη προδιαγραφών και συμβατικών ρητρών από την Εθνική Αρχή ΤΝ, σε συνεργασία με το Γενικό Λογιστήριο, τη Νομική Υπηρεσία, τις αρμόδιες εποπτικές αρχές και ανεξάρτητους εμπειρογνώμονες. Justification Η Στρατηγική προτείνει μετάβαση προς AI-first procurement και ενσωματώνει control gates πριν από την προμήθεια και την ανάπτυξη. Χωρίς ειδικούς συμβατικούς και τεχνικούς κανόνες, όμως, το κράτος κινδυνεύει να αγοράζει συστήματα τα οποία δεν μπορεί να ελέγξει, να μεταφέρει, να διορθώσει ή να παύσει με ασφάλεια. Η εξάρτηση από κλειστά συστήματα και αποκλειστικούς προμηθευτές μπορεί να περιορίσει την ψηφιακή κυριαρχία, να αυξήσει το μακροπρόθεσμο κόστος και να δυσχεράνει τον έλεγχο της νομιμότητας και της αποτελεσματικότητας. Η υπεύθυνη προμήθεια αποτελεί κρίσιμο σημείο πρόληψης. Πολλοί κίνδυνοι μπορούν να περιοριστούν μόνο εάν οι κατάλληλες απαιτήσεις ενσωματωθούν πριν από την υπογραφή της σύμβασης και όχι μετά την έναρξη λειτουργίας." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Yiannis Laouris","5. Προστασία παιδιών και εφήβων Article / paragraph Sections 2.5.5 (Objective 5: Skills and Talent), 3.6.1 (AI Literacy and Awareness), 3.9 (Ethics, Trust and Responsible AI), Annex C – Education and Human Capital Development, including the Cyprus AI Literacy Framework (CALF) and the Ethical Pedagogical Validation Layer (EPVL). Proposed amendment / recommendation Η προστασία παιδιών και εφήβων να αποτελέσει αυτοτελή, οριζόντια και μετρήσιμη προτεραιότητα της Εθνικής Στρατηγικής και όχι μόνο διάσταση της εκπαίδευσης ή της ψηφιακής παιδείας. Να συμπεριληφθούν συγκεκριμένα μέτρα για: • περιορισμό εθιστικών, χειριστικών και παραπλανητικών σχεδιαστικών πρακτικών, • προστασία από την αλγοριθμική προώθηση αυτοκαταστροφικού, βίαιου, σεξουαλικού ή άλλου βλαβερού περιεχομένου, • αποτροπή της εμπορικής εκμετάλλευσης προσωπικών δεδομένων ανηλίκων, • προστασία από grooming, σεξουαλική εκμετάλλευση, πλαστοπροσωπία και τεχνητά παραγόμενο κακοποιητικό υλικό, • ασφαλή, ηλικιακά κατάλληλη και παιδαγωγικά τεκμηριωμένη χρήση συστημάτων παραγωγικής ΤΝ στην εκπαίδευση, • ανεξάρτητη αξιολόγηση εκπαιδευτικών συστημάτων ΤΝ πριν από ευρεία εφαρμογή, • εκπαίδευση παιδιών, γονέων, εκπαιδευτικών, επαγγελματιών ψυχικής υγείας και λειτουργών προστασίας, • εύχρηστους και ασφαλείς μηχανισμούς αναφοράς, υποστήριξης και αποκατάστασης, • συστηματική έρευνα και παρακολούθηση των επιπτώσεων των ΜΚΔ και της ΤΝ στην ψυχική υγεία, στη γνωστική ανάπτυξη και στις κοινωνικές σχέσεις. Οι δείκτες εφαρμογής να περιλαμβάνουν όχι μόνο επίπεδα AI literacy, αλλά και δείκτες ασφάλειας, ευημερίας, προσβασιμότητας και ισότιμης συμμετοχής. Justification Το Annex C περιλαμβάνει σημαντικά στοιχεία, όπως ηλικιακά διαβαθμισμένο πλαίσιο AI literacy και μηχανισμό παιδαγωγικής επικύρωσης. Ωστόσο, η προστασία των ανηλίκων δεν εξαντλείται στη σχολική χρήση της ΤΝ. Τα παιδιά αποτελούν αναπτυσσόμενα άτομα με αυξημένη ευαλωτότητα σε χειριστικές τεχνικές, κοινωνική σύγκριση, ακατάλληλο περιεχόμενο, πλαστοπροσωπία και αλγοριθμική ενίσχυση βλαβερών προτύπων. Η ψηφιακή και αλγοριθμική παιδεία πρέπει να συνδυάζεται με πρόληψη, ασφαλή σχεδιασμό, λογοδοσία των παρόχων και προσβάσιμους μηχανισμούς προστασίας. Η Εθνική Στρατηγική πρέπει να αντιμετωπίζει τον ανήλικο ως φορέα ειδικών δικαιωμάτων και όχι απλώς ως μελλοντικό χρήστη ή εργαζόμενο." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Yiannis Laouris","4. ΜΚΔ, deepfakes, παραπληροφόρηση και δημοκρατική ακεραιότητα Article / paragraph Sections 3.3.1.6 (National AI Misinformation and Security Council), 3.9.2–3.9.6 (Ethics, Trust and Responsible AI), 3.13 (Risk Management, Resilience and Adaptation), Annex A (Ethics and Fundamental Rights), and the Strategy-wide provisions on trustworthy and human-centred AI. Proposed amendment / recommendation Να διευρυνθεί και να εξειδικευτεί η εντολή του National AI Misinformation and Security Council και να προστεθεί αυτοτελές πλαίσιο δράσης για τις επιπτώσεις της παραγωγικής ΤΝ και των Μέσων Κοινωνικής Δικτύωσης στη δημοκρατία, στην ενημέρωση και στην εκλογική διαδικασία. Το πλαίσιο να περιλαμβάνει: • εθνικό πρωτόκολλο ταχείας αναγνώρισης, επαλήθευσης και δημόσιας επισήμανσης deepfakes, • ειδικό σχέδιο προστασίας εκλογών και δημοψηφισμάτων, • πλήρη διαφάνεια στην ψηφιακή πολιτική διαφήμιση, στη χρηματοδότηση και στη στόχευσή της, • υποχρεωτική και ευδιάκριτη σήμανση περιεχομένου που παράγεται ή αλλοιώνεται ουσιωδώς μέσω ΤΝ, • μηχανισμούς εντοπισμού συντονισμένης μη αυθεντικής συμπεριφοράς, δικτύων ψεύτικων λογαριασμών και αυτοματοποιημένης χειραγώγησης, • πρωτόκολλα για περιπτώσεις πλαστοπροσωπίας δημόσιων προσώπων, δημοσιογράφων και κρατικών υπηρεσιών, • συνεργασία κράτους, Βουλής, πανεπιστημίων, δημοσιογράφων, ρυθμιστικών αρχών και οργανώσεων της κοινωνίας, • πρόσβαση ανεξάρτητων ερευνητών σε κατάλληλα δεδομένα για τη μελέτη συστημικών κινδύνων των πλατφορμών, • ετήσια δημόσια έκθεση για απειλές, περιστατικά, τάσεις και μέτρα αντιμετώπισης. Να διασφαλίζεται ότι τα μέτρα προστατεύουν τη δημοκρατική διαδικασία χωρίς να εγκαθιδρύουν μηχανισμό κρατικής λογοκρισίας ή αδικαιολόγητο περιορισμό της ελευθερίας έκφρασης. Justification Η Στρατηγική αναγνωρίζει την παραπληροφόρηση ως πεδίο εποπτείας, αλλά η προβλεπόμενη εντολή παραμένει γενική. Τα ΜΚΔ και η παραγωγική ΤΝ έχουν πλέον καταστεί κρίσιμες υποδομές της δημόσιας σφαίρας και μπορούν να επηρεάσουν άμεσα την πολιτική συμμετοχή, τις εκλογές και την εμπιστοσύνη στους θεσμούς. Η μαζική παραγωγή παραπλανητικού περιεχομένου, η πλαστοπροσωπία, η αδιαφανής μικροστόχευση και η αυτοματοποιημένη προπαγάνδα απαιτούν σαφείς διαδικασίες πρόληψης, ταχείας αντίδρασης και δημόσιας λογοδοσίας. Η παρέμβαση πρέπει να είναι δικαιωματικά ισορροπημένη: να αντιμετωπίζει τη συντονισμένη χειραγώγηση και την εξαπάτηση, διαφυλάσσοντας ταυτόχρονα την ελευθερία έκφρασης, τον πλουραλισμό και την ανεξαρτησία της δημοσιογραφίας." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Yiannis Laouris","3. Χάρτης Δικαιωμάτων του Πολίτη απέναντι στην ΤΝ Article / paragraph Sections 1.1 (Human-Centred AI, Trust and Transparency, and Social Contract Rights Protection), 1.4.8 (Ethics, Trust and Responsible AI), 2.5.7, 3.1.2 (Design Principles), 3.4.3 (Human Oversight and Accountability), 3.9.3–3.9.6, and Annex A (Ethics and Fundamental Rights). Proposed amendment / recommendation Η Εθνική Στρατηγική να συνοδεύεται από σαφή και κατανοητό Χάρτη Δικαιωμάτων του Πολίτη όταν αυτός αλληλεπιδρά με σύστημα ΤΝ ή επηρεάζεται από αυτοματοποιημένη ή αλγοριθμικά υποβοηθούμενη απόφαση. Ο Χάρτης να κατοχυρώνει τουλάχιστον: • το δικαίωμα ενημέρωσης ότι χρησιμοποιείται σύστημα ΤΝ, • το δικαίωμα σε ουσιαστική και κατανοητή εξήγηση της απόφασης ή σύστασης, • το δικαίωμα ανθρώπινης παρέμβασης, επανεξέτασης και υπερίσχυσης της ανθρώπινης κρίσης, • το δικαίωμα ένστασης, αποτελεσματικής προσφυγής και έγκαιρης αποκατάστασης, • το δικαίωμα πρόσβασης και διόρθωσης λανθασμένων ή ελλιπών δεδομένων, • την προστασία από διακρίσεις και αλγοριθμική μεροληψία, • την προστασία της ιδιωτικότητας και τον περιορισμό της χρήσης δεδομένων στον δηλωμένο σκοπό, • το δικαίωμα πρόσβασης σε εναλλακτικό, μη αποκλειστικά ψηφιακό τρόπο εξυπηρέτησης, • το δικαίωμα ενημέρωσης για τον υπεύθυνο φορέα και τον τρόπο υποβολής παραπόνου. Να καθοριστεί ρητά ότι καμία κρίσιμη απόφαση για κοινωνικές παροχές, υγεία, εκπαίδευση, εργασία, φορολογία, αστυνόμευση, μετανάστευση, αδειοδότηση ή πρόσβαση σε δημόσιες υπηρεσίες δεν θα λαμβάνεται αποκλειστικά από αυτοματοποιημένο σύστημα. Justification Η Στρατηγική αναγνωρίζει ήδη την εξηγησιμότητα, την αμφισβήτηση, την ανθρώπινη επανεξέταση και την ανθρώπινη εποπτεία. Οι αρχές αυτές πρέπει να μετατραπούν σε συγκεκριμένα, εύκολα αναγνωρίσιμα και εφαρμόσιμα δικαιώματα. Ο πολίτης δεν αρκεί να πληροφορείται ότι ένα σύστημα χαρακτηρίζεται «υπεύθυνο» ή «αξιόπιστο». Πρέπει να γνωρίζει τι δικαιούται να απαιτήσει, ποιος φέρει ευθύνη, σε ποιον μπορεί να απευθυνθεί και μέσα σε ποιο χρονικό διάστημα πρέπει να λάβει απάντηση. Ένας ενιαίος Χάρτης θα ενισχύσει τη νομική σαφήνεια, τη διοικητική συνέπεια και την εμπιστοσύνη, ιδιαίτερα σε περιπτώσεις όπου οι αποφάσεις επηρεάζουν ουσιωδώς δικαιώματα ή την καθημερινή ζωή." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Yiannis Laouris","2. Δημόσιο μητρώο συστημάτων ΤΝ του κράτους Article / paragraph Sections 2.5.7, 3.3 (Governance and Controls), 3.3.2 (Control Framework), 3.4 (AI Adoption Across Government), 3.9.3 (Transparency and Explainability), 3.9.6 (AI Social Contract Principles), and Annex B (AI Use Case Lifecycle and Control Gates). Proposed amendment / recommendation Να δημιουργηθεί δημόσιο, ενιαίο και διαρκώς ενημερωμένο μητρώο όλων των συστημάτων ΤΝ και των ουσιωδών αλγοριθμικών εργαλείων που χρησιμοποιούνται, αναπτύσσονται, δοκιμάζονται ή προμηθεύονται από υπουργεία, υφυπουργεία, δήμους, οργανισμούς δημοσίου δικαίου και άλλους δημόσιους φορείς. Για κάθε σύστημα να δημοσιεύονται, στον βαθμό που δεν επηρεάζεται η εθνική ασφάλεια, η κυβερνοασφάλεια ή νόμιμο εμπορικό απόρρητο: • ο σκοπός και το πεδίο χρήσης, • ο υπεύθυνος δημόσιος φορέας και ο αρμόδιος λειτουργός, • ο κατασκευαστής, προμηθευτής ή φορέας ανάπτυξης, • οι βασικές κατηγορίες δεδομένων που χρησιμοποιούνται, • η ταξινόμηση κινδύνου και η νομική βάση, • οι προβλεπόμενες μορφές ανθρώπινης εποπτείας, • η κατάσταση έγκρισης και το στάδιο του κύκλου ζωής, • οι εκτιμήσεις επιπτώσεων και οι έλεγχοι συμμόρφωσης, • οι διαδικασίες ενημέρωσης, ένστασης και ανθρώπινης επανεξέτασης, • τα αποτελέσματα ελέγχων ακρίβειας, μεροληψίας και ασφάλειας, • το κόστος ανάπτυξης, αγοράς, αδειοδότησης και συντήρησης, • τυχόν σοβαρά περιστατικά, αναστολές ή αποσύρσεις. Το μητρώο να συνδέεται με τα control gates του Annex B και να ενημερώνεται πριν από την επιχειρησιακή χρήση κάθε συστήματος και μετά από κάθε ουσιώδη τροποποίησή του. Justification Η Στρατηγική απαιτεί τεκμηρίωση, ιχνηλασιμότητα, ελεγκτικότητα, ταξινόμηση κινδύνου και συνεχή παρακολούθηση, αλλά δεν τα μετατρέπει με σαφήνεια σε ενιαίο δημόσιο μηχανισμό πληροφόρησης. Ο πολίτης πρέπει να γνωρίζει πότε και με ποιον τρόπο χρησιμοποιείται ΤΝ κατά την άσκηση δημόσιας εξουσίας ή την παροχή υπηρεσιών. Το μητρώο θα ενισχύσει τη διαφάνεια, θα επιτρέψει ουσιαστικό κοινοβουλευτικό, επιστημονικό και κοινωνικό έλεγχο, θα περιορίσει τις αλληλοεπικαλύψεις και θα διευκολύνει τη συμμόρφωση με το ευρωπαϊκό θεσμικό πλαίσιο. Η δημοσιοποίηση δεν απαιτεί αποκάλυψη πηγαίου κώδικα ή πληροφοριών που δημιουργούν κίνδυνο ασφάλειας. Απαιτεί, όμως, επαρκή διαφάνεια ώστε η λειτουργία του ψηφιακού κράτους να μην μετατρέπεται σε αδιαφανή άσκηση εξουσίας." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Yiannis Laouris","1. Μόνιμος μηχανισμός κοινοβουλευτικής εποπτείας Article / paragraph Sections 2.5.7 (Objective 7: Embed strong governance, ethics and accountability across all AI use), 3.3 (Governance and Controls), 3.3.1 (Governance Structure), 3.11.3 (Monitoring and Reporting), and 4.1.2 (Governance and Policy Foundations). Proposed amendment / recommendation Να προστεθεί ρητή πρόνοια για θεσμική και συστηματική κοινοβουλευτική εποπτεία της εφαρμογής της Εθνικής Στρατηγικής για την Τεχνητή Νοημοσύνη. Η εποπτεία μπορεί να ασκείται μέσω ειδικής κοινοβουλευτικής επιτροπής ή, ως μεταβατική λύση, μέσω μόνιμης διακομματικής υπο-επιτροπής ή θεσμοθετημένου μηχανισμού συντονισμού μεταξύ των αρμόδιων κοινοβουλευτικών επιτροπών. Ο μηχανισμός αυτός πρέπει να παρακολουθεί: • την εφαρμογή της Εθνικής Στρατηγικής και την πρόοδο έναντι των εθνικών δεικτών, • τη συμμόρφωση με τον ευρωπαϊκό Κανονισμό για την ΤΝ και το ευρύτερο ευρωπαϊκό ψηφιακό κεκτημένο, • τη χρήση συστημάτων ΤΝ από το κράτος και τους οργανισμούς δημοσίου δικαίου, • τις δημόσιες συμβάσεις, τις σχετικές δαπάνες και την τεχνολογική εξάρτηση, • τις επιπτώσεις στην εργασία, την εκπαίδευση, την υγεία, την ασφάλεια και τα ανθρώπινα δικαιώματα, • την παραπληροφόρηση, τα deepfakes, την πολιτική μικροστόχευση και την εκλογική ακεραιότητα, • την προστασία παιδιών, εφήβων και άλλων ευάλωτων ομάδων στο ψηφιακό περιβάλλον. Να προβλέπεται τουλάχιστον ετήσια παρουσίαση στη Βουλή από την Εθνική Αρχή ΤΝ, με δημόσια συζήτηση της έκθεσης προόδου, των σημαντικών περιστατικών, των αποκλίσεων από τους στόχους και των αναγκαίων διορθωτικών μέτρων. Justification Η προτεινόμενη δομή διακυβέρνησης είναι κατά κύριο λόγο εκτελεστική και τεχνοκρατική. Προβλέπει Εθνική Αρχή ΤΝ, Διυπουργικό Συμβούλιο, συμβουλευτικά και εποπτικά σώματα, χωρίς όμως να εντάσσει ρητά τη νομοθετική εξουσία στη συνεχή εποπτεία της εφαρμογής. Η ΤΝ επηρεάζει την άσκηση δημόσιας εξουσίας, την κατανομή δημόσιων πόρων, τα δικαιώματα των πολιτών, την αγορά εργασίας και τη δημοκρατική διαδικασία. Η λογοδοσία, επομένως, δεν μπορεί να εξαντλείται σε εσωτερική διοικητική παρακολούθηση. Η αποσπασματική εξέταση θεμάτων ΤΝ από διαφορετικές κοινοβουλευτικές επιτροπές δεν εξασφαλίζει θεσμική μνήμη, οριζόντιο συντονισμό και συνεχή εξειδίκευση. Ένας σταθερός κοινοβουλευτικός μηχανισμός θα συμπληρώσει, χωρίς να υποκαταστήσει, τα εκτελεστικά και ρυθμιστικά όργανα της Στρατηγικής." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",Stephania,"The National AI Strategy for Cyprus is a strong, an ambitious, comprehensive and pragmatic roadmap that seeks to transform the island’s public service and economy. It is a strong and honest strategy that aims for long-term resilience across sectors and sets an important precedent for future government strategies. I appreciate that it makes an honest assessment of the existing weaknesses and gaps, and I believe this can also serve as an impetus to close these. The principles of human-centred and ethical AI, trust and accountability are cross-cutting issues that are mentioned across the document and this is also an important element when re-designing government services. The strategic philosophy behind this strategy is that AI can be an enabler of productivity and public sector transformation, and a strategic asset to enhance national resilience in many ways, always when developed and deployed responsibly and with oversight, and within an EU framework. The below feedback in this e-consultation, although valuable and constructive, I believe cannot all be reflected in the document due to some obvious reasons: 1. The strategy will end up becoming too long, exhaustive and will result into a politicized document, which would go against the very purpose of the strategy, which is to serve as a guiding, overarching document for a whole-of-government reform. 2. And because the technical, bureaucratic details addressed can be put forth in posterity, to the appropriate ministries and institutions. After reading the document, I would like to provide the following feedback: On page 2: on the bullet point referring to “Human Oversight and Social Rights Protection”, I would add in the last sentence “in sensitive areas like health…and private data”. Privacy of data are of outmost importance to citizens and this needs to be explicitly stated. Page 3: Under 1.3, first bullet point on Government and Public Sector: adding “data re-categorization/classification”. Justification: Data re-categorization for AI is the process of updating, cleaning, and restructuring how information is labeled and organized so that machine learning models and language tools can understand it better. It involves defining clear categories, removing old or messy tags, and using automated tools to re-tag files or databases (Forbes, 2025). This is important as public institutions tend to suffer from fragmented data, old datasets and outdate legacy systems. Data modernization (mentioned in page 10) requires first data classification, which is about understanding what private data exist and where it resides. Under that same section 1.3 I would also add a bullet point “Cybersecurity”. Although it is mentioned later in the document, in the executive summary it is not, and I believe it is a very important element to add in that list of priority sectors for leadership. Could also be added under 1.4.2 “Data as a Strategic National Asset”. Page 14, under section 2.4.1 “Priority Sectors for Leadership”: Here I would suggest the addition of another sector, which should also be of national importance. It would be valuable to consider the addition something similar to Urban (Re)Development: Using AI for city and rural digital twins for natural disaster risk management, such as wildfires and flooding, is a of existential matter to us. Considering the reality we are currently facing, with extremely high temperatures and wildfires, and flood during sudden rainfall, for which Cyprus is usually unprepared, embedding AI applications for predictive analytics and forecasting, as well as the re-design of public spaces and urban life should be seen as a priority. The qualitative assessment of such initiatives can be life-saving and can usher a new, more proactive and sustainable future for the island and its people. Could also promote cost-efficient ways of using energy, while helping design smarter, environmentally friendly buildings, public housing and spaces. Environment is not mentioned in strategy, and I believe that it should be seen as an urgent, priority sector for public leadership. Page 16 under 2.5.4 “Transform public services through AI-enabled delivery”: First sentence “AI will be used to modernize public administration and improve service delivery *on a national and municipal level*. Justification: because it is important to understand that albeit the national government is the guiding institution and provides the mandate and resources, local governance is an important element in the implementation of all these national initiatives. Local governance accounts for a lot of the local service delivery that meets the needs of people in a specific neighborhood or village. Extending that mandate to them, and including them in the strategy as part of the wider governance ecosystem, while providing them with the relevant resources and capacity-building can help strengthen local, public service delivery. Page 29: Under 3.4.5 Capacity Building and Change Management. Consider adding concepts such as systems thinking and mapping. These include identifying actors, actions, data gaps and interconnectedness of issues- Important for innovation, alignment of solutions, and for promoting a product operating model for AI. This means creating a new, permanent, cross-functional teams and method of working that manage and improve digital products after they go live." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",sertriant,"The Cyprus National AI Strategy 2032 constitutes an important and timely framework for the country’s digital, economic and institutional transformation. Its vision of establishing Cyprus as a trusted artificial intelligence hub in the Eastern Mediterranean, a reliable European jurisdiction for AI-enabled services and a bridge between the European Union and neighbouring regions is ambitious and broadly consistent with Cyprus’s economic structure, institutional position and comparative advantages. The emphasis placed on trustworthy, human-centred and responsible AI, together with the focus on economic productivity, public-sector modernisation, skills development, research, innovation and digital sovereignty, provides a sound foundation for national action up to 2032. The Strategy appropriately recognises that the successful adoption of AI depends not only on technology, but also on data quality, institutional capacity, governance, skills, infrastructure and public trust. Its eight National Strategic Objectives offer a coherent framework for strengthening Cyprus’s position as a trusted jurisdiction, increasing national productivity, developing an inclusive AI ecosystem, transforming public services, expanding the national talent base, securing data and infrastructure, embedding ethics and accountability, and developing sovereign capability through trusted partnerships. The identification of priority sectors, including government, financial services, healthcare, tourism, legal services, education, shipping and entrepreneurship, is also well aligned with the structure of the Cypriot economy and the areas in which AI could generate significant public and economic value. To strengthen the Strategy’s implementation, it is proposed that the final document be accompanied by a detailed, costed and regularly updated Action Plan for the period 2026–2032. The Strategy already establishes an implementation timeline, immediate actions, responsible governance structures and indicative success metrics. These provisions could be further developed by specifying, for each major action, the responsible organisation, implementation lead, timetable, interim milestones, expected deliverables, estimated budget, funding source, staffing requirements and technological dependencies. The Action Plan should also identify the principal legal, operational, cybersecurity and procurement risks associated with each initiative, together with the measures required to manage them. Particular attention should be given to the full lifecycle cost of national AI investments. The financial assessment of each initiative should not be limited to the initial development or procurement cost, but should also cover operation, maintenance, cybersecurity, auditing, data management, model monitoring, licensing, technical support, upgrading and eventual replacement or decommissioning. This would support more realistic budgeting, improve long-term sustainability and reduce the risk of launching projects that cannot subsequently be maintained or scaled. The proposed governance structure is comprehensive and reflects the need for central coordination combined with decentralised implementation. The establishment or designation of a National AI Authority, an Interministerial AI Council, specialised monitoring and advisory bodies, innovation structures, AI Officers and AI Champions can provide the institutional capacity needed for effective delivery. However, the number of bodies involved may create risks of overlapping responsibilities, fragmented decision-making and delays unless their mandates and relationships are defined with precision. It is therefore recommended that the final Strategy include a clear governance and accountability matrix covering all bodies involved in implementation. The matrix should identify which body sets policy, which body approves initiatives, which body is responsible for implementation, which body performs regulatory or ethical oversight and which body remains accountable for outcomes. It should also establish procedures for resolving institutional disagreements, escalating high-risk matters, addressing delays and responding to implementation failures. The National AI Authority should have a clear legal and institutional basis, sufficient resources, specialised personnel and appropriate functional autonomy, while remaining subject to transparent accountability arrangements and without displacing the responsibilities of ministries, public bodies or existing competent authorities. The Strategy correctly seeks to avoid the proliferation of disconnected pilot projects and promotes a use-case-driven approach based on measurable value. To operationalise this principle, Cyprus should initially concentrate resources on a limited portfolio of high-impact flagship projects. These projects should be selected according to transparent criteria, including their expected benefit for citizens and businesses, contribution to productivity, capacity to reduce administrative burden, availability and quality of the required data, organisational readiness, level of legal and ethical risk, cost-effectiveness and potential for reuse across multiple public bodies or sectors. Each pilot project should have predetermined entry and exit criteria. Before development begins, the responsible authority should define the problem being addressed, the expected benefits, the baseline against which progress will be measured and the conditions under which the project will proceed to production, be redesigned, expanded or terminated. Scaling should take place only where an independent or appropriately qualified evaluation demonstrates clear public or economic value, legal compliance, technical reliability and acceptable levels of risk. This approach would reinforce the Strategy’s stated commitment to value-driven deployment and prevent the accumulation of experimental systems that do not produce sustainable outcomes. The Strategy’s measurement framework is a positive element, particularly its focus on productivity, economic growth, skills, investment, adoption, trust and compliance. Nevertheless, the indicative National KPI and Measurement Framework should be converted into a final, operational and verifiable monitoring system. Each principal indicator should include a baseline value, a numerical target, a target date, a defined data source, a measurement methodology, a reporting frequency and a clearly identified organisation responsible for collection and verification. The national indicators should measure outcomes rather than activity alone. In addition to measuring the number of projects, professionals trained or organisations adopting AI, the framework should assess actual changes in service-processing times, administrative costs, workforce productivity, accessibility, citizen satisfaction, business competitiveness, innovation outputs, investment attraction and public trust. Where macroeconomic objectives such as productivity and GDP impact are retained, the final framework should clarify the assumptions, methodology and external variables affecting those projections. This would allow progress to be assessed transparently and would distinguish the direct contribution of the Strategy from broader economic developments. It is further proposed that the Government publish a consolidated annual progress report on the implementation of the Strategy. The report should present the status of each principal action, expenditure against budget, progress against milestones, measurable outcomes, identified risks and any corrective measures adopted. Core implementation data should be made available in an accessible and reusable format, subject to legitimate security and confidentiality limitations. This would strengthen transparency, public accountability and independent evaluation while supporting informed adjustments to the Strategy. The human-centred approach contained in the Strategy is strongly supported. The principles of human oversight, transparency, explainability, fairness, non-discrimination, accountability and access to redress should be translated into clear operational requirements for all high-impact and citizen-facing AI systems. Individuals should be informed in plain and accessible language when they are interacting with an AI system or when an AI system has materially contributed to a decision affecting them. Where decisions concern healthcare, social benefits, education, employment, licensing, access to public services or other sensitive matters, citizens should have access to meaningful human review, an understandable explanation and an effective procedure for contesting the outcome. Human oversight should be substantive rather than merely formal. Officials responsible for reviewing an AI-assisted decision should have the authority, competence, information and time required to question or overturn the system’s output. The respective responsibilities of the public authority, system provider, operator and individual decision-maker should be documented in advance. No AI system should weaken the accountability of the public body legally responsible for the decision or service concerned. Data governance is appropriately treated as a foundational requirement of the Strategy. The development of a federated national data architecture, common standards, secure interfaces, controlled access mechanisms and appropriate national data infrastructure can support interoperability while avoiding the unnecessary centralisation of sensitive information. The proposed National Intelligent Digital API Fabric and national data layer should be implemented through strong privacy, security, access-control, auditability and data-quality requirements. Before data are reused for AI development or operation, the responsible organisation should demonstrate that the intended use is lawful, necessary, proportionate and compatible with the purpose for which the data were collected. Clear rules should govern data ownership, stewardship, access, retention, anonymisation, correction and deletion. Particular care is required in relation to health, financial, biometric, social and other sensitive data. Secure research environments and controlled-access mechanisms should be used where open access would create unacceptable risks. Cybersecurity and operational resilience should remain central throughout the lifecycle of every AI system. High-impact systems should be subject to proportionate legal, ethical, data-protection, cybersecurity and fundamental-rights impact assessments before procurement or deployment. They should also undergo appropriate testing for reliability, bias, security vulnerabilities, adversarial manipulation and performance deterioration. Monitoring should continue after deployment, with clearly defined procedures for incident reporting, investigation, remediation, suspension and withdrawal where a system no longer meets legal, ethical, security or performance requirements. The Strategy’s focus on skills and workforce transformation is also strongly supported. AI education should address different levels of need across society, from basic AI literacy for citizens and school students to advanced technical, legal, ethical and sector-specific skills for professionals. Public officials, managers, educators, healthcare professionals, lawyers, accountants and employees in tourism, finance and shipping require training that reflects their responsibilities and the particular risks of their sectors. Training should not focus only on the use of AI tools, but also on their limitations. Participants should be able to assess the reliability of outputs, identify bias and fabricated information, protect confidential and personal data, understand when human intervention is required and recognise situations in which AI should not be used. Upskilling and reskilling programmes should be informed by labour-market evidence and should provide meaningful support to workers whose tasks or occupations are likely to be significantly affected by automation. The Strategy should place particular emphasis on small and medium-sized enterprises, which form a central part of the Cypriot economy but may lack the financial capacity, technical expertise, data resources and compliance knowledge required for responsible AI adoption. SMEs should be provided with access to technical guidance, shared computing resources, secure testing environments, training, regulatory support and appropriately designed funding schemes. Public procurement processes should also facilitate the participation of Cypriot startups and SMEs, provided that all requirements relating to security, quality, transparency and accountability are met. Public procurement will be one of the principal mechanisms through which the State influences the development and use of AI. Procurement rules and model contractual clauses should therefore address data rights, intellectual property, confidentiality, cybersecurity, audit access, documentation, performance standards, human oversight, model updates, subcontracting, incident reporting, liability and termination. Contracts should also provide for data and system portability and an orderly transition to another supplier where necessary. The Strategy’s commitment to interoperability, reuse and technological sovereignty should be reinforced by the systematic use of open standards and portable architectures where appropriate. Cyprus should avoid becoming dependent on a single supplier, proprietary system or infrastructure provider for critical public services. Strategic partnerships can be essential for a country of Cyprus’s size, but they should be structured to secure knowledge transfer, domestic capability development, access to technical documentation, interoperability and long-term institutional resilience. The establishment of centres of excellence, innovation hubs, testbeds and shared infrastructure can help connect research with real-world implementation. Their respective mandates should, however, be clearly differentiated. Public funding should be linked to measurable outputs, collaboration with local institutions, knowledge transfer, skills development and the creation of sustainable economic or social value. Research priorities should remain sufficiently flexible to respond to emerging technological developments while maintaining a clear connection to national needs and the Strategy’s priority sectors. Environmental sustainability should also be integrated into investment and procurement decisions. National AI infrastructure and large-scale AI applications may require significant energy, water and hardware resources. Green AI principles should therefore be converted into measurable requirements relating to energy efficiency, carbon impact, infrastructure utilisation, equipment lifecycle and responsible procurement. Environmental costs should form part of the overall assessment of value and sustainability. Finally, the success of the Strategy will depend on public trust and continued stakeholder participation. Consultation should not end with the adoption of the final document. Permanent mechanisms should be established for engagement with citizens, businesses, universities, research organisations, professional bodies, trade unions, civil-society organisations and groups that may be disproportionately affected by AI systems. Particular attention should be given to persons with disabilities, older persons, individuals with limited digital skills and communities at risk of exclusion from AI-enabled services. In conclusion, the Cyprus National AI Strategy 2032 provides a strong and comprehensive strategic direction. The recommendations set out above do not seek to alter its central vision or strategic objectives, but to strengthen their operational implementation. A detailed and costed Action Plan, clearer governance responsibilities, a finalised measurement framework, transparent annual reporting, enforceable safeguards for citizens, robust procurement and data-governance arrangements, and sustained stakeholder participation would enhance the Strategy’s credibility, accountability and long-term effectiveness. Through disciplined implementation and periodic evidence-based review, Cyprus can develop AI capabilities that support productivity, innovation, institutional resilience and economic growth while safeguarding fundamental rights, public trust and the broader public interest." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",christinaioannou,"Contribution to Strengthening the National Artificial Intelligence Strategy 2032 The National Artificial Intelligence Strategy 2032 provides an ambitious and important foundation for positioning Cyprus as a trusted and competitive jurisdiction for Artificial Intelligence, while strengthening productivity, public-sector transformation, innovation, talent, infrastructure and national AI capabilities. My principal recommendation is not to add another standalone initiative, but to strengthen the Strategy with a National AI Execution & Assurance Architecture that connects strategic objectives with implementation, regulatory requirements, institutional accountability, measurable outcomes and continuous adaptation. The critical challenge for Cyprus through 2032 will not be AI adoption alone. It will be the ability to manage multiple technological, regulatory, financial and institutional dependencies simultaneously, while maintaining strategic coherence and measurable national value. 1. National AI Execution & Assurance Architecture The Strategy could be strengthened through an integrated National AI Execution & Assurance Architecture, serving as the connective layer between national strategy, AI programmes, regulation, implementation and impact. The framework would operate across six interconnected layers: Strategy → Portfolio → Regulatory → Execution → Assurance → Impact** Every major national AI initiative should be traceable throughout its lifecycle, from strategic prioritisation through deployment, operational monitoring and impact assessment. 2. National AI Portfolio Management A unified National AI Portfolio could provide a common management structure for major public AI investments and initiatives. Each strategic initiative should have a standardised execution profile covering: • Strategic objective and expected value • Ownership and accountability • Required data and infrastructure • Regulatory and technological dependencies • Risks and control points • Budget and resource requirements • Milestones and KPIs • Deployment readiness • Measurable socioeconomic and public-sector impact This would shift performance measurement from “how many AI projects are initiated” to “how many generate measurable national value”. 3. AI Lifecycle Governance The Strategy could also be reinforced through a common AI Lifecycle Governance Framework for public-sector AI systems. Significant AI systems should follow controlled lifecycle stages: Identify → Assess → Design → Test → Approve → Deploy → Monitor → Review** Each stage should incorporate appropriate requirements for: • Regulatory compliance • Data protection • Cybersecurity • Risk assessment • Human oversight • Documentation and traceability • Model quality and security • Operational resilience • Post-deployment review and assurance This would position compliance not as a final administrative checkpoint, but as an embedded component of the AI system lifecycle. 4. National AI Readiness & Execution Index A National AI Readiness & Execution Index could provide a consistent mechanism for assessing national and institutional readiness and implementation progress. The Index could measure, among other dimensions: Infrastructure Readiness | Data Readiness | Regulatory Readiness | Institutional Capacity | Talent | Adoption | Security | Economic Impact Such a mechanism would allow government to identify bottlenecks, delivery delays and systemic dependencies at an early stage and adjust resources and priorities before strategic initiatives become stalled or remain permanently at pilot stage. 5. From Pilot to Scale Particular emphasis should be placed on the transition from pilot projects to production-scale deployment. Major AI initiatives should follow a defined pathway: Research → Experimentation → Validation → Governance Approval → Procurement → Deployment → Scaling → Impact Measurement** Clear “stage gates” would reduce the risk of fragmented pilots without a pathway to adoption and ensure that public investment is progressively directed towards solutions demonstrating measurable value, feasibility and institutional readiness. 6. Strategic AI Foresight and Continuous Adaptation The Strategy should ultimately operate as a “living national framework”, rather than as a static long-term plan. AI technologies, geopolitical conditions, European regulation, infrastructure requirements and business models are evolving significantly faster than traditional strategic planning cycles. A structured Annual National AI Strategic Review could therefore assess: • Technological and geopolitical developments • Emerging regulatory requirements • National dependencies • Investment priorities • AI adoption and deployment • Performance of strategic initiatives • Emerging risks • New opportunities for the Cypriot economy This would allow the Strategy to evolve without losing its long-term direction. Conclusion Cyprus does not need to compete with larger countries solely on the scale of infrastructure or investment. It can compete through the quality, agility and coherence of its national AI architecture. A strategic advantage for Cyprus could be its ability to connect AI policy, regulation, data, infrastructure, investment, governance and execution within one coherent national operating framework. The success of the National AI Strategy 2032 should therefore not be measured solely by the adoption of Artificial Intelligence, but by whether Cyprus develops the institutional capacity to prioritise, design, approve, implement, govern, monitor, scale and measure the value of AI systems consistently. The proposed National AI Execution & Assurance Architecture would provide an additional execution layer capable of transforming the Strategy from a framework for national direction into a measurable, adaptive and execution-oriented national AI system through 2032. Submitted by Christina Ioannou Founder & CEO, Arete Strategy AI Ltd Policy, Governance & Regulatory Execution Intelligence www.aretestrategyai.org LinkedIn: https://www.linkedin.com/in/christina-ioannou-8a3bb1177/" "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",christinaioannou,"The National Artificial Intelligence Strategy 2032 provides an ambitious and important foundation for positioning Cyprus as a trusted and competitive jurisdiction for Artificial Intelligence, while strengthening productivity, public-sector transformation, innovation, talent, infrastructure and national AI capabilities My principal recommendation is not to add another standalone initiative, but to strengthen the Strategy with a National AI Execution & Assurance Architecture, that connects strategic objectives with implementation, regulatory requirements, institutional accountability, measurable outcomes and continuous adaptation. The critical challenge for Cyprus through 2032 will not be AI adoption alone. It will be the ability to manage multiple technological, regulatory, financial and institutional dependencies simultaneously, while maintaining strategic coherence and measurable national value. 1. National AI Execution & Assurance Architecture The Strategy could be strengthened through an integrated National AI Execution & Assurance Architecture, serving as the connective layer between national strategy, AI programmes, regulation, implementation and impact. The framework would operate across six interconnected layers: Strategy → Portfolio → Regulatory → Execution → Assurance → Impact Every major national AI initiative should be traceable throughout its lifecycle, from strategic prioritisation through deployment, operational monitoring and impact assessment. 2. National AI Portfolio Management A unified National AI Portfolio could provide a common management structure for major public AI investments and initiatives. Each strategic initiative should have a standardised execution profile covering: * strategic objective and expected value; * ownership and accountability; * required data and infrastructure; * regulatory and technological dependencies; * risks and control points; * budget and resource requirements; * milestones and KPIs; * deployment readiness; * measurable socioeconomic and public-sector impact. This would shift performance measurement from “how many AI projects are initiated” to “how many generate measurable national value”. 3. AI Lifecycle Governance The Strategy could also be reinforced through a common AI Lifecycle Governance Framework for public-sector AI systems. Significant AI systems should follow controlled lifecycle stages: Identify → Assess → Design → Test → Approve → Deploy → Monitor → Review Each stage should incorporate appropriate requirements for: * regulatory compliance; * data protection; * cybersecurity; * risk assessment; * human oversight; * documentation and traceability; * model quality and security; * operational resilience; * post-deployment review and assurance. This would position compliance not as a final administrative checkpoint, but as an embedded component of the AI system lifecycle. 4. National AI Readiness & Execution Index A National AI Readiness & Execution Index could provide a consistent mechanism for assessing national and institutional readiness and implementation progress. The Index could measure, among other dimensions: Infrastructure Readiness | Data Readiness | Regulatory Readiness | Institutional Capacity | Talent | Adoption | Security | Economic Impact Such a mechanism would allow government to identify bottlenecks, delivery delays and systemic dependencies at an early stage and adjust resources and priorities before strategic initiatives become stalled or remain permanently at pilot stage. 5. From Pilot to Scale Particular emphasis should be placed on the transition from **pilot projects to production-scale deployment. Major AI initiatives should follow a defined pathway: Research → Experimentation → Validation → Governance Approval → Procurement → Deployment → Scaling → Impact Measurement Clear “stage gates” would reduce the risk of fragmented pilots without a pathway to adoption and ensure that public investment is progressively directed towards solutions demonstrating measurable value, feasibility and institutional readiness. 6. Strategic AI Foresight and Continuous Adaptation The Strategy should ultimately operate as a “living national framework” , rather than as a static long-term plan. AI technologies, geopolitical conditions, European regulation, infrastructure requirements and business models are evolving significantly faster than traditional strategic planning cycles. A structured “Annual National AI Strategic Revie” could therefore assess: * technological and geopolitical developments; * emerging regulatory requirements; * national dependencies; * investment priorities; * AI adoption and deployment; * performance of strategic initiatives; * emerging risks; * new opportunities for the Cypriot economy. This would allow the Strategy to evolve without losing its long-term direction. Conclusion Cyprus does not need to compete with larger countries solely on the scale of infrastructure or investment. It can compete through the **quality, agility and coherence of its national AI architecture**. A strategic advantage for Cyprus could be its ability to connect **AI policy, regulation, data, infrastructure, investment, governance and execution** within one coherent national operating framework. The success of the National AI Strategy 2032 should therefore not be measured solely by the adoption of Artificial Intelligence, but by whether Cyprus develops the institutional capacity to prioritise, design, approve, implement, govern, monitor, scale and measure the value of AI systems consistently. The proposed National AI Execution & Assurance Architecture would provide an additional execution layer capable of transforming the Strategy from a framework for national direction into a measurable, adaptive and execution-oriented national AI system through 2032. Submitted by: Christina Ioannou Founder & CEO, Areté Strategy AI Ltd Policy, Governance & Regulatory Execution Intelligence https://www.aretestrategyai.org/ https://www.linkedin.com/in/christina-ioannou-8a3bb1177/" "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",christinaioannou,"The National Artificial Intelligence Strategy 2032 provides an ambitious and important foundation for positioning Cyprus as a trusted and competitive jurisdiction for Artificial Intelligence, while strengthening productivity, public-sector transformation, innovation, talent, infrastructure and national AI capabilities My principal recommendation is not to add another standalone initiative, but to strengthen the Strategy with a National AI Execution & Assurance Architecture, that connects strategic objectives with implementation, regulatory requirements, institutional accountability, measurable outcomes and continuous adaptation. The critical challenge for Cyprus through 2032 will not be AI adoption alone. It will be the ability to manage multiple technological, regulatory, financial and institutional dependencies simultaneously, while maintaining strategic coherence and measurable national value. 1. National AI Execution & Assurance Architecture The Strategy could be strengthened through an integrated National AI Execution & Assurance Architecture, serving as the connective layer between national strategy, AI programmes, regulation, implementation and impact. The framework would operate across six interconnected layers: Strategy → Portfolio → Regulatory → Execution → Assurance → Impact Every major national AI initiative should be traceable throughout its lifecycle, from strategic prioritisation through deployment, operational monitoring and impact assessment. 2. National AI Portfolio Management A unified National AI Portfolio could provide a common management structure for major public AI investments and initiatives. Each strategic initiative should have a standardised execution profile covering: * strategic objective and expected value; * ownership and accountability; * required data and infrastructure; * regulatory and technological dependencies; * risks and control points; * budget and resource requirements; * milestones and KPIs; * deployment readiness; * measurable socioeconomic and public-sector impact. This would shift performance measurement from ""how many AI projects are initiated"" to ""how many generate measurable national value"". 3. AI Lifecycle Governance The Strategy could also be reinforced through a common AI Lifecycle Governance Framework for public-sector AI systems. Significant AI systems should follow controlled lifecycle stages: Identify → Assess → Design → Test → Approve → Deploy → Monitor → Review Each stage should incorporate appropriate requirements for: * regulatory compliance; * data protection; * cybersecurity; * risk assessment; * human oversight; * documentation and traceability; * model quality and security; * operational resilience; * post-deployment review and assurance. This would position compliance not as a final administrative checkpoint, but as an embedded component of the AI system lifecycle. 4. National AI Readiness & Execution Index A National AI Readiness & Execution Index could provide a consistent mechanism for assessing national and institutional readiness and implementation progress. The Index could measure, among other dimensions: Infrastructure Readiness | Data Readiness | Regulatory Readiness | Institutional Capacity | Talent | Adoption | Security | Economic Impact Such a mechanism would allow government to identify bottlenecks, delivery delays and systemic dependencies at an early stage and adjust resources and priorities before strategic initiatives become stalled or remain permanently at pilot stage. 5. From Pilot to Scale Particular emphasis should be placed on the transition from **pilot projects to production-scale deployment. Major AI initiatives should follow a defined pathway: Research → Experimentation → Validation → Governance Approval → Procurement → Deployment → Scaling → Impact Measurement Clear ""stage gates"" would reduce the risk of fragmented pilots without a pathway to adoption and ensure that public investment is progressively directed towards solutions demonstrating measurable value, feasibility and institutional readiness. 6. Strategic AI Foresight and Continuous Adaptation The Strategy should ultimately operate as a ""living national framework"" , rather than as a static long-term plan. AI technologies, geopolitical conditions, European regulation, infrastructure requirements and business models are evolving significantly faster than traditional strategic planning cycles. A structured ""Annual National AI Strategic Revie"" could therefore assess: * technological and geopolitical developments; * emerging regulatory requirements; * national dependencies; * investment priorities; * AI adoption and deployment; * performance of strategic initiatives; * emerging risks; * new opportunities for the Cypriot economy. This would allow the Strategy to evolve without losing its long-term direction. Conclusion Cyprus does not need to compete with larger countries solely on the scale of infrastructure or investment. It can compete through the **quality, agility and coherence of its national AI architecture**. A strategic advantage for Cyprus could be its ability to connect **AI policy, regulation, data, infrastructure, investment, governance and execution** within one coherent national operating framework. The success of the National AI Strategy 2032 should therefore not be measured solely by the adoption of Artificial Intelligence, but by whether Cyprus develops the institutional capacity to prioritise, design, approve, implement, govern, monitor, scale and measure the value of AI systems consistently. The proposed National AI Execution & Assurance Architecture would provide an additional execution layer capable of transforming the Strategy from a framework for national direction into a measurable, adaptive and execution-oriented national AI system through 2032. Submitted by: Christina Ioannou Founder & CEO, Areté Strategy AI Ltd Policy, Governance & Regulatory Execution Intelligence https://www.aretestrategyai.org/ https://www.linkedin.com/in/christina-ioannou-8a3bb1177/" "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",ravatar,"SUBMISSION TO THE PUBLIC CONSULTATION ON THE NATIONAL AI STRATEGY OF THE REPUBLIC OF CYPRUS 2032 Recognising Multimodal and Embodied Conversational Interfaces as a National Accessibility Capability Submitted by: Cyber Leo Limited (trading as RAVATAR), HE384983, Limassol, Cyprus Contact: Ruslan Synytskyy, Chief Executive Officer Email: rs@ravatar.com Date: 29 July 2026 EXECUTIVE RECOMMENDATION The Strategy correctly identifies conversational AI and multilingual assistants as reusable national services rather than isolated sector applications. We support this framing without reservation. We recommend one clarification, applied consistently across the Strategy: that conversational AI be specified as multimodal, capable of speech, visual presence and natural interaction, and not implicitly limited to text-based interfaces. This is not a technical preference. The Strategy commits Cyprus to digital inclusion for people with disabilities and for pensioners, and to multilingual access. A text-only interface systematically excludes the populations the Strategy names as priorities: older citizens, people with low digital literacy, people with visual or motor impairments, and non-Greek-speaking residents. Where the interface is the service, the modality of the interface is an accessibility decision, not an implementation detail. We also recommend that the Strategy establish a national transparency standard for synthetic-persona interfaces, so that Cyprus sets the governance rules for this technology rather than importing them. The six comments below address: 1. Specification of shared conversational AI services as multimodal 2. A national disclosure standard for synthetic-persona interfaces 3. Accessibility requirements for the Virtual AI Patient Orchestrator 4. Scope of the tourism SME co-funding scheme 5. Sovereign deployment of the citizen-facing interface layer 6. A glossary definition for multimodal conversational interfaces All proposed amendments are drafted in capability terms and are technology-neutral. None names or favours a specific product, vendor or architecture. COMMENT 1: SPECIFY SHARED CONVERSATIONAL AI SERVICES AS MULTIMODAL SECTION REFERENCE Section 3.4.4 (Shared Capabilities and Reuse); Annex C, Government and Public Sector, Implementation, evidence and compliance; Annex B, Control Gate 1, category ""reusable common services"". COMMENT / SUGGESTION The Strategy states that Cyprus will build shared, reusable AI services including ""conversational AI for continuous citizen service delivery"" and ""multilingual citizen assistants"", exposed through ""a common, modular intelligent government platform"". We suggest these references be amended to read, in substance: ""conversational AI, including multimodal and embodied interfaces supporting speech, visual presence and accessible interaction, for continuous citizen service delivery"" and that the shared services catalogue explicitly list a multimodal interaction layer as a reusable component alongside identity, payments, document intelligence and case management. JUSTIFICATION The Strategy commits, in Section 3.9 and in the OECD-aligned principles at Annex A, that ""new solutions must cater to multilingual support and inclusive access tools that ensure that people with disabilities can interact with the services"", and in the Executive Summary to promoting digital inclusion ""including people with disabilities and pensioners"". Section 3.4.4 establishes that capabilities built once will be reused across government. This makes the specification of the shared conversational service unusually consequential: whatever modality is scoped into the reference architecture will propagate into every ministry that adopts it, and will be difficult to retrofit once the platform is procured. The Strategy notes that procurement for the first six transformational solutions is intended to launch within eight months. The specification decision is therefore imminent. The current wording does not exclude multimodal interfaces. It also does not require them, and in procurement practice an unspecified requirement is an absent requirement. Given that the Strategy sets an explicit target of reducing citizen waiting times by 40% and improving citizen experience, and given that the citizens least well served by existing digital channels are precisely those least able to use a text interface, we consider the clarification proportionate and low-cost. A second consideration: architectural optionality over a seven-year horizon. Section 3.7.3 provides that infrastructure choices ""should therefore be guided by considerations of interoperability, portability, vendor diversity, supply-chain resilience, security, and long-term sustainability"", and that this ""reduces lock-in risks while preserving strategic flexibility"". Section 3.13.4 commits the Strategy to remaining ""adaptive rather than static"" in the face of technological change. We suggest these principles apply with particular force to the interaction layer, and that the Strategy would benefit from stating so explicitly. The Strategy runs to 2032. The shared conversational service will be specified once and inherited by every ministry that adopts it, across the sixteen transformation projects and beyond. Interaction modality is an architectural property of that service: a platform designed for multimodal interaction can serve text, whereas a platform designed for text cannot later serve speech and visual interaction without substantial rework or re-procurement. The asymmetry is the point. Requiring modality-extensibility in the initial specification is close to costless, because it constrains architecture rather than mandating deployment. Retrofitting it into a procured national platform is expensive, slow, and may not be practicable within the Strategy's timeframe. This holds regardless of how interaction preferences evolve over the period, which is why we put it forward as a resilience argument rather than a forecast. We would specifically suggest that shared conversational services be required to expose a modality-independent interaction layer, so that additional modalities can be added without re-architecting the underlying service, and that this be treated as a portability requirement of the kind Section 3.7.3 already contemplates. We note that this comment asks for a specification of an existing commitment, not for a new programme or new expenditure. COMMENT 2: ESTABLISH A NATIONAL DISCLOSURE STANDARD FOR SYNTHETIC-PERSONA INTERFACES SECTION REFERENCE Section 3.9.3 (Transparency and Explainability); Section 3.9.6 (AI Social Contract Principles); Annex B, Control Gate 2. COMMENT / SUGGESTION We recommend the Strategy commit to a national transparency standard governing AI systems that present a synthetic human persona, whether visual, vocal or both. The standard should require, at minimum: - Persistent disclosure. Continuous, unambiguous indication that the citizen is interacting with an AI system, present throughout the interaction and not only at its start. - No impersonation of identifiable individuals. Synthetic personas deployed in public services must not replicate the likeness or voice of a real, identifiable person without that person's explicit, documented and revocable consent. - One-step human escalation. A visible, always-available route to a human official, with no requirement to restate the request. - Provenance and audit. Recorded lineage of the persona asset, the underlying models, and the interaction logs, consistent with the auditability requirements already set out in Section 3.9.3. - Proportionality. Requirements scaled to risk, consistent with the EU AI Act's risk-based approach, with the strictest application to health, benefits and legal contexts. JUSTIFICATION Article 50 of the EU AI Act establishes transparency obligations for systems that interact directly with natural persons and for systems generating synthetic audio, image, video or text. It requires that this information be provided in a clear and distinguishable manner at the latest at the time of first interaction, and that it conform to applicable accessibility requirements. The Strategy itself notes the 2 August 2026 compliance milestone. Synthetic-persona interfaces are an area where the Act sets a floor and where national implementation guidance does not yet exist in most Member States. We note that the Act's own linkage of transparency to accessibility supports the point made in Comment 1: disclosure that a citizen cannot perceive is not disclosure. The Strategy commits to leveraging EU AI Act alignment as a source of competitive advantage rather than treating it as a constraint, and this is an area where that ambition can be made concrete. Cyprus has an opportunity to publish that guidance first. The Strategy states an ambition for Cyprus to be ""a testing and deployment environment for EU and regional markets, particularly for regulated and multilingual contexts"". A clear, published national standard for trustworthy synthetic-persona deployment would be a concrete instance of that positioning, and would give operators regulatory certainty in a technology area where uncertainty is currently the main barrier to adoption. There is a public trust argument as well. The Strategy is explicit that ""AI systems must be explainable, auditable, and understandable to those they affect"", and that citizens interacting with AI must be made aware of it. Embodied interfaces raise this question more sharply than text interfaces do. Addressing it in the Strategy rather than after the first incident is the lower-risk path. We raise this comment notwithstanding that stricter rules apply to our own product category. We consider a published standard preferable to an unregulated market, both for citizens and for responsible operators. For transparency as to our own position: we are currently implementing AI disclosure, human oversight and interaction logging as architectural requirements of our platform, together with a formal EU AI Act conformity assessment, under a dedicated compliance work package in our European Innovation Council Accelerator programme application. The measures proposed above are therefore ones we are building to, not ones we are proposing for others. COMMENT 3: SPECIFY ACCESSIBILITY REQUIREMENTS FOR THE VIRTUAL AI PATIENT ORCHESTRATOR SECTION REFERENCE Annex C, Healthcare and Life Sciences, Flagship programme(s). COMMENT / SUGGESTION The Strategy describes the Virtual AI Patient Orchestrator as ""an intelligent, multilingual Virtual AI Patient Orchestrator that functions as a national digital front door"", operating ""under clinician oversight, with safety nets for vulnerable populations"". We suggest the programme description specify that the front door must be accessible by voice and visual interaction, not by text alone, and that accessibility for older patients and patients with disabilities be included among the programme's evaluation indicators rather than treated as a downstream implementation concern. We further suggest that a bounded pilot be conducted before national rollout, comparing interaction modalities on a defined patient cohort, with pre-registered indicators covering completion rate, comprehension, time to first clinical assessment and patient-reported experience, disaggregated by age group and language. JUSTIFICATION The Strategy already commits to evaluating national triage and care navigation pilots ""against WHO-aligned indicators, focusing on triage accuracy, time to first clinical assessment, and reduction of avoidable visits"". Adding accessibility indicators to that set is consistent with the existing evaluation design and adds little cost. The clinical case is straightforward. A digital front door that is intended to reduce pressure on emergency services succeeds only if the patients most likely to present at emergency departments can use it. Those patients are disproportionately elderly, and elderly patients in Cyprus include a substantial cohort with limited digital literacy. A front door that only the digitally confident can open will shift load rather than reduce it, and may widen rather than narrow the access gap the programme is meant to close. The Strategy identifies ""AI theatre"" as a national risk: many pilots, little measured impact. A pre-registered, modality-comparative pilot with disaggregated outcomes is a direct mitigation of that risk and would produce evidence usable across the other citizen-facing programmes. COMMENT 4: EXTEND THE TOURISM SME CO-FUNDING SCHEME TO MULTIMODAL CONCIERGES SECTION REFERENCE Annex C, Tourism and Hospitality, Implementation (Empowered Digital Tourists programme); and the pillar deliverables ""Support for sustainable hotels and SMEs"" and ""Digital concierges and transparent AI use"". COMMENT / SUGGESTION The Strategy provides that the Empowered Digital Tourists programme ""co-funds multilingual, privacy-compliant GenAI chatbots and recommendation systems for sustainability-certified hotels and tourism SMEs"", and separately anticipates ""GenAI-based concierges supporting multilingual guidance, culture and heritage explanations, and human escalation"". We suggest the co-funding provision be worded to cover multilingual, privacy-compliant conversational AI systems including chatbots, voice assistants and embodied digital concierges, so that the funding instrument matches the concierge capability the same pillar describes. JUSTIFICATION As currently drafted, the deliverables table describes digital concierges while the funding mechanism references chatbots. Aligning the two removes an inconsistency and avoids a situation in which the stated capability is not eligible for the stated instrument. The substantive case is that hospitality is an in-person, multilingual, service-quality-driven sector, and the Strategy is explicit that AI adoption in tourism must preserve ""the hospitality, warmth, and cultural authenticity that distinguish Cyprus"". A text chatbot is a poor expression of that objective. A concierge that speaks, in the visitor's language, with visible AI disclosure and immediate human escalation, is a closer fit to both the service standard and the transparency requirement. We note the Strategy's own cited evidence that 8% of chatbot conversations resulted in a confirmed booking, rising to 25% with a single follow-up, with an estimated 10% increase in direct sales. Those figures are drawn from text-based deployments. Extending eligibility would allow Cyprus to generate comparative national evidence on whether multimodal interfaces improve on that baseline, which is information no other Member State currently holds. We also support the Strategy's emphasis that this scheme reach SMEs and local communities and not only large hotel chains. Interface quality is one of the few areas where a small operator can match a large chain if the tooling is accessible, and the co-funding mechanism is well designed for that purpose. COMMENT 5: TREAT THE CITIZEN-FACING INTERFACE LAYER AS A SOVEREIGN CAPABILITY SECTION REFERENCE Section 3.7.3 (Digital Sovereignty and Strategic Autonomy); Section 1.4.6; Executive Summary, ""AI sovereignty leveraging partnerships"". COMMENT / SUGGESTION We suggest that the Strategy identify the citizen-facing conversational interface layer as among the critical layers over which Cyprus should retain sovereign control, alongside compute, data and skills, and that shared conversational services procured for government be required to support deployment within national infrastructure. JUSTIFICATION The Strategy frames the national choice as being between ""coordinated, sovereign, human-centred AI on Cyprus's own terms, or piecemeal adoption of foreign platforms that gradually lock the country into other people's economic and governance models"". It commits to Cyprus ""controlling all critical layers, including sovereign compute, governed access to high-value data, core skills, and national AI assurance"". The interface layer belongs on that list. It is the layer through which every citizen interaction passes, where the transcript of that interaction is generated, and where the tone, language and cultural register of the state's relationship with its citizens is set. A conversational interface that can only run as a foreign-hosted service creates a dependency at precisely the point of highest sensitivity, and constrains the data-residency and audit guarantees the Strategy commits to elsewhere. This is not a hypothetical concern. The established providers of multimodal and avatar-based conversational interfaces are, to our knowledge, almost entirely non-EU: Synthesia (United Kingdom), HeyGen (United States), D-ID (Israel), DeepBrain AI (South Korea) and UneeQ (United States). We are not aware of a major EU-headquartered provider in this category. Where a capability category has no European supply, adopting it without a sovereignty requirement produces exactly the dependency the Strategy warns against, and does so silently, because the dependency is created at procurement rather than announced as a policy choice. The corollary is that a sovereignty requirement in this layer is also an industrial policy instrument. It creates addressable demand for European and Cypriot suppliers in a category where European capability is currently thin, which is consistent with the Strategy's stated ambition to move Cyprus ""from consumer to creator of AI solutions"". Requiring deployability within national infrastructure does not require Cyprus to build the technology itself, and is consistent with the Strategy's partnership model. It requires only that the procurement specification permit it, which is a question of how the requirement is written and is therefore appropriate to settle at strategy stage. This provision would also align the shared services layer with the G-Cloud programme described in Annex C, which is intended to ""provide a fully governed, hybrid cloud foundation, expand the AI compute capacity, and establish governed sandboxes"". COMMENT 6: ADD A GLOSSARY DEFINITION FOR MULTIMODAL CONVERSATIONAL INTERFACES SECTION REFERENCE Annex G (Glossary of Key Terms). COMMENT / SUGGESTION We suggest the Glossary include an entry along the following lines: ""Multimodal Conversational Interface. An AI system that interacts with a person through more than one channel, such as speech, visual presence, gesture or text, rather than through text alone. Such systems are commonly referred to as conversational avatars or digital humans. They are used to improve accessibility and comprehension for users with limited digital literacy, visual or motor impairments, or limited proficiency in the interface language, and are subject to the transparency obligations applicable to AI systems that interact directly with natural persons."" JUSTIFICATION The Strategy refers to conversational AI, multilingual assistants and digital concierges in several places without defining what interaction modalities those terms encompass. The Glossary states that its purpose is to ""support consistent understanding and interpretation of the Strategy"". A definition would resolve an ambiguity that will otherwise be resolved differently by each implementing body. Including the common commercial terminology in the definition, while keeping the operative term capability-based, allows the Strategy to remain technology-neutral in its requirements while ensuring that implementers, procurement officers and suppliers interpret those requirements consistently. Terminology in this field is not yet settled, and a national definition reduces the risk of divergent interpretation across the sixteen transformation projects and the Institutional AI Strategies due in March 2027. PROPOSED CONTRIBUTION FROM RAVATAR RAVATAR is a Cyprus-registered technology company developing multi-sensory digital human systems: AI interfaces that see, hear, speak and express in real time, deployable across web, mobile, kiosks and life-sized holographic displays. The company holds copyright in the RAVATAR AI Avatar Platform and the Genesis AI Avatar Studio, both developed and owned in Cyprus, and supports both cloud and fully on-premise deployment with no data egress. The technology is deployed in operational environments today. Reference deployments include an AI financial advisor at the Luxembourg House of Financial Technology, the country's national fintech hub; three interactive AI hosts handling approximately 1,200 unscripted interactions with 2,500 participants at the PwC Tax Leadership Conference 2025; holographic deployments with Capgemini at VivaTech Paris and with AMD at GITEX Dubai; a hyper-realistic avatar of Nobel Laureate Sir Konstantin Novoselov developed with Constructor University, Bremen; and a holographic avatar of Howard Carter in ongoing visitor operation at a museum in Egypt. The company reported EUR 440,000 in revenue in 2025 and is currently a Stage 2 applicant to the European Innovation Council Accelerator. We note these deployments not as commercial references but because they bear on the questions raised above: the accessibility, transparency and sovereign-deployment measures we propose are drawn from operational experience of running such systems in regulated and public-facing settings, including in an EU Member State. Should it be useful to the National AI Taskforce or to the bodies established under the Strategy, we would be willing to contribute practical experience in: - Multimodal and embodied conversational interface design - Multilingual real-time voice and video interaction - Accessibility evaluation for older and low-digital-literacy users - Transparency and disclosure design for synthetic-persona systems - On-premise and sovereign deployment of conversational AI - Interface-layer requirements for public sector procurement Any participation should take place through transparent, competitive and outcome-based mechanisms. We would equally welcome the opportunity to contribute to the development of a national disclosure standard under Comment 2 on a non-commercial basis, including where the resulting standard applies to our own product category. CONCLUSION The Strategy's treatment of conversational AI as reusable national infrastructure is, in our view, one of its strongest design decisions. Our comments do not seek to alter that architecture. They seek to ensure that the interface layer built on top of it is usable by the citizens the Strategy names as priorities, and governed by rules Cyprus writes for itself. Specifying modality is a small edit at strategy stage. It becomes a substantially more expensive correction once reference architectures are published and the first six transformational procurements are underway. We thank the National AI Taskforce and the Deputy Ministry of Research, Innovation and Digital Policy for the opportunity to contribute. Ruslan Synytskyy Chief Executive Officer Cyber Leo Limited (RAVATAR) Limassol, Cyprus" "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",Algorithmx,"Article / paragraph: Goal 6, Ensuring secure, sovereign and interoperable data and infrastructure, and Section 3.3 on national compute Comment / Suggestion: Rather than attempt to fund a national GPU cluster on the domestic budget alone, Cyprus should pursue an EuroHPC AI Factory Antenna, in partnership with the nearest hosting AI Factory in Athens, and use the Antenna as the shared compute layer for Cypriot academia, startups and public bodies. Access should be gated through a voucher system managed alongside the AdoptAI scheme, with reserved capacity for regulated workloads that require EU data residency, in particular health, legal and public sector use cases. Justification: Cyprus is a EuroHPC Joint Undertaking participating state. The AI Factories initiative, and the Antenna model for member states that do not host a full Factory, is the practical route by which a country of one million people can give its researchers and its startups access to frontier-scale training and fine-tuning compute without building a hyperscale data centre from scratch. The initial wave of AI Factories has been selected and the Antenna model was created precisely for the situation Cyprus is in. An Antenna gives Cyprus three things at once. It gives startups and universities real access to serious compute, on terms set inside the EU, without asking the domestic budget to carry the full capital cost. It creates an operational relationship with the Athens Factory, which is culturally and linguistically the easiest partner for Cyprus to work with day to day. And it gives the Strategy a credible answer to the sovereignty question, because the compute sits under EU governance and inside EU data residency rules, rather than under a US or Gulf cloud provider whose terms can change unilaterally. This suggestion complements, rather than replaces, the point raised by Theo on the environmental limits of large domestic data centres. Sharing an EuroHPC-anchored Antenna, rather than each ministry or company building its own, is the lower-footprint answer to the same problem. It also matches the collaborative posture of the Strategy, which explicitly names EU-level partnerships as one of the routes to national capability. To make the compute reach the intended users, the access model matters as much as the hardware. A voucher scheme run through the AdoptAI budget, with reserved slots for public sector and regulated workloads, keeps the compute from being fully consumed by whichever few well-connected teams learn to book it first. A published quarterly report of who used how much compute, for what class of workload, would keep the scheme honest. Samuel Adu-Berekorang https://www.linkedin.com/in/samueladuberekorangx/" "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",Algorithmx,"Article / paragraph: Section 2.5.3, Objective 3, and the AdoptAI voucher scheme. Comment / Suggestion: Make the AdoptAI voucher explicitly cover annual subscriptions to EU-resident vertical AI software, not only consulting engagements and one-off pilot projects. Justification: Most Cypriot SMEs will not benefit from a consultancy pilot. What they need is a working tool they can log into on Monday morning. If the voucher only pays for advice or bespoke development, the money will flow to a small number of consultancies and the SME will be left with a slide deck and no operational tool once the engagement ends. If the voucher also covers annual subscriptions to EU-based vertical AI software, the SME gets something it can actually use, the money stays inside the EU tax base, and Cypriot and EU AI vendors get a fair chance to win work that would otherwise default to US SaaS by inertia. The scheme should require the vendor to be established in an EU member state and to host data inside the EU, which keeps it aligned with the sovereignty goals set out elsewhere in the Strategy. Samuel Adu-Berekorang https://linkedin.com/in/samueladuberekorangx/" "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",Algorithmx,"Article / paragraph: Section 1.3, Priority Sectors for Leadership, and Annex C Comment / Suggestion: Add Sustainability and Climate Compliance as a ninth priority sector, alongside Shipping, Tourism, Financial Services and the others already listed. Justification: The compliance wave is no longer a future scenario. CBAM entered its definitive regime on 1 January 2026 and is now live for Cypriot importers of cement, iron and steel, aluminium, fertilisers, hydrogen and electricity above the de minimis threshold. CSRD Wave 1 companies are already filing for FY2025 under the revised timeline set by Directive (EU) 2025/794, and listed SMEs are in scope from FY2028. The VSME voluntary standard is the template that banks and large buyers are pushing down the supply chain, which pulls unlisted Cypriot SMEs into reporting through customer contracts rather than through direct legal obligation. Naming this as a priority sector does two things. First, it lets Cypriot AI vendors build vertical tools for a market that is guaranteed by EU law, which is the kind of defensible niche a small country should pursue. Second, it gives Cypriot SMEs a home-grown path to compliance in Greek, with local data, instead of routing the work through UK or German consultancies. Shipping is already named in the Strategy, and shipping is one of the sectors most exposed to the EU ETS extension to maritime and to CBAM through fuel and materials, so the new sector fits naturally next to what is already in the list. Samuel Adu-Berekorang" "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",paandreou,"Μια Εθνική Στρατηγική θα ήταν σκόπιμο να διατίθεται και στην ελληνική γλώσσα, ώστε να είναι πλήρως προσβάσιμη σε όλους τους εμπλεκόμενους φορείς και να διευκολύνεται η ευρύτερη κατανόηση και εφαρμογή της. Παράλληλα, θα ήταν χρήσιμο να ετοιμαστεί και μια συνοπτική, περισσότερο οπτικοποιημένη έκδοση, με χρήση διαγραμμάτων, γραφικών και infographics, η οποία να παρουσιάζει με σαφή και εύληπτο τρόπο το όραμα, τους στρατηγικούς στόχους, τις βασικές δράσεις και το χρονοδιάγραμμα υλοποίησης της Στρατηγικής." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Nicos Palios","ΔΕΝ ΧΡΕΙΑΖΟΜΑΣΤΕ ΑΠΛΩΣ ΕΞΥΠΝΟ ΚΡΑΤΟΣ. ΧΡΕΙΑΖΟΜΑΣΤΕ ΕΝΑ ΚΡΑΤΟΣ ΠΟΥ, ΟΣΟ ΠΙΟ ΕΞΥΠΝΟ ΓΙΝΕΤΑΙ ΤΕΧΝΟΛΟΓΙΚΑ, ΤΟΣΟ ΠΙΟ ΑΝΘΡΩΠΙΝΟ ΓΙΝΕΤΑΙ ΑΠΕΝΑΝΤΙ ΣΤΟΝ ΠΟΛΙΤΗ. Η ΤΕΧΝΟΛΟΓΙΑ ΜΠΟΡΕΙ ΝΑ ΜΕΙΩΣΕΙ ΤΗ ΓΡΑΦΕΙΟΚΡΑΤΙΑ, ΝΑ ΕΠΙΤΑΧΥΝΕΙ ΤΙΣ ΔΗΜΟΣΙΕΣ ΥΠΗΡΕΣΙΕΣ ΚΑΙ ΝΑ ΔΗΜΙΟΥΡΓΗΣΕΙ ΝΕΕΣ ΟΙΚΟΝΟΜΙΚΕΣ ΕΥΚΑΙΡΙΕΣ. ΔΕΝ ΠΡΕΠΕΙ, ΟΜΩΣ, ΝΑ ΔΗΜΙΟΥΡΓΗΣΕΙ ΕΝΑ ΚΡΑΤΟΣ ΣΤΟ ΟΠΟΙΟ ΕΝΑΣ ΠΟΛΙΤΗΣ ΘΑ ΛΑΜΒΑΝΕΙ ΜΙΑ ΑΡΝΗΤΙΚΗ ΑΠΟΦΑΣΗ ΑΠΟ ΕΝΑΝ ΑΛΓΟΡΙΘΜΟ ΧΩΡΙΣ ΝΑ ΓΝΩΡΙΖΕΙ ΤΟ ΓΙΑΤΙ ΚΑΙ ΧΩΡΙΣ ΝΑ ΜΠΟΡΕΙ ΝΑ ΜΙΛΗΣΕΙ ΜΕ ΑΝΘΡΩΠΟ. ΓΙ’ ΑΥΤΟ ΕΙΣΗΓΟΥΜΑΙ ΤΗ ΘΕΣΜΟΘΕΤΗΣΗ ΕΝΟΣ ΧΑΡΤΗ ΔΙΚΑΙΩΜΑΤΩΝ ΤΟΥ ΠΟΛΙΤΗ ΑΠΕΝΑΝΤΙ ΣΤΗΝ ΤΕΧΝΗΤΗ ΝΟΗΜΟΣΥΝΗ. ΚΑΘΕ ΠΟΛΙΤΗΣ ΠΡΕΠΕΙ ΝΑ ΕΧΕΙ ΔΙΚΑΙΩΜΑ ΕΝΗΜΕΡΩΣΗΣ, ΕΞΗΓΗΣΗΣ, ΑΝΘΡΩΠΙΝΗΣ ΕΠΑΝΕΞΕΤΑΣΗΣ ΚΑΙ ΠΡΟΣΦΥΓΗΣ. ΚΑΘΕ ΚΡΑΤΙΚΟ ΣΥΣΤΗΜΑ ΤΕΧΝΗΤΗΣ ΝΟΗΜΟΣΥΝΗΣ ΠΟΥ ΕΠΗΡΕΑΖΕΙ ΖΩΕΣ ΠΡΕΠΕΙ ΝΑ ΕΙΝΑΙ ΚΑΤΑΓΕΓΡΑΜΜΕΝΟ, ΕΛΕΓΧΟΜΕΝΟ ΚΑΙ ΔΗΜΟΣΙΑ ΥΠΟΛΟΓΟ. ΔΕΝ ΠΡΕΠΕΙ ΝΑ ΕΠΙΛΕΞΟΥΜΕ ΑΝΑΜΕΣΑ ΣΤΗΝ ΤΕΧΝΟΛΟΓΙΚΗ ΠΡΟΟΔΟ ΚΑΙ ΣΤΗΝ ΑΝΘΡΩΠΙΝΗ ΑΞΙΟΠΡΕΠΕΙΑ. Η ΤΕΧΝΗΤΗ ΝΟΗΜΟΣΥΝΗ ΠΡΕΠΕΙ ΝΑ ΥΠΗΡΕΤΕΙ ΤΟΝ ΠΟΛΙΤΗ — ΟΧΙ ΝΑ ΚΥΒΕΡΝΑ ΤΗ ΖΩΗ ΤΟΥ." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","andreas spanashis","Προς κάθε ενδιαφερόμενο, Διάβασα τη στρατηγική στο σύνολό της και, ενώ οι αρχές της είναι αξιοπρεπείς και η σύνταξή της επαγγελματική, έχω σοβαρές επιφυλάξεις — οι περισσότερες εκ των οποίων προκύπτουν από τις ίδιες τις σελίδες του κειμένου. Οι κεντρικοί στόχοι δεν στέκουν μεταξύ τους. Ο στόχος υιοθέτησης ΤΝ 75% χρονολογείται το 2030 στη σελ. 51, το 2032 στη σελ. 61 και ξανά το 2030 στο κεντρικό γράφημα της σελ. 64 — με σημείο εκκίνησης που η ίδια η στρατηγική δηλώνει στο 9,3%. Φιλοδοξεί εργατικό δυναμικό «στην πρώτη δεκάδα της Ευρώπης» σε ψηφιακές δεξιότητες, μία μόλις σελίδα μετά την παραδοχή ότι βρισκόμαστε κάτω από τον ευρωπαϊκό μέσο όρο στις βασικές ψηφιακές δεξιότητες. Η «αύξηση του ΑΕΠ κατά 12%» (σελ. 6) εμφανίζεται μία φορά, χωρίς μοντέλο ή πηγή, και δεν ξαναεμφανίζεται πουθενά. Το βασικό στατιστικό στοιχείο του ναυτιλιακού πυλώνα παραπέμπει στη Wikipedia· η τεκμηρίωση του χρηματοοικονομικού πυλώνα βασίζεται σε διαφημιστικό υλικό προμηθευτών. Και σε 101 σελίδες δεν υπάρχει ούτε ένα ευρώ κόστους για κανένα πρόγραμμα, ταμείο ή θεσμό που δημιουργεί η στρατηγική — τα οφέλη ποσοτικοποιούνται με ακρίβεια δεκαδικού, το κόστος καθόλου. Χαρακτηριστικό είναι ότι το παράρτημα των δεικτών (KPIs) τιτλοφορείται «(δείγμα)» και επιτρέπει κάθε στόχος να «αναθεωρείται, να επεκτείνεται ή να αντικαθίσταται» χωρίς επίσημη αναθεώρηση της Στρατηγικής. Τα γυαλιστερά γραφήματα δεσμεύονται· τα ψιλά γράμματα αποδεσμεύουν. Η μεγαλύτερη ανησυχία μου αφορά τον μηχανισμό. Η στρατηγική δημιουργεί περίπου δέκα νέα σώματα — Αρχή ΤΝ, συμβούλια, επιτροπές, παρατηρητήρια, κέντρα αριστείας — συν Λειτουργούς ΤΝ σε κάθε υπουργείο και ετήσιες υπουργικές στρατηγικές ΤΝ, χωρίς κανένα από αυτά να διαθέτει στελέχωση ή προϋπολογισμό. Όλα αυτά θα λειτουργήσουν από τη δημόσια υπηρεσία όπως πραγματικά υπάρχει, όχι όπως τη φαντάζεται το διάγραμμα: ένα σύστημα όπου καμία καριέρα δεν ζημιώθηκε ποτέ από χαμένη προθεσμία ή αποτυχημένο έργο, και όπου το μόνο παραδοτέο που ανταμείβεται αξιόπιστα είναι η παραγωγή εγγράφων. Το προβλέψιμο αποτέλεσμα είναι ακριβώς το «θέατρο ΤΝ» για το οποίο προειδοποιεί η ίδια η στρατηγική στη σελ. 4 — με μια Ομάδα Εργασίας να αξιολογεί μια στρατηγική που συνέταξε η ίδια. Και εδώ θα ζητούσα μια στιγμή ειλικρίνειας για το ιστορικό μας. Πρόκειται για ένα κράτος που, σχεδόν μία δεκαετία μετά την έναρξη της διαδικασίας, αδυνατεί ακόμη να επιβάλει την αναλογία γάλακτος στο ίδιο του το εμβληματικό τυρί — το χαλλούμι, το πολυτιμότερο εξαγωγικό μας όνομα. Ένα κράτος του οποίου το Υπουργείο Άμυνας φιλοδοξεί να στήσει αμυντική βιομηχανία χωρίς εμφανή κατανόηση του πώς χρηματοδοτούνται και κλιμακώνονται τέτοιες επιχειρήσεις. Ένα κράτος που δαπάνησε 62 εκατομμύρια ευρώ σε «έξυπνες» στάσεις λεωφορείων τοποθετημένες ανάποδα — με συμπαγή κολόνα και παγκάκι να κρύβουν από τον επιβάτη τη θέα του λεωφορείου που έρχεται, λες και οδηγούμε στα δεξιά — σχεδιασμό που ο ίδιος ο Γενικός Ελεγκτής χαρακτήρισε «πρωτοφανή και απαράδεκτο» και τον οποίο το υπουργείο εξακολουθεί να υπερασπίζεται. Ένα κράτος του οποίου το εμβληματικό ενεργειακό έργο, το τερματικό ΥΦΑ στο Βασιλικό, κατέληξε με τερματισμό της σύμβασης του αναδόχου μετά από χρόνια καθυστερήσεων, εκατοντάδες εκατομμύρια δεσμευμένα, έρευνα της Ευρωπαϊκής Εισαγγελίας — και κανένα τερματικό. Το λέω όχι για να είμαι σκληρός αλλά για να είμαι ακριβής: μια κυβέρνηση, ως σώμα δημοσίων λειτουργών, με αυτό το ιστορικό, που προτείνει να διαχειριστεί εικονικούς ανθρώπινους διδύμους, μητρώα ΤΝ σε blockchain και εργαστήρια πιστοποίησης θεμελιωδών μοντέλων, δεν είναι φιλόδοξη — είναι μη σοβαρή. Το χάσμα ανάμεσα στο λεξιλόγιο της στρατηγικής και στην αποδεδειγμένη ανικανότητα του κράτους είναι το σημαντικότερο δεδομένο αυτού του εγγράφου, και πουθενά δεν αναγνωρίζεται μέσα σε αυτό. Θα πρότεινα την αντίθετη φιλοδοξία, που συμπτωματικά είναι και η μόνη φθηνή. Το ελάχιστο όριο της Πράξης για την ΤΝ ορίζεται στις Βρυξέλλες· δεν μπορούμε να εξαιρεθούμε. Τα κράτη μέλη όμως αποφασίζουν πόσο βαριά θα την εφαρμόσουν, και η υπόλοιπη Ευρώπη προβλέψιμα θα την επιχρυσώσει σε έναν λαβύρινθο συμμόρφωσης. Η μία πραγματική ευκαιρία της Κύπρου είναι να γίνει η ελαφρύτερη και ταχύτερη δικαιοδοσία ΤΝ που επιτρέπει το ευρωπαϊκό δίκαιο: το υποχρεωτικό ελάχιστο, ούτε μία υποχρέωση παραπάνω, με δεσμευτικούς χρόνους απόκρισης από τις ρυθμιστικές μας αρχές. Αυτό απαιτεί από το κράτος να είναι καλό σε ένα μόνο πράγμα — την αυτοσυγκράτηση. Όλα τα υπόλοιπα πρέπει να φύγουν: τα «κυρίαρχα» κέντρα δεδομένων (το απομονωμένο δίκτυο και το κόστος ενέργειας τα αποκλείουν, και η σελ. 61 παραδέχεται ότι δεν υπάρχουν εγκαταστάσεις έτοιμες για ΤΝ), το ταμείο καινοτομίας που υπόσχεται «τρεις μονόκερους» από μια χώρα που δεν έχει παραγάγει κανέναν, και τα έξι μεγαλεπήβολα ερευνητικά προγράμματα — από δίκτυα 6G και κβαντικούς υπολογιστές μέχρι το διάστημα και την άμυνα — όταν η χώρα δαπανά για έρευνα λιγότερο από το 1% του ΑΕΠ της. Αν παρ' όλα αυτά τα υπουργεία πρέπει οπωσδήποτε να κάνουν κάτι, μια μισοσοβαρή ιδέα: να ανατεθεί σε ιδιωτικές εταιρείες να εντοπίσουν εξοικονομήσεις στη δημόσια διοίκηση, με αμοιβή αποκλειστικά ως ποσοστό επί των επαληθευμένων εξοικονομήσεων — χωρίς πάγια, χωρίς ημερήσιες χρεώσεις, χωρίς παραδοτέα σε PowerPoint. Θα ήταν η πρώτη πρωτοβουλία στην ιστορία της Δημοκρατίας όπου ο ανάδοχος, ο φορολογούμενος και η αλήθεια κάθονται όλοι στην ίδια πλευρά του τραπεζιού. Και θα παίρναμε επιτέλους εμπειρική απάντηση στο μεγάλο εθνικό ερώτημα: αν οι αναποτελεσματικότητές μας είναι τόσο τεράστιες ώστε αυτές οι εταιρείες να γίνουν οι πρώτοι μας μονόκεροι — ή τόσο δομικά προστατευμένες που ούτε το κίνητρο του κέρδους δεν μπορεί να τις ξεθάψει. Με εκτίμηση, Ανδρέας" "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",spectralbranding,"A gap is sitting underneath both Gate 3 and Gate 4. Both gates confirm that a system ""meets performance and compliance expectations"" and ""continues to... deliver expected value."" What they don't specify is HOW that match is checked: against what, exactly, and by what mechanism, before a citizen or business ever touches the output. As written, the verification is procedural – did the right assessments happen, were the right people signed off – rather than a check against an explicit, machine-readable statement of what the service actually commits to deliver. Procedural conformance and outcome conformance are different things, and a system can pass every approval gate in Annex B while still not delivering the specific experience that was promised at Stage 1. Proposal: Add an explicit requirement, at Control Gate 3 (Deployment Readiness), for an ex-ante, machine-checkable acceptance contract: a structured specification of the citizen-facing outcome the system commits to, written before development in a form that can be automatically checked against the delivered system, with backward traceability from the delivered experience to the originating specification. This is distinct from (and a precondition for) the compliance and ethics checks already required at Gate 2, and distinct from runtime admissibility control at Gate 4: it answers ""did we build and verify the thing we said we'd build,"" not ""did we follow the right process"" or ""is this specific action allowed right now."" I've published open research specifically on this problem – machine-checkable acceptance contracts as a governance mechanism for organizational and AI-mediated service specification, and the more general problem of verification mechanisms that check process conformance without checking ex-ante experience-layer acceptance: - Machine-Checkable Acceptance Contracts for Organizational Design. https://doi.org/10.5281/zenodo.18946043 - Verification as Operator: Spectral Projection, Rank Deficiencies, and the Persistence of the Audit Society. https://doi.org/10.5281/zenodo.19778588 I'd welcome the chance to discuss whether this pattern – a specification-cascade acceptance contract, verified before deployment, sitting alongside (not replacing) the existing risk/ethics/compliance and runtime-admissibility layers – is something the Strategy's implementation guidance could reference directly. Cyprus is well positioned to be an early, formal adopter of this kind of standard rather than a follower of it. With regards, Dmitry Zharnikov spectralbranding.com" "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",AndreasP,"Recognise meaningful user choice, interoperability, portability and freedom from unjustified platform lock-in as elements of human-centred AI. Where technically compatible, secure and lawful, users should be able to install, select, change and remove AI assistants and other AI-enabled services on devices and platforms they own or lawfully use. Choosing an alternative provider should not cause unjustified loss of functionality, discriminatory treatment or unreasonable barriers to transferring data and switching services. This principle is especially important where a device manufacturer, operating-system provider or digital platform controls hardware access, interfaces, default settings, application distribution or data needed by competing AI services. Cyprus should advocate at European level for effective competition enforcement, appropriate assessment of AI gateways and connected-device operating systems, interoperability with competing AI services, and protection against unjustified self-preferencing, restrictive bundling and defaults that prevent meaningful choice. At national level, public procurement and government AI frameworks should favour open standards, documented interfaces, configurable defaults, data portability and avoidance of unnecessary single-vendor dependence. Relevant authorities should also provide a process for recording evidence of AI-related lock-in or discriminatory access and referring it to competent European authorities. These principles should remain subject to proportionate cybersecurity, privacy, technical-integrity, accessibility, child-protection and legal requirements. Justification: AI assistants and AI-enabled interfaces are becoming gateways through which citizens access information, digital services, connected devices and commercial platforms. A provider controlling the operating system, hardware interface or default assistant can therefore influence which services users can access and how competing services function. Restrictions on installing alternatives, changing defaults, accessing necessary device functionality or transferring user data can create platform lock-in. They may reduce competition and innovation and prevent citizens from selecting services that better meet their language, accessibility, privacy or functional needs. Protecting meaningful choice would give practical effect to the Strategy's commitments to human agency, digital inclusion, interoperability and citizens' rights. It would also support Cyprus's objective of avoiding excessive dependence on external platforms and economic models. The proposal does not require access to every AI service offered globally. It establishes the narrower principle that lawful and technically compatible alternatives should not be excluded through unjustified commercial or technical restrictions. This would strengthen individual autonomy, fair competition and national digital resilience." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",AndreasP,"Establish an Authoritative National Address and Premises Register as a foundational national reference dataset. The Strategy should require machine-readable address data that extends beyond building-level postal addresses. Every separately addressable unit or premises should have a persistent unique identifier linked to its building, entrance or access point, floor where available, and official geographic location. A designated public authority should own and steward the official register. Municipalities, planning and land authorities, postal operators, utilities and telecom providers should contribute relevant premises, service-point and connection records for controlled validation and reconciliation. Their operational or customer databases should not automatically become the official source of truth. The National Intelligent Digital API Fabric should provide secure, controlled access to this reference data for authorised public bodies and, where legally appropriate, regulated private-sector participants. The register should identify physical buildings, entrances and addressable units only. It should not become a centralised register of residents, occupants, owners, utility customers or telecom subscribers. Any link to personal or account-holder information should remain separately governed and permitted only for a lawful, necessary and clearly defined purpose. Justification: A common unit-level premises identifier would reduce reliance on inconsistent free-text addresses and fragmented organisational databases. It would support emergency response, postal and courier delivery, utility services, municipal administration, planning, property processes and citizen-facing digital services. Utility and telecom providers hold valuable and frequently updated service-point and premises records. With appropriate privacy, security and legal safeguards, these records can help the public authority identify duplicate, incomplete or conflicting address information. The capability would strengthen Digital Citizen 2.0 and Digital Company 2.0 by enabling authorised services to refer reliably to the correct premises when location information is necessary, without unnecessarily centralising personal or occupancy data. Without a common addressable-unit identifier, automated and AI-enabled workflows will continue to require manual verification and may cause delays, failed service delivery or incorrect record matching. Implementation should be measured through national coverage, duplicate and conflict rates, update times, API availability, adoption by public bodies and correction-request resolution times." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Petros Nearchou","The Strategy provides a strong foundation for trusted and responsible AI adoption. As implementation moves from governance principles to operational systems, continuous governance and identity security should be defined more explicitly. Sections 3.13.3, Security and Threat Management, and 3.3.2, Control Framework: Comment / Suggestion The Strategy should establish continuous operational governance and identity security for human users, systems, workloads, APIs and AI agents, including other non-human actors. Implementation requirements should include continuous policy and access evaluation, delegated authority, least-privilege controls, rapid revocation, monitoring for control drift and complete auditability(end-to-end) across the full AI lifecycle. These requirements should be formalised through a national continuous operational governance standard, ensuring that AI systems, APIs and agents remain within approved identity, access, policy and accountability boundaries from design through operation, modification and decommissioning. Justification The Strategy anticipates interconnected government APIs, shared data services and AI agents operating across sensitive and regulated environments. Although it addresses access controls, monitoring and lifecycle governance, it does not explicitly define how non-human systems and AI agents will be identified, authorised and continuously controlled. AI systems, integrations, permissions and agent capabilities may change after deployment. Initial approval and periodic review alone may therefore be insufficient. Continuous governance would help ensure that security, access and compliance controls remain enforced and evidenced while systems are operating. Including this requirement would strengthen accountability, cybersecurity and public trust, while allowing detailed technical standards and reference architectures to be developed during implementation. Best regards, Petros Nearchou www.linkedin.com/in/petros-nearchou" "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",theoand,"Reading through the National AI Strategy 2032, the vision for making Cyprus a tech hub is clear, but there is a major elephant in the room: **AI isn't just software. It runs on physical data centers that consume massive amounts of electricity and water.** For an island like Cyprus, this is a huge risk if we don't get the ground rules right from day one. We operate on an isolated grid, we face chronic water shortages, we deal with summer peak blackouts, and we have to decommission of conventional generation by 2029. Meanwhile, every spring we literally throw away clean solar energy because our grid can't absorb it. Allowing unconstrained data center growth in this environment without strict boundaries will cause real problems for our basic infrastructure. Here are the critical gaps in the current draft and what needs to be added: ### The Big Loopholes in the Strategy 1. **The ""Where Feasible"" Cop-Out** The current draft talks about green energy using soft language like *""where feasible""*. In the real world, ""where feasible"" means optional. Private operators will always choose whatever is cheapest for their bottom line, pushing the burden of grid instability and water consumption onto the public. 2. **The Sovereign Procurement Loophole** If we don't enforce strict rules across *all* projects—including state-backed or ""sovereign"" builds—private developers will exploit it. They will build resource-heavy facilities under the excuse of ""helping the government fulfill its capacity needs,"" monopolize our power and water, and then sell that expensive compute back to the state for private profit. ### Non-Negotiable Rules to Add to the Strategy If we are going to host compute infrastructure in Cyprus, the strategy must lay down clear, binding rules for **any** new facility (private, public, or public-private): * **No ""Sovereign"" Exemptions:** The exact same environmental and grid rules must apply to every facility. No developer gets a free pass under the banner of ""national strategic interest."" * **Total Ban on Drinking Water for Cooling:** No evaporative cooling towers using municipal drinking water or groundwater. Cooling must be zero-potable-water—using closed-loop liquid cooling or coastal seawater heat exchange. * **Mandatory On-Site Batteries (BESS):** Any facility over 1 MW must install battery storage and integrate with the TSO to act as a grid-support asset, helping feed power back during summer peak hours. * **Real Green Energy & Smart Scheduling:** Replace ""where feasible"" with mandatory 100% renewable Power Purchase Agreements (PPAs). Force heavy, non-urgent AI workloads to run *only* during spring solar overproduction windows when we would otherwise dump excess clean energy. * **Cap On-Island Compute to Inference Only:** Cyprus does not need power-hungry mega-factories for training massive base AI models. We should restrict local builds to efficient edge data centers for low-latency local services and government data, while offloading heavy AI model training to EU EuroHPC supercomputers abroad. Placing these practical guardrails directly into the 2032 Strategy will give serious investors regulatory certainty while ensuring digital transformation doesn't come at the expense of our power grid and water supply." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",NEST,"**Article / Sections:** 3.9.2 — Human Oversight and Accountability 3.9.5 — Responsible Deployment and Monitoring 3.9.6 — AI Social Contract Principles Annex B — AI Use Case Lifecycle and Control Gates, particularly Control Gate 4 **Comment / Proposal** The proposed National AI Strategy provides a strong and important foundation for positioning Cyprus as a trusted, sovereign and responsible AI jurisdiction. Its principle that people must remain in control is correct. However, human control should not necessarily mean that a person must manually approve every routine AI-generated action. Continuous human approval can become a bottleneck in speed, scale and consistency, while still remaining vulnerable to fatigue, overload and delayed intervention. A stronger operational model is: **Human-governed admissible boundaries, with machine-speed autonomy inside those boundaries.** Accountable people and institutions should define the objectives, authority, operating context, protected consequences and conditions under which an AI system may act. The AI may then operate autonomously within that predefined space. Where a proposed transition is unauthorised, unsupported, contextually invalid or outside the permitted boundary, it should be denied, held or escalated before reaching external consequence. I therefore propose adding an explicit: **Operational Pre-Consequence Admissibility Gate** For high-impact, citizen-facing, regulated and critical-infrastructure AI applications, each material AI-originated transition should be independently evaluated at the latest trustworthy point before it affects a protected digital or physical system. The control should: * operate independently of the acting AI; * verify authority, context and admissibility; * prevent inadmissible transitions from reaching the protected consequence; * bind the decision to the actual execution route; * verify whether the intended consequence occurred or remained absent; * produce tamper-evident and independently inspectable evidence; * permit normal machine-speed operation within approved bounds; * escalate only those exceptions requiring human judgement. **Justification** The Strategy already establishes strong lifecycle controls covering assessment, development, deployment readiness and periodic operational assurance. These controls are necessary, but they do not explicitly require a live admissibility decision immediately before each material external consequence. This distinction becomes increasingly important for autonomous and agentic AI systems capable of generating novel actions, combinations and operating states at machine speed. Human oversight should therefore govern the boundary, remain responsible for its authorised modification and retain the ability to review, contest and override outcomes—without making continuous human approval the routine execution mechanism. Cyprus should consider establishing a national technical testbed for pre-consequence AI control, beginning in shadow mode on a bounded public-sector or critical-infrastructure workflow. NEST is a Cyprus-developed pre-consequence architecture from Bounded System Technology Ltd. Its public proof pack demonstrates an inadmissible transition being denied before backend consequence, together with signed and independently verifiable evidence. I propose that NEST be considered for independent technical evaluation—not as a replacement for legal, institutional or human governance, but as a candidate mechanism for making human-governed operating boundaries technically enforceable. This would allow Cyprus to test a practical interpretation of the Strategy’s central principle: **People govern the boundary. AI operates at machine speed within it. Inadmissible consequences do not pass.** Bounded System Technology Ltd - Cyprus" "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας",romavm,"3.3.1.7 National AI Skills Observatory / Government AI Accelerator 1.3 Priority Sectors for Leadership After carefully reviewing the document, I would like to propose reconsidering the institutional model of the AI Accelerator. Rather than positioning the AI Accelerator as part of the Government Innovation Hub, I recommend establishing it as a separate, public, open, and independent national initiative. While the Government Innovation Hub should remain focused on public sector innovation and digital transformation, the AI Accelerator should serve a broader mission of advancing AI adoption, innovation, research, and commercialization across the entire national ecosystem. Such a model would encourage broader participation and make it easier to attract leading AI talent through permanent positions, fixed-term contracts, fellowships, secondments, and project-based engagements. It would also strengthen collaboration between government, academia, startups, industry, investors, and international partners, creating a sustainable environment for AI innovation. As part of the AI Accelerator, I recommend establishing an Open AI Institute to act as the national centre of excellence for artificial intelligence. The Institute would consolidate expertise, best practices, reusable AI assets, validated solutions, implementation guidance, and lessons learned into a shared national resource that could be leveraged by public institutions, businesses, researchers, and innovators. This would reduce duplication, accelerate AI adoption, and improve the quality and consistency of AI implementations across sectors. 1.3 Priority Sectors for Leadership / Entrepreneurship and Innovation In addition, the AI Accelerator should include a dedicated unit responsible for developing the national AI innovation ecosystem. Its mandate should include supporting AI startups and scale-ups, facilitating public-private partnerships, attracting investment and talent, promoting international collaboration, and enabling the development and export of AI-enabled products and services. An open and independent AI Accelerator would complement the Government Innovation Hub rather than duplicate its role, while creating a stronger foundation for innovation, economic growth, and the country’s long-term competitiveness in artificial intelligence. Best regards, Roman Medvedev https://www.linkedin.com/in/romavm/" "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Education Speaks","Beyond education, the government’s e‑consultation document presents a clear and confident direction for Cyprus’s National AI Strategy. It treats AI as a practical capability that the country must adopt with intention and discipline. The strategy explains why AI matters, where Cyprus can lead, and how the country can build sovereign capability while staying aligned with European standards. The vision of Cyprus becoming a trusted AI hub in the Eastern Mediterranean is ambitious but believable. The document places strong emphasis on human‑centred design, responsible governance and transparent systems. These elements are essential for public trust, and they are woven throughout the strategy rather than mentioned as afterthoughts. The focus on sectors such as finance, tourism, shipping, healthcare and legal services shows a good understanding of where AI can deliver real economic value. The strategy is honest about the gaps Cyprus faces. It highlights fragmented data, limited compute capacity and a shortage of specialised talent. What stands out is the way the document moves directly from problem to solution. It proposes national compute infrastructure, unified data governance, AI Officers in ministries, Centres of Excellence and national testbeds for validation. This gives the strategy a practical and grounded tone. The implementation plan is structured and measurable. It sets out timelines, milestones and KPIs that make the strategy accountable. The expected outcomes are ambitious but realistic. Higher productivity, GDP uplift, more AI professionals and modernised sectors are all achievable if the plan is executed with consistency. Overall, the document is thoughtful, practical and forward‑looking. It shows that Cyprus is approaching AI with seriousness and strategic intent. It deserves strong support." "Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας","Education Speaks","Schools and Learning Cultures in Cyprus - response to AI Cypriot schools have several strengths that give the system genuine potential for transformation. Educators demonstrate strong commitment to learners, and schools maintain warm, relational environments where students feel known, supported and connected. This relational quality is a cultural advantage: Cypriot learners tend to be expressive, social and engaged, which creates fertile ground for a learning culture built on curiosity, dialogue and shared meaning. The national appetite for modernisation, visible in digital initiatives, curriculum updates and professional development, shows that Cyprus is willing to evolve and align with European expectations for contemporary schooling. These strengths form a solid foundation for a learning ecosystem where attention, agency and intellectual presence can flourish. Many schools are already experimenting with project-based learning, modernisation approaches and digital tools, signalling an early shift toward more participatory learning. There is also growing recognition that education must prepare students not only for examinations but for confident participation in a rapidly changing world. This awareness is an important cultural shift: it opens the door for schools to cultivate discernment, critical thinking and humane participation as core educational outcomes. Signalling this trajectory, Cyprus now needs to move from individual initiatives to systemic coherence. Schools require a shared understanding of what a strong learning culture looks like: environments where students practise discernment, think with depth, collaborate meaningfully and engage with learning as a humane, relational process. This means aligning curriculum, pedagogy, assessment and school culture so that students experience learning as a coherent journey rather than a series of disconnected tasks. When these elements reinforce one another, learning becomes intentional rather than mechanical. A second priority is leadership capacity. School leaders should be supported to shape culture, not only manage operations. Leadership development programmes can help principals and senior teams design intentional learning environments, steward change with clarity and build staff cultures that are reflective, collaborative and intellectually purposeful. When leaders understand learning culture deeply, reform becomes sustainable rather than compliance-driven. Finally, Cyprus would benefit from a national framework that helps schools embed AI and digital tools in ways that strengthen human presence rather than replace it. Technology should support teachers in designing learning moments that are connected, thoughtful and alive - moments where students learn to think well, act with awareness and participate confidently in their world. AI becomes most powerful when it amplifies human discernment, not when it accelerates performance pressure. Cyprus has the relational foundations, the cultural strengths and the willingness to modernise. With coherent learning cultures, intentional leadership and human-centred use of technology, the country can build an education system that is not only competitive but deeply humane - one where students grow into thoughtful, capable participants in their society. Best regards, Tassos Anastasiades" "01 - ΕΘΝΙΚΗ ΣΤΡΑΤΗΓΙΚΗ ΓΙΑ ΤΗΝ ΤΕΧΝΗΤΗ ΝΟΗΜΟΣΥΝΗ ΤΗΣ ΚΥΠΡΙΑΚΗΣ ΔΗΜΟΚΡΑΤΙΑΣ","Menicos Mavrommatis","IBM Feedback on the Cyprus National AI Strategy 2032 IBM welcomes the opportunity to participate in the ongoing public consultation on the National AI Strategy 2032 of the Republic of Cyprus and appreciates the efforts of the Chief Scientist, the National AI Taskforce and the Deputy Ministry of Research, Innovation and Digital Policy in developing a comprehensive national vision for artificial intelligence. We also recognise and strongly support the significant effort undertaken by the Strategy Committee. The Strategy sets out an ambitious objective for Cyprus to become a trusted AI hub in the Eastern Mediterranean, a reliable European jurisdiction for AI-enabled services, and a bridge between the European Union and neighbouring regions by 2032. IBM strongly supports the Strategy's overarching goal of fostering trustworthy and responsible AI adoption and welcomes the Government's commitment to engaging stakeholders through this public consultation process. In this spirit, we offer our recommendations with the objective of strengthening the Strategy's contribution to innovation, competitiveness, cybersecurity, and the development of an open and globally connected AI ecosystem. In our comments, we highlight that the strategy should remain technology-neutral, risk-based, and aligned with the EU Single Market. Achieving the Strategy’s objectives will also require sustained investment in future-ready skills and close alignment between the Strategy’s AI ambitions and the evolution of hybrid cloud and quantum technologies, which together will underpin the next generation of secure and high-performance computing. 1. Coordinate AI, quantum computing and cybersecurity strategies The AI Strategy should be implemented with holistic approach, in coordination with policies and investments in quantum computing, high-performance computing and cybersecurity. These technologies are increasingly complementary: AI can accelerate the design, calibration and operation of quantum systems, while quantum computing may open new avenues for machine learning, optimisation and scientific discovery. Policymakers should therefore foster integrated ecosystems in which AI, quantum processors and classical high-performance computing resources can be combined through open, interoperable and hybrid computing architectures. This should include coordinated investment in infrastructure, research, skills and early-stage industrial experimentation, as well as collaboration with international technology providers and research partners. This coordination must also address the cybersecurity implications of quantum computing. Future cryptographically relevant quantum computers could undermine widely used public-key cryptography, while “harvest now, decrypt later” attacks already create risks for sensitive data with a long confidentiality life. Our recommendation is therefore to start integrating post-quantum cryptography into AI, cybersecurity and critical-infrastructure planning now, rather than treating quantum safety as a future issue. AI solutions can help critical organisations accelerate specific stages of the migration process, including the preparation of cryptographic asset inventories and quantum-risk assessments. Ultimately, these efforts should align with the EU’s coordinated PQC roadmap and internationally recognised standards, while accounting for supply-chain dependencies and the long lifecycle of operational technology and critical infrastructure. 2. Preserve technical approach and avoid origin-based sovereignty criteria IBM supports the objective of strengthening digital sovereignty and trust in AI. However, sovereignty should be assessed based on the degree of technical, operational, and legal control exercised by customers over their data, systems, and business continuity, rather than provider’s nationality or headquarters location. In particular, we welcome the Strategy’s focus on building partnerships in Section 3.7 – however, the approach should be clearer to avoid interpretations that discriminate companies based on their country of origin. Requirements should be based on verifiable security, resilience, transparency, and governance outcomes, ensuring open competition and access to best-in-class technologies. 3. Avoid national gold-plating beyond the EU AI Act The strategy should build on existing EU legislation, including the AI Act, GDPR, and sectoral frameworks, without introducing additional national requirements that could create regulatory fragmentation. Consistency with EU rules will reduce compliance burdens, improve legal certainty, and support the development and deployment of AI solutions across the Single Market. 4. Accelerate AI adoption in priority sectors IBM welcomes the Strategy’s focus on sectors in which Cyprus has established economic strengths and where AI can deliver significant productivity, competitiveness and public-value gains, as outlined in Section 3.5. We recommend that the Strategy translates into concrete sectoral roadmaps, supported by access to trusted data, secure hybrid-cloud infrastructure, skilling initiatives, testbeds and regulatory sandboxes. Particular attention should be given to the following sectors: - Tourism and hospitality: AI can support demand forecasting, personalised visitor services, multilingual assistance, destination management, resource optimisation and more sustainable tourism. - Healthcare and life sciences: AI can augment clinical decision-making, improve patient pathways and preventive care, support resource planning and accelerate research, subject to strong protections for sensitive health data, governance and human oversight. - Financial services and fintech: AI can strengthen fraud detection, risk management, compliance, customer due diligence and operational efficiency. - Energy: while this sector is not highlighted in the Strategy, we emphasise that AI can optimise grids and renewable-energy integration, forecast demand, improve asset maintenance and energy efficiency, and increase the resilience of critical infrastructure. A coordinated approach across these sectors would create reusable capabilities and economies of scale, accelerate diffusion among smaller enterprises, and enable successful solutions developed in Cyprus to expand across the EU Single Market and internationally. 5. Foster innovation through proportionate governance Trustworthy AI provides the foundation for sustainable innovation. At the same time, Governance mechanisms should be proportionate, risk-based, and targeted at high-risk use cases. The strategy should encourage experimentation, AI sandboxes, public-private collaboration, and rapid adoption of beneficial AI applications. Excessive approval layers, mandatory certifications, or broad compliance obligations risk slowing deployment, increasing costs, and reducing the attractiveness of Cyprus as a destination for AI investment and innovation. The Strategy should also recognise the shift from governance based primarily on policies, assessments, and periodic human review towards the technical enforcement of risk and compliance requirements at runtime. While not every control can be automated, this evolution is particularly important for agentic AI systems, where risks may emerge dynamically across multi-step workflows and cannot be addressed adequately through human processes alone. Section 3.3.2 should therefore explicitly promote the implementation of proportionate runtime controls to complement organisational governance and enable scalable, trustworthy deployment. 6. AI skills IBM welcomes the Strategy's strong focus on AI skills, workforce development, and lifelong learning. We particularly support the recognition that AI should be used to augment human capabilities and productivity, enabling people to work more effectively alongside AI systems rather than simply automating tasks. To ensure that skills programmes remain aligned with rapidly evolving technologies and labour market needs, Cyprus should promote close collaboration between government, academia, and industry in the design and delivery of AI education, training, and reskilling initiatives. Such partnerships will be critical to developing a future-ready workforce and supporting the successful adoption of AI across the economy. Conclusion We recommend that the Strategy positions Cyprus as an open, innovation-friendly AI hub by combining strong security and governance with technology neutrality, support for AI development, interoperability with international standards, and full alignment with the EU Single Market." "01 - ΕΘΝΙΚΗ ΣΤΡΑΤΗΓΙΚΗ ΓΙΑ ΤΗΝ ΤΕΧΝΗΤΗ ΝΟΗΜΟΣΥΝΗ ΤΗΣ ΚΥΠΡΙΑΚΗΣ ΔΗΜΟΚΡΑΤΙΑΣ",Yiorgos,"It is suggested that the Research and Innovation focus areas be reviewed to consider the inclusion of Culture and Creativity as a dedicated Research Focus Area or strategic cross-cutting research domain. This could represent an area in which Cyprus has the potential to develop a distinctive position at European level. Cyprus already has a strong foundation on which to build, including an established creative and cultural ecosystem, a growing games and digital creative industries sector, and a solid base of researchers, technologists and experts. Bringing these capabilities together could create a strong environment for applied research and innovation at the intersection of AI, culture, creativity, digital heritage, gaming and immersive technologies. This direction is also increasingly aligned with EU research and innovation priorities. Initiatives such as the Culture Compass for Europe, Horizon Europe, the New European Bauhaus, EIT Culture & Creativity and S+T+ARTS increasingly recognise the convergence of culture, creativity, research and technology as an important driver of innovation, competitiveness and societal impact. Such a focus could also have a direct positive impact on tourism, by enabling the development of new cultural experiences, immersive heritage applications, AI-enhanced visitor experiences and innovative ways of presenting Cyprus’s cultural assets. In this way, investment in culture and creativity could also contribute to strengthening the competitiveness and attractiveness of Cyprus as a destination. Similarly, it could support the growth of the games industry by fostering the development and adoption of AI, immersive technologies, digital storytelling and creative technologies, while creating stronger links between research, talent and the emerging games and digital creative industries ecosystem in Cyprus." "01 - ΕΘΝΙΚΗ ΣΤΡΑΤΗΓΙΚΗ ΓΙΑ ΤΗΝ ΤΕΧΝΗΤΗ ΝΟΗΜΟΣΥΝΗ ΤΗΣ ΚΥΠΡΙΑΚΗΣ ΔΗΜΟΚΡΑΤΙΑΣ",StellaK,"First off, congratulations to the team of experts that put together this national AI strategy. It is the first of its kind, and while we will be commenting on points that might require clarification, we want to be clear that we support the effort as well as the prompt for public consultation before the strategy is enacted into law. 1. Comment 1 — National AI Authority: undefined legal basis and mandate Αρ. Άρθρου και εδαφίου: Section 3.3.1.1 (National AI Authority), page 23–24; cross-referenced with Section 2.5.1, page 16 Comment: The Strategy establishes the National AI Authority as ""policy coordination and execution body"" and ""governance and control gatekeeper"" with a ""clear political mandate,"" but does not specify the legal instrument creating it, its statutory powers, its enforcement or sanctioning authority, or its relationship to the AI Act's designated competent and market-surveillance authorities. The only defined element of its establishment is procedural (designation by the President, ratified by the Council of Ministers) — a political appointment mechanism, not a legal competence framework. Section 2.5.1 compounds this by referring separately to oversight by ""appropriate competent authorities as defined by the Government,"" without reconciling this with the Authority's own gatekeeper function. Requested amendment: Before final adoption, the Strategy should specify (a) the legal act by which the Authority will be established (law, decree, or otherwise), (b) an exhaustive list of its powers, including whether it has binding decision-making, sanctioning, or only coordinating/advisory authority, and (c) an express statement of how its mandate is bounded relative to existing and AI Act-mandated competent authorities. Grounds: A body given a ""gatekeeper"" label without a defined legal basis creates regulatory uncertainty for businesses and investors — precisely the opposite of the ""trusted jurisdiction"" outcome the Strategy seeks under Objective 1. This ambiguity also creates litigation and compliance risk for private-sector actors who cannot determine which body's guidance is authoritative. Comment 2 — Overlap between the National AI Authority and existing regulatory bodies Αρ. Άρθρου και εδαφίου: Section 3.3.1.1, page 23; Legal Services pillar (NAICF), page 35; Section 2.5.1, page 16 Comments: The Authority's stated functions — ""establishing common frameworks and standards"" and ""compliance oversight"" — duplicate functions already assigned by law to sector regulators (e.g., CySEC for financial services, the Digital Security Authority for cybersecurity) and to the national standardisation body. Similarly, the proposed National AI Compliance Framework (NAICF) is described as supporting ""certification, auditing, and regulatory oversight,"" without clarifying how this sits against statutory conformity-assessment procedures under Regulation (EU) 2024/1689, or against the powers of national competent authorities under Article 74 of that Regulation. Requested amendment: The Strategy should include an explicit division-of-functions table or section distinguishing (a) policy coordination and strategic direction (appropriate for the National AI Authority), from (b) statutory supervision, enforcement, and conformity assessment (which remain with existing competent authorities), and (c) standards development and adoption (which falls within the remit of the national standardisation body). NAICF's certification and auditing language should be reframed as support tools that do not themselves constitute or replace formal regulatory determinations. Grounds: Without this clarification, businesses face parallel or conflicting compliance expectations from multiple bodies, and there is a real risk that NAICF outputs could be mistaken for, or represented as, formal EU-recognised certification when they are not. This also risks institutional duplication and wasted public resources — a concern already raised independently by CYS and the Office of the Commissioner of Electronic Communications in this consultation, which supports treating it as a priority fix. Comment 3 — Breach determination rests on the judgment of a single individual, with no institutional check (emphasis on this point): Αρ. Άρθρου και εδαφίου: Section 1.7 (Methodology), page 7; Section 3.3.1.1 ""AI Officers,"" page 27; Section 3.3.2 ""Control Framework,"" page 27–28 Comments: The Strategy repeatedly concentrates the responsibility for identifying non-compliance, ethical breaches, or governance failures in a single office rather than an institutional or collective mechanism: The Chief Scientist for Research, Innovation and Technology is named the sole ""accountable custodian"" of the entire Strategy. Each ministry is assigned one AI Officer, described as the ""focal point for AI"" who is personally responsible for ""ensuring compliance with governance, legal, and ethical requirements."" The complementary AI Ambassador/Champion role is limited to adoption and promotion, not compliance determination — so, in practice, breach identification within each ministry rests on one individual's judgment. The Control Framework (Section 3.3.2) requires ""clear procedures for incident reporting, escalation, and remediation"" but does not specify who makes the initial determination that a breach or failure has occurred, nor does it provide for any second-reviewer, peer-review, or independent verification step. This is compounded by the fact that AI Officers are provided by, and functionally report to, the National AI Authority — the same body whose own conduct or initiatives they may need to flag. Requested amendment: Replace single-officer breach determination with a documented two-step or panel-based process for any finding of non-compliance or incident above a defined risk threshold — for example, requiring sign-off or review by a second designated person or by the relevant oversight committee (e.g., the National Ethics and Values Committee or National AI Infrastructure Committee) before a breach finding is closed or escalated. The Strategy should also state explicitly how an AI Officer would report a concern involving the National AI Authority itself, to avoid a structural conflict of interest. Grounds: Placing sole responsibility for detecting and calling out breaches on one person per ministry — without independent review, and without a defined channel for reporting concerns about the appointing Authority itself — creates a single point of failure in the entire governance and control architecture (Section 3.3), undermining the ""robust governance and control mechanisms"" the Strategy itself identifies as its intended outcome. This is a structural, not a resourcing, problem, and cannot be solved simply by staffing the role adequately. Thank you to all for their contribution and to the Chief Scientist who spearheaded this initiative, which is aimed at improving the way we live, work and operate in today's technological environment in Cyprus." "01 - ΕΘΝΙΚΗ ΣΤΡΑΤΗΓΙΚΗ ΓΙΑ ΤΗΝ ΤΕΧΝΗΤΗ ΝΟΗΜΟΣΥΝΗ ΤΗΣ ΚΥΠΡΙΑΚΗΣ ΔΗΜΟΚΡΑΤΙΑΣ","CHRISTOS PETROU","The National AI Strategy 2032 appropriately identifies Healthcare and Life Sciences as a priority domain and includes important directions such as national health-data infrastructure, AI-supported triage and care navigation, digital clinical support tools, interoperability, security and regulatory compliance. These provide a credible foundation. However, the health component remains primarily focused on the digital enhancement of the existing healthcare-delivery model. It could be strengthened by articulating a more integrated, preventive and scientifically advanced model in which AI supports precision health, biomedical innovation, population health and safer patient care. Precision health and multimodal data A key gap is the limited integration of precision-health principles. Future national health-data infrastructure should not be confined to electronic health records, prescriptions, laboratory results and imaging. Cyprus should develop a longitudinal, multimodal precision-health data infrastructure. Digital Healthcare Twin The proposed Digital Healthcare Twin also requires a clearer scientific and operational definition. A health digital twin should be more than an advanced electronic record or an AI-generated summary. It should represent a dynamic longitudinal model integrating clinical, biological, imaging, medication, behavioural and environmental data and should be subject to defined standards for scientific validation, clinical utility and regulatory oversight. Without these safeguards, there is a risk that the concept remains technologically attractive but clinically insufficiently defined. Healthy ageing and longevity The strategy would benefit from a more explicit focus on healthy ageing and healthy longevity. Population ageing, multimorbidity, polypharmacy and frailty will increasingly affect healthcare demand and system sustainability. AI can support the prediction of frailty and functional decline, early identification of cardiometabolic and neurodegenerative risk, optimisation of pharmacotherapy and deprescribing, and personalised preventive interventions. Patient safety and quality of care Patient safety and quality of care should be positioned as central objectives of health-related AI. Success should not be assessed only by speed, efficiency or cost savings, but by demonstrable improvements in clinical outcomes and reduction of preventable harm. AI could contribute to medication-safety surveillance, detection of adverse drug reactions and interactions, identification of clinical deterioration, reduction of diagnostic and prescribing errors, and improved continuity of care. High-risk applications should be subject to robust local clinical validation, human-in-the-loop oversight, transparent accountability, incident-reporting mechanisms and continuous post-deployment monitoring for bias, model drift and systematic error. AI should strengthen, rather than replace, professional judgement, accountability and the therapeutic relationship. From a data repository to a learning health system The proposed national health-data infrastructure should also evolve beyond the concept of a repository towards a National AI-enabled Learning Health System. In such a model, routine care, research data, intervention outcomes and AI-supported analysis form a continuous learning cycle in which new evidence is systematically returned to clinical practice and policy. This would allow the health system itself to become progressively more evidence-generating and adaptive. Population health and capacity planning Another gap is the relatively limited emphasis on AI for population-health intelligence and long-term health-system planning. AI can support disease-burden forecasting, epidemiological surveillance, modelling of healthcare demand, workforce and capacity planning, analysis of geographical inequalities and assessment of the consequences of demographic ageing. A national Population Health and Capacity Intelligence capability could therefore provide strategic support to the sustainability and future planning of the health system. Life sciences, regulatory science and validation Finally, the Life Sciences dimension should be broadened beyond healthcare delivery. AI is increasingly relevant across drug discovery and development, clinical-trial design and matching, real-world evidence, pharmacovigilance, pharmacogenomics, medication safety, HTA and regulatory science. Cyprus could consider a national Health AI Regulatory Science and Clinical Validation Sandbox, bringing together the requirements of the AI Act, MDR/IVDR, the European Health Data Space and bioethical governance. Such an environment could support controlled evaluation, local validation and post-market monitoring of AI-enabled health technologies and position Cyprus as a credible European testbed for responsible innovation. Conclusion Overall, the Strategy provides a strong basis for the digital transformation of healthcare. Its scientific and policy value would be enhanced by moving from a primarily digital-health perspective towards an integrated framework encompassing precision health, prevention, healthy longevity, patient safety, population intelligence, biomedical sciences and regulatory science. This would enable Cyprus to use AI not only to improve existing services, but to redesign future healthcare around safer, more personalised, preventive and learning-oriented care. Prof. Christos C. Petrou petrou.c@unic.ac.cy" "01 - ΕΘΝΙΚΗ ΣΤΡΑΤΗΓΙΚΗ ΓΙΑ ΤΗΝ ΤΕΧΝΗΤΗ ΝΟΗΜΟΣΥΝΗ ΤΗΣ ΚΥΠΡΙΑΚΗΣ ΔΗΜΟΚΡΑΤΙΑΣ",YWO1978,"General comment I support the overall direction of the National Artificial Intelligence Strategy 2032, particularly its emphasis on responsible adoption, compliance by design, lifecycle governance and human accountability. My detailed written submission focuses on the intellectual-property and copyright aspects of implementation. The principal recommendations are summarised below. 1. Annex G – Definition of Artificial Intelligence Comment / suggestion: For legal and compliance purposes, the Strategy should expressly use the definition of an “AI system” in Article 3(1) of Regulation (EU) 2024/1689. Annex G may retain a plain-language explanation, but it should not narrow or expand the EU definition and should expressly include content generation among possible outputs. Justification: A parallel national formulation could create avoidable uncertainty in procurement, compliance and lifecycle assessment. Alignment with the directly applicable EU definition provides a common legal baseline. 2. Compliance by Design and the AI Use Case Lifecycle Comment / suggestion: The National AI Compliance Framework and lifecycle control gates should include a proportionate intellectual-property review covering, where relevant, copyright and related rights, database and software rights, trade secrets, confidentiality, contractual restrictions, and ownership and licensing of AI-related assets. Projects materially relying on third-party material should document relevant sources, acquisition methods, licences or other asserted legal bases and applicable rights reservations. Justification: The Strategy already requires legal and risk assessment. Making intellectual-property questions explicit would use the existing governance structure rather than create a new regulatory layer, while addressing issues that are considerably harder to reconstruct after procurement, training or deployment. 3. Public procurement and model governance Comment / suggestion: Public-sector AI procurement should include model contractual provisions addressing the roles of providers and deployers, source information, ownership and permitted reuse of government material, confidentiality, evidence preservation, complaint handling, remediation, liability, portability and exit arrangements. Generative systems presenting a material risk of reproducing protected expression should also undergo proportionate, model-specific testing before deployment and following substantial updates. Justification: Public accountability cannot depend solely on supplier assurances. Contractual allocation, documentation and testing make the Strategy's lifecycle obligations operational and enforceable. 4. Cyprus legal language model Comment / suggestion: The proposed Cyprus legal language model should have a project-specific corpus and rights-governance plan covering authoritative sources, privately authored legal material, licences and access terms, citation and source verification, updating, ownership, portability and restrictions on reproduction of protected publications. Justification: A national legal AI system must be reliable, current and capable of showing the authority and lawful basis of the material on which it relies. The submission treats this as a suitable flagship project for responsible public-sector AI governance. 5. Legal Services Pillar – “AI Judge Capability” Comment / suggestion: The term “AI Judge Capability” should be removed and replaced by an AI-Assisted Small Claims Administration Programme. AI may support filing, triage, administrative calculations, document completeness, drafting and settlement processes, but findings of fact, legal determinations and final orders should remain with human judicial officers. Justification: The objective of improving the efficiency of low-value claims is legitimate, but the value of the claim does not remove questions of jurisdiction, evidence, procedural fairness or legal responsibility. The Strategy should preserve an unambiguous distinction between technological assistance and judicial adjudication. 6. Computer-generated works Comment / suggestion: The objective of providing “improved protection for computer-generated works” should be reframed as providing greater legal certainty regarding human-authored AI-assisted works, contractual ownership, licensing, provenance and evidence. Justification: The current wording appears to assume that additional proprietary protection for autonomously generated output is desirable before resolving questions of human authorship, originality and the limits imposed by EU copyright law. Cyprus can protect investment and contractual certainty without creating a national quasi-copyright for machine-generated material. 7. AIREG Comment / suggestion: AIREG should be described as a voluntary, technology-neutral provenance, timestamping and rights-information service. Registration should expressly be non-constitutive and without prejudice to judicial determinations of authorship, originality, copyright subsistence, ownership or infringement. Justification: A national registry can provide useful evidence of dates, development history, claimed ownership and licensing, but it cannot itself create copyright or establish an EU-wide presumption of ownership. This reframing preserves the useful evidentiary and investor-confidence objectives of AIREG without overstating its legal effect. 8. European AI Certification Lab Comment / suggestion: The proposed European AI Certification Lab should be recast as a Cyprus AI Assurance, Testing and Regulatory Readiness Centre. It may provide testing, benchmarking, documentation reviews, sandbox support and standards mapping, while formal conformity assessment or certification should remain with bodies legally competent to perform the relevant procedure. Justification: The concepts of “pre-certification” and “dual recognition” may otherwise suggest formal regulatory authority or international legal equivalence that has not been established. Closing comment These recommendations do not seek to create a separate Cypriot copyright regime for artificial intelligence or to predetermine legal questions currently governed by EU copyright law and the courts. The objective is more practical: to ensure that public-sector AI projects identify the rights and sources they use, preserve evidence, allocate contractual responsibility, test foreseeable risks and retain human accountability. A fuller written submission setting out the legal analysis, comparative material and proposed implementation roadmap is being provided separately." "01 - ΕΘΝΙΚΗ ΣΤΡΑΤΗΓΙΚΗ ΓΙΑ ΤΗΝ ΤΕΧΝΗΤΗ ΝΟΗΜΟΣΥΝΗ ΤΗΣ ΚΥΠΡΙΑΚΗΣ ΔΗΜΟΚΡΑΤΙΑΣ",MARA,"Article/Section number(s) the comment refers to Sections 2.5.5 – Objective 5: Develop, attract and retain AI-related skills and talent; 3.3.1.6 – National AI Misinformation and Security Council; 4.1.3 – Human Capital and Workforce Development; as well as the related provisions of the Strategy on Ethics, Fundamental Rights, Transparency and Explainability, and information integrity. Comment / Recommendation Strengthening the dimension of journalism, news media, and information integrity in the National AI Strategy The National Strategy rightly acknowledges the need to address misinformation and disinformation amplified through AI, as well as the need to strengthen information integrity while respecting freedom of expression. It also provides for the establishment of a National AI Misinformation and Security Council and the development of AI literacy and sector-specific competencies. In this context, it is proposed that the Strategy be further strengthened with more specific provisions for the journalism and information ecosystem, namely: Specialised training for journalists and media professionals. Journalists and media professionals should be explicitly included in sector-specific AI skills development and professional training programmes. Such training could cover the responsible use of AI tools in journalistic work, content verification, the detection of synthetic or manipulated content, and issues of algorithmic bias, data protection, ethics and transparency. This proposal can be incorporated into the Strategy's existing framework, which already provides for basic AI literacy, advanced technical skills and sector-specific competencies, as well as upskilling and reskilling within the context of lifelong learning. Involvement of media-sector expertise in mechanisms addressing misinformation. Within the framework of the National AI Misinformation and Security Council, it is proposed that the participation of, or structured consultation with, representatives of the journalistic community, media and information literacy specialists, fact-checking organisations, and researchers with expertise in the relationship between AI, news media, and the information ecosystem be ensured. The Strategy itself assigns to this Council the task of addressing misinformation, disinformation, and related risks, and of providing guidelines and policy recommendations to the competent authorities. Guiding principles for the use of AI in the information and journalism ecosystem. It is proposed that, in cooperation with the relevant professional and academic bodies, guiding principles be developed for the responsible use of AI in the production and dissemination of news content. Particular emphasis could be placed on transparency regarding the use of AI, human oversight, clear editorial responsibility and accountability, as well as on addressing the risks posed by synthetic and manipulated content. This proposal is consistent with the Strategy's existing principles on transparency and explainability, and with its provisions for mechanisms to strengthen information integrity, while respecting freedom of expression. Justification Generative AI is transforming not only the economy, employment, and public services, but also the way information is produced, distributed, and consumed. The ability to generate synthetic text, images, audio, and video at scale creates new challenges for information verification and public trust. The National Strategy itself already acknowledges that AI can amplify misinformation and disinformation, and provides for mechanisms to protect information integrity. At the same time, AI offers significant opportunities for journalism and the media, including in data analysis, research, the processing of large volumes of information, and the development of new forms of producing and delivering news content. For this reason, journalism and the media should not be treated merely as another professional sector affected by technological transformation. The quality and integrity of the information environment are directly linked to public trust and the functioning of democratic society. Including specialised training for media professionals, drawing on relevant journalistic and academic expertise within misinformation-response mechanisms, and developing clear guiding principles could therefore strengthen the Strategy's existing objectives on AI literacy, information integrity, transparency, accountability, and public trust. The Strategy already establishes governance, ethics, and accountability as a horizontal strategic objective for every use of AI. Maria Constantinou Journalist | AI and Media Researcher" "01 - ΕΘΝΙΚΗ ΣΤΡΑΤΗΓΙΚΗ ΓΙΑ ΤΗΝ ΤΕΧΝΗΤΗ ΝΟΗΜΟΣΥΝΗ ΤΗΣ ΚΥΠΡΙΑΚΗΣ ΔΗΜΟΚΡΑΤΙΑΣ",RSEVEN,"These recommendations would also strengthen Cyprus’s alignment with the Digital Decade Policy Programme 2030, under which the European Union and Member States are expected to pursue a digitally skilled population and highly skilled digital professionals with the aim of achieving gender balance, including by promoting women’s access to ICT professions. Comment 1 Article/paragraph reference: Section 2.5.5, Objective 5 ""Develop, attract and retain AI-related skills and talent"" Comment/Recommendation: The Strategy commits to developing a skilled AI workforce of approximately 3,000 professionals by 2032 but sets no gender composition target or measure for this workforce, nor for the leadership layer above it. We recommend Objective 5 be amended to include an explicit target or monitoring measure for women's representation in AI leadership and senior technical roles, alongside the existing workforce-size target, and that this be tracked by the National AI Skills Observatory (Section 3.3.1.7) as a standard indicator. Justification: Cyprus-specific data indicates the current gap is concentrated at leadership level rather than at entry. The European Institute for Gender Equality's 2025 Cyprus factsheet records women at 24% of ICT specialists and 26% of management positions, but only 11% of board members at major listed companies — evidence of a leadership transition point, not an entry-point problem. Eurostat places women at 20.1% of ICT specialists in Cyprus in 2025, in line with the EU average of 19.5%. A workforce target without a leadership-composition measure risks growing the base of the pipeline while leaving its narrowest point unaddressed. Comment 2 Article/paragraph reference: Section 2.5.3, Objective 3 ""Build a strong and inclusive AI ecosystem"" Comment/Recommendation: The Strategy defines ""inclusive"" in this objective in terms of SME and non-technology-sector access to AI capabilities. We recommend this definition be extended to explicitly include gender diversity at leadership and governance level within AI-driven organisations, and that capacity-building measures under this objective include AI governance literacy and board-readiness training targeted at women already working in the sector. Justification: An inclusive AI ecosystem depends on the diversity of who makes strategic and governance decisions about AI, not solely on access to tools and infrastructure. Given that Objective 7 (Section 2.5.7) assigns governance, ethics and accountability a dedicated national objective, and that AI governance capacity is currently concentrated among a narrow demographic in Cyprus (11% female board representation per EIGE, cited above), broadening this specifically strengthens the resilience and quality of judgement in the governance functions the Strategy identifies as critical. Comment 3 Article/paragraph reference: Section 3.5, Priority Sector 6 (Education and Human Capital Development) FutureAI CY flagship programme; and Section 2.5.8, Objective 8, human capital development paragraph Comment/Recommendation: FutureAI CY is structured around six priority groups, including ""executive leadership"" and ""senior leadership"" tiers, and Objective 8 separately commits to training programmes for ""senior leadership"" and ""mid-management"" across sectors. Neither reference includes a gender-specific track or design consideration. We recommend the executive/senior leadership tiers of FutureAI CY explicitly incorporate a leadership-pipeline track for women already in technical or management roles, covering AI governance literacy, board readiness, and scaling into executive positions, delivered in partnership with organisations experienced in this area. Justification: Without a targeted design element, general leadership upskilling programmes tend to reach those already closest to promotion, who in Cyprus's ICT sector are disproportionately male given the 26% management representation versus 11% board representation gap cited above. A specific track addresses the documented transition point directly rather than assuming general leadership training closes it. This recommendation is informed by [Czech partner]'s delivery experience on two prior EU-funded projects addressing tech leadership and women on boards specifically. Comment 4 Article/paragraph reference: Section 3.11, “Measuring Impact and National KPIs”; Annex F, Talent and Skills Indicators; and Section 3.3.1.7, National AI Skills Observatory Comment/Recommendation: We recommend that the Strategy’s talent and workforce indicators be reported on a sex-disaggregated basis and that the National AI Skills Observatory monitor not only participation in AI education and employment, but also progression, retention and representation across technical, management and senior leadership levels. At minimum, the monitoring framework should include women’s representation among AI-related professionals, FutureAI CY participants and completers, senior and executive AI roles, and relevant AI governance positions. Justification: The Strategy already establishes the National AI Skills Observatory as a mechanism for monitoring the education-to-labour pipeline and provides a national framework for measuring talent and skills outcomes. Incorporating sex-disaggregated indicators into these existing mechanisms would allow Cyprus to assess whether increased investment in AI skills translates into progression and representation across different levels of responsibility. This is particularly important because aggregate participation figures alone may show growth in the AI talent pool while concealing persistent underrepresentation at senior leadership and decision-making levels. Adding these indicators would provide a clearer evidence base for future policy adjustments, programme design and funding decisions. Comment 5 Article/paragraph reference: Section 3.3.1, Governance Structure, particularly Sections 3.3.1.3 to 3.3.1.7 Comment/Recommendation: We recommend that gender balance be included as a consideration in the composition of the national AI governance, advisory and oversight bodies established under the Strategy, and that the composition of these bodies be monitored and transparently reported. This should apply particularly to bodies influencing AI ethics, talent and workforce policy, strategic priorities, skills development and national AI implementation. Justification: The Strategy recognises that AI governance extends beyond technical implementation and encompasses ethics, accountability, societal impact, workforce transformation and public trust. The bodies responsible for shaping these areas should therefore reflect a sufficiently broad range of leadership perspectives and professional experience. Current Cyprus data shows that women remain significantly underrepresented at senior economic decision-making level. Incorporating gender balance into the governance structures created under the Strategy would translate the Strategy’s principles of inclusion, fairness and equality into implementation practice. This recommendation does not require the creation of an additional institution or programme. It can be incorporated into the appointment, monitoring and reporting processes of the governance bodies already envisaged under the Strategy. Comment 6 Article/paragraph reference: Section 2.5.3, Objective 3, “Build a strong and inclusive AI ecosystem”, and the related implementation measures concerning AI adoption by SMEs and non-technology sectors Comment/Recommendation: We recommend that the Strategy complement access to AI infrastructure, technical capabilities and training with a structured AI Business Readiness and Value Realisation Framework, particularly for SMEs and organisations in traditional, non-technology sectors. The framework should support organisations in assessing, before significant AI investment or deployment: • strategic fit and the business problem to be addressed; • prioritisation of AI use cases according to expected business value and feasibility; • process, data and organisational readiness; • workforce and role implications; • governance, accountability and regulatory considerations; • implementation capability and change readiness; and • the expected return and measurable business outcomes of AI adoption. For publicly supported AI adoption initiatives, we further recommend the use of baseline and post-implementation indicators that measure outcomes such as productivity improvement, cost reduction, revenue impact, service quality, process efficiency, workforce impact and actual organisational adoption. Justification: Increasing the number of businesses using AI should not in itself be treated as evidence of successful adoption. The strategic objective should be productive and responsible use of AI that creates measurable economic and organisational value. A business may acquire an AI solution while lacking the processes, data, internal capability, governance or strategic clarity required to generate value from it. In such cases, technology adoption can increase expenditure and organisational complexity without producing the expected productivity or competitiveness gains. A national readiness and value-realisation framework would therefore strengthen the connection between AI investment and business outcomes. It would also allow Cyprus to distinguish between technology uptake and meaningful transformation, identify where businesses encounter implementation barriers, and direct future support towards the areas producing the strongest economic impact. The framework should encourage multidisciplinary implementation, combining technological expertise with business strategy, organisational transformation, governance and sector-specific knowledge, so that technology selection follows a clearly defined business need rather than becoming an objective in itself. Submitted by:RSEVEN with input informed by WhomLab's delivery experience on EU-funded (KA210) leadership and governance programmes Date: 12/08/26" "01 - ΕΘΝΙΚΗ ΣΤΡΑΤΗΓΙΚΗ ΓΙΑ ΤΗΝ ΤΕΧΝΗΤΗ ΝΟΗΜΟΣΥΝΗ ΤΗΣ ΚΥΠΡΙΑΚΗΣ ΔΗΜΟΚΡΑΤΙΑΣ",christinaioannou,"CONTRIBUTION TO THE PUBLIC CONSULTATION ON THE NATIONAL ARTIFICIAL INTELLIGENCE STRATEGY 2032 Strengthening the Execution, Assurance and Measurable Impact of Cyprus's National AI Strategy Submitted by: Christina Ioannou Founder & CEO, Areté Strategy AI Ltd Global Governance & Regulatory Execution Intelligence Expert Date: 30 July 2026 The National Artificial Intelligence Strategy 2032 provides an ambitious and important foundation for positioning Cyprus as a trusted, competitive and forward-looking jurisdiction for Artificial Intelligence. The Strategy establishes eight interconnected national strategic objectives covering trusted AI, productivity, ecosystem development, public-sector transformation, talent, secure and interoperable data and infrastructure, governance and accountability, and sovereign national capabilities. These priorities provide a strong strategic direction for Cyprus's AI transition. My principal recommendation is therefore not to introduce another standalone initiative or duplicate existing strategic priorities. It is to strengthen the Strategy with a National AI Execution, Assurance & Performance Architecture that connects strategic objectives with implementation, regulatory requirements, institutional accountability, dependencies, measurable outcomes and continuous adaptation. The central challenge for Cyprus through 2032 will not be AI adoption alone. It will be the ability of the Republic of Cyprus to manage multiple technological, regulatory, financial, institutional and operational dependencies simultaneously while maintaining strategic coherence, accountability and measurable national value. The Strategy should therefore be designed not only to define what Cyprus wants to achieve, but also to provide a structured mechanism for understanding how national AI priorities are being executed, where dependencies and risks are emerging, whether initiatives are ready to scale, and whether they are producing measurable value. The proposed architecture would provide this additional execution layer: Strategy → Portfolio → Dependencies → Regulation → Execution → Assurance → Impact 2. STRENGTHS OF THE NATIONAL AI STRATEGY 2032 The Strategy provides several strong foundations on which Cyprus can build. 2.1 Clear National Direction The 2032 horizon provides continuity beyond individual projects, funding cycles and technology developments. The ambition to position Cyprus as a trusted European AI jurisdiction and a regional bridge between the European Union and neighbouring regions provides a clear strategic identity for the country. 2.2 Whole-of-Government and Whole-of-Economy Perspective AI will affect public administration, businesses, research, education, infrastructure, data, cybersecurity, employment and society simultaneously. The Strategy's broad national approach is therefore appropriate and necessary. 2.3 Responsible and Human-Centred AI The emphasis on trust, governance, accountability and human control is particularly important as AI systems become increasingly capable and embedded in institutional and economic decision-making. This direction is also consistent with the EU's risk-based regulatory framework under the AI Act. 2.4 National Infrastructure and Capability Secure data, infrastructure, computing capacity, digital connectivity, cybersecurity and specialised talent are fundamental components of national AI capability. Cyprus is already advancing initiatives in areas including AI infrastructure, the AI Factory ecosystem, public-sector AI adoption and national digital infrastructure. The strategic opportunity is now to ensure that these capabilities operate as interconnected components of one national system. 2.5 Strong Implementation Orientation The Strategy's value will ultimately depend on implementation. The European Commission's 2026 Digital Decade assessment identifies implementation of the new national AI strategy as an important priority, particularly in accelerating AI adoption by businesses and SMEs. This reinforces the importance of strengthening the execution dimension of the Strategy from the outset. 3. AREAS FOR FURTHER STRENGTHENING The following observations are intended not as criticism of the Strategy's strategic direction, but as recommendations for strengthening its implementation architecture. 3.1 National Execution Visibility As the number of AI initiatives increases, decision-makers will require consolidated visibility over: Strategic priorities Implementation status Dependencies Risks Resources Regulatory readiness Performance Outcomes Individual initiatives may progress successfully while the wider national portfolio becomes fragmented or develops unmanaged dependencies. A national execution mechanism would provide visibility not only over individual projects, but over how projects interact with the broader national AI system. 3.2 Strategic Dependency Management AI initiatives increasingly depend on interconnected capabilities including: Data Cloud Compute Cybersecurity Procurement Skills Regulation Funding Technology Providers Critical Public Systems These dependencies can extend across ministries, sectors and individual projects. A structured mechanism for identifying and monitoring critical dependencies would enable bottlenecks and systemic risks to be identified before they become delivery failures. 3.3 From Project Completion to Value Realisation The completion of an AI project does not necessarily represent strategic success. The more important question is whether the initiative generates measurable improvements in: Productivity Public Services Economic Performance Resilience Citizen Outcomes Institutional Capacity The Strategy should therefore progressively move from measuring activity and project completion towards measuring realised value. 3.4 Lifecycle Assurance AI assurance should not operate solely as a final compliance checkpoint. The regulatory environment increasingly requires consideration of risk management, data governance, documentation, traceability, human oversight, accuracy, robustness and cybersecurity throughout the lifecycle of relevant AI systems. Cyprus can turn this requirement into an institutional strength by embedding assurance into the lifecycle of AI initiatives rather than treating compliance as an administrative endpoint. 3.5 Continuous Strategic Adaptation AI technology, geopolitical conditions, European regulation, infrastructure requirements and business models evolve significantly faster than traditional strategic planning cycles. The Strategy should therefore incorporate an evidence-based mechanism for continuous review and adaptation while preserving its long-term 2032 direction. 4. PROPOSED SOLUTIONS AND POLICY RECOMMENDATIONS 4.1 Establish a National AI Execution, Assurance & Performance Architecture The Strategy could be strengthened through a complementary National AI Execution, Assurance & Performance Architecture. This should not create another governance body or duplicate existing institutional responsibilities. Instead, it should provide an execution layer connecting: Strategy → Decisions → Portfolio → Dependencies → Regulation → Execution → Assurance → Outcomes Every significant national AI initiative should be traceable across its lifecycle, from strategic prioritisation through implementation, monitoring, scaling and impact assessment. The purpose would be to create a common national language for execution. 4.2 Establish National AI Portfolio Management A consolidated National AI Portfolio could provide decision-makers with a common view of significant public-sector and strategically relevant AI initiatives. Each major initiative could have a standardised execution profile covering: Strategic objective Expected value Institutional ownership Accountability Required data and infrastructure Regulatory dependencies Technology dependencies Risk profile Budget and resources Milestones KPIs Deployment readiness Scaling requirements Measured impact This would shift the performance question from: “How many AI projects have been launched?” to: “How many strategic AI initiatives are producing measurable national value?” International evidence supports the importance of structured monitoring and KPIs in national AI strategies. 4.3 Create a National AI Execution and Dependency Map A National AI Execution and Dependency Map could provide an integrated view of the critical dependencies affecting strategic AI initiatives. The map could connect: Data → Infrastructure → Compute → Cloud → Cybersecurity → Regulation → Procurement → Funding → Talent → Technology Providers → Public Systems This would enable early identification of: Cross-project dependencies Bottlenecks Resource constraints Single points of failure Vendor concentration Regulatory dependencies Infrastructure gaps Skills gaps The objective would be to move from individual project management towards national system management. 4.4 Introduce AI Lifecycle Assurance Gates Significant AI initiatives could follow proportionate evidence-based stages: Identify → Assess → Design → Test → Validate → Approve → Deploy → Monitor → Scale → Review Each stage should incorporate appropriate requirements for: Regulatory compliance Data governance Cybersecurity Risk assessment Technical readiness Human oversight Documentation Traceability Operational resilience Procurement readiness Value realisation The purpose would not be to create additional bureaucracy. The purpose would be to create evidence-based decision gates determining whether an initiative should proceed, be redesigned, paused, scaled or discontinued. 4.5 Establish a National AI Value Realisation Framework A National AI Value Realisation Framework should connect: Investment → Adoption → Operational Performance → Public Value → Economic Impact For significant initiatives, expected value should be defined before implementation and assessed after deployment. Potential measures could include: Productivity improvement Cost reduction Service quality Citizen experience Economic output Time savings Institutional efficiency Risk reduction Resilience Innovation and spillover effects This would ensure that national AI investment is evaluated according to outcomes rather than activity alone. 4.6 Establish a National AI Readiness & Execution Index A National AI Readiness & Execution Index could provide a consistent mechanism for measuring national and institutional readiness and execution progress. Potential dimensions could include: Infrastructure Readiness Data Readiness Regulatory Readiness Institutional Capacity Talent Adoption Security Execution Performance Economic Impact The Index should function as a decision-support mechanism rather than simply a reporting instrument. It could allow decision-makers to identify where resources, technical assistance, policy intervention or strategic adjustment are required. This would complement international approaches to measuring national AI capability and implementation. 4.7 Create a Defined Pathway from Pilot to Scale A major strategic challenge is ensuring that experimentation leads to sustainable deployment. Strategic AI initiatives should follow a defined pathway: Research → Experimentation → Validation → Assurance → Procurement → Deployment → Scaling → Impact Measurement Clear stage gates would reduce the risk of fragmented pilots that do not progress into production. Scaling decisions should be based on evidence of: Technical readiness Regulatory adequacy Operational viability Security and resilience Institutional readiness Economic or public value This is particularly relevant to SMEs, where AI adoption continues to lag behind larger enterprises. 4.8 Establish a National AI Strategic Risk and Dependency Register Cyprus should consider establishing a National AI Strategic Risk and Dependency Register for critical national AI capabilities. It could monitor: Technology dependencies Vendor concentration Cloud and compute dependencies Critical data dependencies Skills dependencies Regulatory dependencies Cybersecurity exposure Supply-chain risks Geopolitical risks Emerging systemic AI risks This would provide an early-warning mechanism for strategic vulnerabilities and allow intervention before risks become structural. 4.9 Introduce Strategic AI Foresight and Continuous Adaptation The Strategy should operate as a living national framework. A continuous feedback loop could be established: Evidence → Performance → Risk → Foresight → Decision → Strategy Adjustment An annual National AI Strategic Review could assess: Technological developments Geopolitical developments Regulatory changes National dependencies Investment priorities AI adoption Strategic project performance Emerging risks Economic and societal outcomes New opportunities This would allow the Strategy to evolve without losing its long-term direction. 5. LEGISLATIVE IMPLICATIONS AND REGULATORY REQUIREMENTS The proposed architecture does not necessarily require extensive new legislation. The immediate priority should be to ensure that existing European and national requirements are translated into practical, interoperable and operational mechanisms. 5.1 AI Act Implementation The EU AI Act introduces requirements relating to risk management, data governance, documentation, traceability, transparency, human oversight, accuracy, robustness and cybersecurity for relevant AI systems. Cyprus should seek to translate these requirements into practical national lifecycle governance. Compliance should become an embedded operating process rather than a final administrative checkpoint. 5.2 Regulatory Interoperability AI governance should connect with: Data Protection Cybersecurity Digital Identity Public Procurement Critical Infrastructure Administrative Law Sectoral Regulation This would reduce regulatory fragmentation and make compliance more predictable for institutions and businesses. 5.3 Evidence, Traceability and Accountability Significant AI systems should maintain appropriate evidence throughout their lifecycle so decision-makers can establish: What was assessed What risks were identified What controls were applied Who approved deployment What was deployed What changed How the system performed This would strengthen accountability and support responsible AI deployment. 5.4 Proportionate Regulation and SME Accessibility Regulation should remain proportionate to the risk, scale and societal impact of AI applications. This is particularly important for SMEs and innovative companies. Cyprus should seek a regulatory environment that is: Predictable Interoperable Risk-Based Evidence-Based Innovation-Enabling 5.5 Regulatory Foresight The national framework should incorporate mechanisms to anticipate emerging technologies, risks and European regulatory developments. The objective should be to move from reactive compliance towards: Regulatory Foresight → Preparedness → Assurance → Responsible Innovation 6. POTENTIAL CYPRIOT IMPLEMENTATION CAPABILITY AND STRATEGIC CONTRIBUTION Successful implementation of the National AI Strategy 2032 will require not only public-sector leadership and institutional coordination, but also access to specialised expertise capable of translating policy, regulation and strategic priorities into structured execution. Cyprus has an opportunity to develop and retain such capabilities domestically. In this context, Areté Strategy AI Ltd, a Cyprus-based policy, governance and regulatory execution intelligence company, has developed specialist expertise at the intersection of: AI Policy Regulatory Intelligence Governance Strategic Execution Institutional Transformation Assurance Areté's work is particularly relevant to the proposed execution layer because it focuses on translating complex strategic and regulatory requirements into structured implementation frameworks, governance mechanisms, execution controls, evidence and measurable outcomes. Arete has developed the concept of Regulatory Execution Intelligence (REI™), approaching regulation and policy not only as requirements to be interpreted, but as systems that can be translated into: Decisions → Responsibilities → Controls → Evidence → Execution → Outcomes Within the national AI context, this capability could potentially contribute to areas such as: National AI Portfolio Structuring Mapping strategic AI initiatives, objectives, dependencies, responsibilities, risks, milestones and expected outcomes. AI Regulatory and Governance Mapping Translating applicable European and national requirements into operational governance requirements, lifecycle controls and institutional responsibilities. AI Execution Assurance Supporting stage-gated approaches through which AI initiatives can be assessed for readiness, risk, governance, implementation and scaling. Strategic Dependency Intelligence Mapping relationships between data, infrastructure, cloud, cybersecurity, procurement, regulation, skills, technology providers and institutional capabilities. AI Readiness and Execution Measurement Supporting structured assessments of institutional readiness, execution progress and value realisation. Executive Decision Intelligence Providing decision-makers with structured intelligence concerning implementation status, emerging risks, dependencies, strategic bottlenecks and opportunities for intervention. Arete could therefore contribute, where appropriate and subject to applicable institutional, legal, procurement and competition requirements, as a specialist Cypriot implementation and strategic execution capability supporting selected components of the National AI Strategy 2032. This contribution does not seek to replace the responsibilities of Government, competent authorities, public institutions or national AI governance structures. Rather, it highlights the potential value of developing domestic Cypriot capabilities that can complement public-sector capacity where specialised execution, governance and regulatory intelligence are required. Any future engagement, pilot, technical assistance, research collaboration or procurement of services should be considered independently through the appropriate institutional and legal mechanisms. The broader objective should be to: Build National Capability → Test in Cyprus → Measure Results → Institutionalise What Works → Develop Exportable Expertise This would enable Cyprus not only to adopt AI, but potentially to develop internationally relevant expertise in AI governance, regulatory execution and responsible national implementation. 7. NEXT STEPS The recommendations could be translated into practice through a phased implementation pathway. Step 1 — Establish a National AI Execution Baseline Conduct a structured baseline assessment of existing AI initiatives, governance mechanisms, infrastructure, data capabilities, regulatory requirements, dependencies, resources and performance indicators. Step 2 — Establish National AI Portfolio and Dependency Mapping Create a consolidated view of strategic AI initiatives and their critical interdependencies across Government and relevant sectors. Step 3 — Define the Assurance and Stage-Gate Framework Develop common and proportionate evidence requirements for assessing significant AI initiatives from design through deployment and scaling. Step 4 — Establish Value and Performance Metrics Define common KPIs and outcome measures connecting AI investment with measurable public, economic and strategic value. Step 5 — Pilot the Execution Architecture Apply the proposed architecture to a limited number of strategically important AI initiatives. The pilot should test: Portfolio Visibility → Dependency Mapping → Regulatory Readiness → Assurance Gates → Execution Monitoring → Value Measurement Step 6 — Establish Continuous Strategic Review Create an annual evidence-based review mechanism through which implementation performance, risks, technological developments and emerging opportunities inform adjustments to the Strategy. Step 7 — Develop a National AI Execution Dashboard Subject to appropriate governance, security and data-access requirements, establish an executive-level dashboard providing decision-makers with consolidated visibility over: Strategic initiatives Execution status Dependencies Risks Assurance status KPIs Investment Value realisation The dashboard should function as a decision-support mechanism, not merely a reporting tool. Step 8 — Establish a Cyprus AI Execution Capability Pilot Following adoption of the Strategy and subject to appropriate governance and procurement procedures, Cyprus could consider a controlled pilot bringing together relevant public-sector expertise, academia, technology providers and qualified Cypriot specialist firms. The purpose would be to test the proposed execution architecture under real institutional conditions before determining which capabilities should subsequently be institutionalised. This would allow Cyprus to: Test Before Scaling → Measure Before Institutionalising → Build National Capability → Avoid Permanent External Dependency 8. CONCLUSION Cyprus does not need to compete with larger states solely through the scale of infrastructure, compute or financial investment. It can create strategic advantage through the quality, agility, coherence and execution capacity of its national AI architecture. The National AI Strategy 2032 already provides the strategic direction. The opportunity now is to strengthen the mechanisms through which that direction becomes measurable national capability. The success of the Strategy should therefore not be measured solely by the number of AI initiatives launched, pilots completed or investments made. It should ultimately be measured by whether Cyprus has developed the institutional capacity to: Prioritise → Decide → Execute → Assure → Scale → Measure → Adapt its AI investments and capabilities. The proposed National AI Execution, Assurance & Performance Architecture would provide a complementary execution layer connecting: AI Policy → Regulation → Data → Infrastructure → Investment → Governance → Execution → Impact Its purpose is not to create another programme or governance body. Its purpose is to strengthen the ability of the Republic of Cyprus to operate AI as a coherent, measurable and continuously adaptive national system. The strategic advantage for Cyprus may therefore lie not in attempting to replicate the scale of larger AI economies, but in becoming exceptionally capable at connecting policy, regulation, governance, infrastructure, innovation and execution within one trusted national framework. By 2032, the strongest measure of success would be a Cyprus that is not only an adopter of AI, but a country capable of designing, governing, deploying, assuring, scaling and measuring AI responsibly and consistently. The National AI Strategy 2032 can provide the direction. The proposed execution architecture can help ensure that Cyprus has the institutional intelligence and operational discipline required to deliver it. SUBMITTED BY Christina Ioannou Founder & CEO of Arete Strategy AI Ltd Expert of Global Policy, Governance & Regulatory Execution IntelligenceTM Specialist contribution: National AI Execution, Regulatory Intelligence, Governance, Assurance, Strategic Execution" "01 - ΕΘΝΙΚΗ ΣΤΡΑΤΗΓΙΚΗ ΓΙΑ ΤΗΝ ΤΕΧΝΗΤΗ ΝΟΗΜΟΣΥΝΗ ΤΗΣ ΚΥΠΡΙΑΚΗΣ ΔΗΜΟΚΡΑΤΙΑΣ","Pavlos Loizou","Submission to the Public Consultation on the National AI Strategy of Cyprus 2032: Recognising Property, Land and the Built Environment as a Strategic AI Domain Executive recommendation Cyprus should recognise Property, Land and the Built Environment as a cross-cutting national AI application domain and establish a Cyprus Property Intelligence Data Space and Testbed. This would connect the Strategy’s priorities in government, financial services, tourism, infrastructure, climate and public policy through one of Cyprus’s most economically important and data-intensive systems. The proposal directly supports four national objectives: * Increasing national productivity * Transforming public services * Ensuring secure, sovereign and interoperable data * Developing national capability through public-private partnerships It also addresses the Strategy’s identified challenges relating to fragmented institutional data, limited interoperability and immature data governance. Comment 1: Recognise property as a cross-cutting national AI domain Relevant Strategy sections: Sections 1.3 and 1.4.2 concerning priority sectors and data as a national asset. Recommendation Add Property, Land and the Built Environment as a cross-cutting domain supporting the Strategy’s existing priority sectors, rather than as an additional standalone sector. The Strategy states that priority sectors were selected partly because of their high contribution to national GDP. On that basis, the omission of property and the built environment is material. Economic importance Construction generated approximately €1.73 billion and real-estate activities approximately €3.12 billion in 2024. Combined, these activities generated approximately €4.85 billion, representing 15.7% of Cyprus’s gross value added. Financial stability At 31 December 2023, lending to households and non-financial companies secured by immovable property represented 63.7% of the banking sector’s loan portfolio. The value of this exposure was equivalent to approximately 317% of the banking sector’s Common Equity Tier 1 capital. The Central Bank of Cyprus has highlighted that adverse developments in residential and commercial property markets could negatively affect the banking sector. Property data, valuations and risk analytics are therefore directly relevant to: * Credit risk * Collateral management * Capital adequacy * Financial supervision * Non-performing exposure management * Climate and insurance risk Population and housing The population in the government-controlled areas reached approximately 983,000 at the end of 2024, increasing by 1.7% during the year. Net migration was 13,588, while long-term immigration reached 40,471. These demographic changes increase the need for reliable intelligence on: * Housing supply * Rental affordability * New development activity * Local infrastructure requirements * School and healthcare capacity * Population concentration * Urban expansion * Demand by municipality and neighbourhood Tourism and residential accommodation Cyprus received approximately 4.04 million tourists and generated approximately €3.21 billion in tourism receipts in 2024. At the same time, short-term accommodation is increasingly interconnected with the residential housing market. Short-stay guest nights booked through major online platforms increased by 22.3% year-on-year in Cyprus during the first quarter of 2026. This creates a clear policy need to understand the interaction between: * Tourism demand * Short-term accommodation * Long-term rental supply * Housing affordability * Seasonal infrastructure demand * Municipal services * Development planning Rationale Property data is not relevant only to the real-estate industry. It is foundational to: * Banking and collateral risk * Housing affordability * Tourism and destination management * Taxation and municipal revenues * Urban planning and infrastructure * Energy efficiency * Insurance * Climate resilience * Social policy * Public-sector investment Recognition of the built environment as a cross-cutting domain would align the Strategy with its economic selection criteria and with its stated focus on policy design and evidence-based decision-making. Comment 2: Build a governed national property data layer Relevant Strategy sections: Sections 3.2.4 and 3.2.5 concerning data-by-design, capability and infrastructure. Recommendation Create a Cyprus Property Intelligence Data Space within the proposed National Intelligent Digital API Fabric. The State should establish: * Common property identifiers * Interoperability standards * Data governance rules * Secure access mechanisms * Authoritative source registers * Audit and accountability requirements The State should not attempt to build a single monolithic commercial application. Instead, it should provide the trusted data infrastructure and governance framework upon which public institutions and qualified private providers can develop applications. Subject to legal permissions, the initial data model should connect: * Cadastral parcels * Ownership rights * Property transactions * Addresses * Buildings and individual units * Planning zones * Development rights * Planning applications * Building permits * Building characteristics and use * Energy performance information * Utility connections * Aggregated utility consumption * Climate and environmental exposure * Natural-hazard data * Registered leases * Short-term accommodation registrations * Property taxation * Municipal charges * Public infrastructure Access should be tiered: * Public datasets should be reusable * Regulated and commercially sensitive data should be purpose-limited * Access should be role-based * All access should be logged and auditable * Personal data should be anonymised or accessed through privacy-preserving environments * Data owners should remain accountable for accuracy, quality and update frequency International precedents Cyprus can adapt proven European models rather than create an entirely new architecture. Greece Greece is implementing a Unified Property Registry designed to integrate information held by the Hellenic Cadastre, the tax authority, the electricity network operator, planning authorities and other public systems. The initiative has a reported budget of approximately €8.29 million. It is intended to cover: * Buildings * Land * Infrastructure * Ownership * Leases * Tax obligations * Property characteristics Changes recorded in one authoritative database are intended to update the wider public administration, reducing duplication and inconsistencies. This supports: * Better tax compliance * Reduced undeclared property use * Faster transactions * More efficient public administration * Improved planning * Better-quality national property data Source: Greek Ministry of Economy and Finance, Unified Property Registry https://minfin.gov.gr/sto-tameio-anakampsis-to-eniaio-mitroo-akiniton/ Denmark Denmark operates a Data Distribution Platform that provides standardised access to core public registers, including: * Addresses * Buildings * Dwellings * Businesses * Geospatial information * Administrative boundaries The platform is treated as critical national infrastructure and is used by public authorities, private companies and financial institutions. Denmark’s model demonstrates how authoritative public data, common identifiers and standardised access can: * Reduce duplication * Improve data quality * Lower administrative costs * Support private innovation * Enable better planning * Improve public-service delivery Source: Danish Agency for Climate Data, Data Distribution Platform https://www.eng.klimadatastyrelsen.dk/data/the-data-distribution-platform Netherlands The Netherlands links cadastral information, buildings, addresses and municipal property valuations through a coordinated national system. Municipalities assess properties annually through the WOZ system. The resulting values are used for: * Municipal property taxes * National income tax * Corporate tax * Inheritance tax * Water-board charges * Official statistics * Notarial functions * Social-housing rent controls Residential property values and core property characteristics are also publicly accessible. This demonstrates how a common property data infrastructure can support multiple government functions without requiring each institution to create a separate system. Source: Netherlands Council for Real Estate Assessment https://www.waarderingskamer.nl/en/for-residents/explanation-woz-value Common lessons from these jurisdictions The international examples share four principles: * Authoritative source registers * Common identifiers * Interoperability * Controlled public and private reuse Comment 3: Add a Property Intelligence Testbed Relevant Strategy sections: Section 3.8.5 and the initiatives relating to government, financial services, tourism and hospitality. Recommendation Include a Property Intelligence Testbed among the Strategy’s national AI testbeds. The testbed should initially cover three measurable pilot programmes. Pilot 1: Collateral and valuation risk Develop and test: * Explainable automated valuation models * Valuation confidence ranges * Comparable evidence * Independent model validation * Portfolio monitoring * Early-warning indicators * Climate-risk overlays * Model drift monitoring * Human review workflows Primary users would include: * Banks * Credit-acquiring companies * Servicers * Insurers * Regulators * Government valuation authorities Pilot 2: Housing and tourism intelligence Develop a national monitoring framework covering: * Housing supply * Housing affordability * Rental levels * Vacant stock * New construction * Migration-driven demand * Long-term rental availability * Short-term accommodation * Tourism capacity * Demand by municipality * Infrastructure pressure This would enable the Government to assess how tourism, migration, development activity and short-term rentals affect local housing markets. Pilot 3: Planning, compliance and public revenue Connect, where legally permissible: * Planning permissions * Building permits * Registered property use * Ownership records * Lease registrations * Tax records * Utility indicators * Short-term rental registrations The objective would be to: * Identify inconsistencies between approved and actual property use * Improve permitting and inspections * Detect undeclared rental activity * Reduce tax leakage * Improve municipal revenue collection * Monitor unauthorised development * Support infrastructure planning Rationale These pilots directly operationalise the Strategy’s priorities in: * Fraud detection * Compliance * Risk modelling * Smart tourism * Destination management * Resource allocation * Public-sector productivity * Evidence-based policymaking They would create reusable national capabilities rather than isolated demonstrations, reducing the Strategy’s identified risk of AI theatre. Comment 4: Define ownership, timing and measurable outcomes Relevant Strategy sections: Sections 1.5 and 3.3 concerning governance, implementation and measurement. Recommendation Assign strategic delivery responsibility to the proposed National AI Authority. The Department of Lands and Surveys, relevant ministries, planning authorities and municipalities should act as operational owners. A multidisciplinary working group should include: * Department of Lands and Surveys * Planning and building-control authorities * Tax Department * Municipalities * Deputy Ministry of Tourism * Central Bank of Cyprus * Financial institutions * Insurers * Universities * Research organisations * Qualified property-data and technology providers Implementation timetable Months 0 to 8: * Appoint institutional owners * Map available datasets * Identify legal bases for data sharing * Assess data quality * Agree a common property identifier * Define governance standards * Select pilot projects * Agree baseline measurements Months 6 to 12: * Deploy secure APIs * Create controlled testing environments * Launch the initial pilots * Implement independent model validation * Establish audit and monitoring processes Months 12 to 24: * Evaluate pilot results * Scale successful applications * Integrate operational systems * Publish performance outcomes * Extend data coverage * Introduce additional public and private use cases Key performance indicators The programme should measure: * Percentage of properties linked across registers * Dataset coverage * Dataset accuracy * Update frequency * API availability * API response performance * Reduction in valuation time * Reduction in permitting time * Reduction in policy-analysis time * Model accuracy * Model confidence * Model drift * Number of inconsistencies identified * Number of undeclared uses identified * Public-sector cost savings * Additional public revenues * Number of pilots transferred into production * Number of government departments using the infrastructure * Number of approved private-sector applications Proposed contribution from Ask Wire Ask Wire would be willing to contribute practical experience in: * Property-data integration * Automated valuation * Portfolio and collateral risk * Market intelligence * Housing analytics * Climate-risk analytics * Model governance * Data quality controls * Institutional implementation Any participation should take place through transparent, competitive and outcome-based mechanisms. The State should retain ownership of sovereign data, standards and governance. Qualified providers should compete on applications, analytics, innovation and service quality. Conclusion Cyprus cannot implement credible AI in banking, taxation, housing, tourism, climate resilience or urban planning without a governed and interoperable property-data foundation. Property, Land and the Built Environment should therefore be recognised as a cross-cutting national AI domain. The proposed Cyprus Property Intelligence Data Space and Testbed would: * Strengthen financial stability * Improve housing policy * Support sustainable tourism * Reduce tax leakage * Improve planning and permitting * Strengthen climate resilience * Increase public-sector productivity * Enable private-sector innovation This would translate the National AI Strategy from a high-level framework into a practical national capability with measurable economic and social outcomes."