Featured Article : New EU Cars Must Now Watch The Driver

From 7 July 2026, every newly manufactured passenger car and van sold in the European Union must include a new generation of advanced safety systems, including technology that monitors whether drivers are paying attention to the road, marking another significant step towards vehicles that actively watch over both their occupants and everyone around them.

The Next Stage Of Smarter Vehicle Safety

The changes form part of the second phase of the EU’s General Safety Regulation, which has gradually introduced advanced driver assistance systems as mandatory equipment rather than optional extras.

The first phase, which took effect in 2024, introduced technologies such as intelligent speed assistance, lane-keeping systems, reversing detection and driver drowsiness warnings.

This latest phase goes further by requiring all newly manufactured passenger cars and vans to include advanced emergency braking capable of detecting pedestrians and cyclists, a driver distraction warning system, improved forward vision, new tyre performance tests and a larger area of safety glass designed to offer greater protection for pedestrians.

The European Commission says these new requirements are intended to make “safer cars, safer roads” while helping protect “pedestrians and cyclists, address crashes caused by driver distraction, and encourage widespread adoption of advanced driver-assistance systems.”

The Camera Watching The Driver

Perhaps the most talked-about feature is the new driver distraction warning system.

Unlike traditional driver assistance features that monitor the road ahead, this system uses a cabin-facing camera to observe the driver’s head position and gaze direction. If it determines that the driver’s attention has wandered away from the road for too long, it provides a warning encouraging them to refocus.

The technology is designed to reduce one of the biggest causes of road accidents, namely driver distraction.

Importantly, this is not an autonomous driving system. The driver remains fully responsible for controlling the vehicle at all times. Instead, the technology acts as another safety aid, much like automatic emergency braking or lane departure warnings.

Even so, the requirement has generated debate among privacy campaigners, who question the increasing use of cameras inside vehicle cabins, even where the systems are designed to analyse attention in real time rather than permanently record drivers.

Building Towards More Automated Vehicles

Although the regulation is focused on improving safety rather than introducing self-driving cars, it also reflects a much broader change taking place across the automotive industry.

Modern vehicles increasingly rely on cameras, radar, sensors and powerful onboard computers to assist drivers with everyday tasks. As more of this technology becomes mandatory, every new vehicle effectively gains much of the hardware needed to support increasingly advanced driving functions in the future.

Although the distinction is important, it’s worth noting that these are still driver assistance systems rather than autonomous vehicles. That means they’re really just designed to support a human driver, who remains responsible for the vehicle, rather than making driving decisions independently.

However, the same sensors and processing power that help detect pedestrians or monitor driver attention today are likely to form part of the foundation for more advanced automated driving capabilities tomorrow.

Part Of Vision Zero

The regulation forms part of the European Union’s long-term Vision Zero strategy, which aims to reduce road deaths and serious injuries to as close to zero as possible by 2050.

While European roads are already among the safest in the world, thousands of people continue to die or suffer serious injuries every year in road accidents.

The European Commission believes expanding the use of advanced safety technology across every new vehicle will make a significant contribution towards reducing those numbers.

As the Commission explains: “Manufacturers were given more time to develop these more technically demanding features, which is why the legislation was rolled out in multiple phases.”

What Does This Mean For Your Business?

For businesses operating company cars or commercial vehicle fleets, these technologies will increasingly become standard equipment rather than expensive optional extras.

Over time, that could help reduce accidents involving distracted driving while improving protection for pedestrians and cyclists, potentially lowering repair costs, insurance claims and vehicle downtime.

The wider significance extends beyond road safety. The regulation demonstrates how software, cameras and artificial intelligence are becoming fundamental components of modern vehicles rather than premium add-ons. Cars are steadily evolving into sophisticated computing platforms that continuously monitor both their surroundings and, increasingly, the behaviour of their drivers.

For organisations purchasing vehicles over the coming years, the conversation is therefore likely to become less about choosing advanced safety technology and more about understanding how increasingly intelligent vehicles fit within wider policies covering driver training, fleet management, privacy and data governance. The move towards smarter vehicles is no longer optional and is becoming the new baseline for road transport across Europe.

Sustainability-in-Tech : EU Wants Households To Shift Energy Use As AI Demand Grows

The European Commission is encouraging households to move electricity consumption away from peak periods as rising demand from AI data centres, electrification, and digital infrastructure places growing pressure on Europe’s power grids.

What The EU Has Announced

As part of its new Strategic Roadmap for Digitalisation and Artificial Intelligence in Energy, the European Commission has outlined plans to accelerate the rollout of smart meters and other digital technologies designed to help consumers use electricity when demand is lower and prices are cheaper.

The initiative forms part of a broader effort to modernise Europe’s energy system while managing rapidly growing electricity demand.

Alongside the roadmap, the Commission has also introduced a Data Centre Energy Efficiency Package that includes a new rating scheme for data centres and lays the groundwork for future minimum energy performance standards.

According to the Commission, digital solutions can help consumers “shift consumption to hours when electricity is cheaper and thereby lower their energy bills.”

The Commission believes that greater demand-side flexibility could reduce electricity costs for EU consumers by more than €71 billion per year.

Why Data Centres Are Becoming Part Of The Energy Debate

The growing focus on electricity demand is closely linked to the rapid expansion of AI infrastructure.

Training and operating advanced AI models requires vast computing resources, much of which is housed in large-scale data centres. As AI adoption accelerates, so does the amount of electricity needed to power and cool those facilities.

According to the Commission, data centres already account for around 2.5 per cent of EU electricity consumption, and demand is expected to more than double over the next four years.

At the same time, electricity demand is also increasing from electric vehicles, heat pumps, hydrogen production, and the wider electrification of the economy.

The result is a growing challenge for policymakers attempting to balance economic growth, climate goals, energy security, and affordability.

Ireland Offers A Glimpse Of The Challenge

Ireland provides one of the clearest examples of the pressures that can emerge when data centre growth outpaces energy infrastructure investment.

Data centres now consume more than 22 per cent of Ireland’s national electricity supply, making it one of the most concentrated data centre markets in the world.

The issue has become significant enough that some proposed developments have faced planning and grid-capacity challenges. Concerns have also been raised about the potential impact on electricity prices in regions with large concentrations of digital infrastructure.

While AI data centres are not the sole cause of rising energy demand, they are becoming an increasingly visible contributor to a broader capacity challenge affecting many countries.

A Difficult Balancing Act

The situation highlights a growing tension within European policy. For example, on one hand, the EU wants to accelerate AI development and reduce dependence on foreign technology providers. On the other, the infrastructure required to support those ambitions consumes large amounts of electricity at a time when Europe is simultaneously trying to decarbonise its economy and keep energy affordable.

The Commission argues that digitalisation can help address part of the problem. The roadmap notes that AI-based optimisation of energy systems could improve efficiency, reduce waste, and make better use of existing infrastructure.

As the Commission states, “Tech sovereignty in the energy sector is therefore more urgent than ever” while digital technologies can help create “a clean, competitive and secure EU energy system.”

However, efficiency improvements alone may not solve the underlying challenge if electricity demand continues to grow faster than generation and grid capacity.

What Does This Mean For Your Organisation?

For organisations, the announcement highlights a sustainability issue that is likely to become increasingly important over the next decade.

AI offers significant opportunities for innovation, productivity, and economic growth. However, the infrastructure required to support those benefits has real environmental and energy consequences that governments, businesses, and consumers will need to manage.

The Commission’s response suggests that future energy policy may focus not only on generating more electricity but also on using existing capacity more intelligently through smart meters, AI-enabled grid management, demand flexibility, and stricter efficiency standards.

The wider lesson is that the sustainability debate around AI is moving beyond questions about individual technologies and towards a much larger discussion about how societies generate, distribute, and consume energy in an increasingly digital world.

Tech News : EU Renews UK Data Adequacy Decisions Until 2031

The European Commission has renewed its decisions allowing personal data to flow freely between the EU and the UK, confirming that the UK’s data protection framework continues to meet EU standards despite recent legal changes.

Applies To Two Frameworks

The decision, announced on 19 December 2025, extends the EU’s existing data adequacy arrangements with the UK for a further six years, until December 2031. It applies to two parallel frameworks, one under the General Data Protection Regulation and another covering law enforcement data under the Law Enforcement Directive. Together, these decisions determine whether personal data can be transferred from the European Economic Area to the UK without additional safeguards or legal mechanisms.

What Data Adequacy Means In Practice

Under EU law, personal data can only be transferred outside the EU and EEA if the receiving country provides an “adequate” level of protection. Adequacy decisions are adopted by the European Commission and confirm that a third country’s legal and regulatory framework offers protections that are essentially equivalent to those guaranteed under EU law.

For example, when an adequacy decision is in place, organisations can transfer personal data without needing to rely on alternative tools such as standard contractual clauses, binding corporate rules, or case by case risk assessments. For businesses, public bodies, and digital services, this significantly reduces legal complexity, compliance costs, and operational friction.

The UK first received adequacy decisions in 2021, following its departure from the EU. Those decisions were time limited and included a sunset clause, reflecting concerns about future regulatory divergence after Brexit.

Why The Renewal Was Not Automatic

The original UK adequacy decisions were due to expire on 27 December 2025 but, in June 2025, the Commission adopted a technical six month extension to avoid a legal cliff edge while it reassessed the UK’s legal framework. This review was triggered by the passage of the Data (Use and Access) Act, which amended aspects of UK data protection law.

The Act introduced targeted changes, including adjustments to how personal data can be used for research and charitable fundraising, alongside new requirements for organisations to operate clearer data protection complaints procedures. The UK government described the reforms as limited and pragmatic rather than a wholesale departure from GDPR, but they nonetheless required close scrutiny by EU regulators.

During the extension period, the Commission assessed whether the amended UK framework continued to meet the threshold of essential equivalence required under EU law. This assessment covered both general data protection under GDPR and the handling of personal data for policing and criminal justice purposes under the Law Enforcement Directive.

The Role Of EU Oversight Bodies

The renewal decision followed a formal process involving EU institutions and Member States. The European Data Protection Board, which brings together national data protection authorities across the EU, issued an opinion on the UK’s legal framework. Member States then gave their approval through the so-called comitology procedure, which allows national representatives to scrutinise and endorse Commission implementing decisions.

Sufficiently Aligned

The Commission concluded that the UK’s safeguards remain sufficiently aligned with EU standards, including in areas such as individual rights, oversight mechanisms, and restrictions on onward transfers of data to other third countries.

As with the original decisions, the renewed adequacy determinations include safeguards designed to monitor future developments. A review of how the arrangements are functioning is scheduled after four years, with the option to amend, suspend, or revoke adequacy if the UK diverges in ways that undermine data protection.

A Six Year Extension With Built In Limits

The renewed adequacy decisions will now run until 27 December 2031 and include a fresh sunset clause. This essentially means adequacy is not permanent and must be actively reassessed in light of legal, political, and technological changes.

From the Commission’s perspective, this structure balances continuity with control. It provides long-term legal certainty for organisations that depend on EU UK data transfers, while preserving the EU’s ability to intervene if standards fall.

For UK businesses, the extension avoids what many had warned would be a serious disruption. The UK is one of the EU’s largest data partners, with personal data flowing daily for purposes including trade, financial services, health research, cloud computing, advertising, and human resources management.

Economic And Operational Significance

Industry groups and legal experts have repeatedly warned that losing adequacy would impose substantial compliance burdens. Organisations would need to put alternative transfer mechanisms in place, reassess international data flows, and potentially redesign systems and contracts at short notice.

Previous estimates from UK industry bodies have suggested that the administrative cost of relying on standard contractual clauses and transfer risk assessments could run into billions of pounds across the economy. Also, smaller organisations, charities, and public sector bodies would likely be hit hardest.

The Commission explicitly highlighted these practical implications in its announcement. Henna Virkkunen, Executive Vice President for Tech Sovereignty, Security and Democracy, said the renewal “benefits businesses and citizens alike on both sides of the Channel”. She added that it “ensures the free flow of personal data between the EEA and the UK in full compliance with data protection rules while reducing costs and administrative burdens”.

Virkkunen also emphasised continuity for European organisations, stating that the decision allows companies to keep sharing data seamlessly with UK partners, supporting innovation, competitiveness, and trusted digital cooperation.

Law Enforcement And Justice Cooperation

The adequacy decision covering law enforcement data is particularly significant because it underpins data sharing between EU Member States and UK authorities for policing, criminal investigations, and judicial cooperation.

Michael McGrath, Commissioner for Democracy, Justice, the Rule of Law and Consumer Protection, described the United Kingdom as “an important strategic partner for the European Union”. He said the adequacy decisions “form a central pillar of this partnership” by enabling both commercial exchanges and cooperation in the fields of justice and law enforcement.

McGrath added that the renewal reflects the Commission’s assessment that the UK’s legal framework continues to provide robust safeguards for personal data that remain closely aligned with EU standards, including in the context of recent legislative developments.

Ongoing Concerns And Future Scrutiny

It should be noted here, however, that while the renewal provides stability, it does not remove all uncertainty. Privacy advocates and some EU lawmakers have previously raised concerns about the UK’s approach to surveillance, data sharing with third countries, and the potential for future divergence from GDPR principles.

The four year review mechanism is intended to address these risks by allowing the Commission and the European Data Protection Board to reassess adequacy in light of concrete evidence rather than hypothetical concerns. Any significant weakening of protections could still result in suspension or revocation of the decisions.

For now though, it looks as though the Commission’s renewal signals confidence that the UK remains closely aligned with EU data protection standards, while retaining the ability to revisit that judgement if circumstances change.

What Does This Mean For Your Business?

The renewal confirms that the EU continues to see the UK as a trusted destination for personal data, despite political separation and limited legal divergence since Brexit. It removes the immediate risk of disruption to data flows that underpin everyday commercial activity, public services, and cross border cooperation. For now, the legal foundations that allow organisations to move personal data between the EU and UK without additional safeguards remain intact.

For UK businesses, this brings practical certainty. For example, companies operating across borders can continue to rely on existing systems, contracts, and data driven services without having to introduce costly transfer mechanisms or redesign operations at short notice. That stability is particularly important for sectors such as finance, technology, healthcare, research, and professional services, where routine access to EU personal data is fundamental rather than optional.

The decision also has wider implications beyond commerce. Continued adequacy supports cooperation between regulators, law enforcement agencies, and public authorities, ensuring that data sharing for policing, justice, and safeguarding purposes can continue without new legal barriers. At the same time, the inclusion of a sunset clause and a four year review reflects the EU’s ongoing caution, making clear that adequacy depends on sustained alignment rather than historical precedent.

Taken together, the renewal appears to strike a careful balance. In essence, it signals confidence in the UK’s current data protection framework while reinforcing that future reforms will be judged against EU standards. For businesses and other stakeholders, the takeaway message is that the current framework offers breathing space and legal certainty, but long-term stability will depend on how closely the UK continues to track core principles of EU data protection law.

Featured Article : EU Data Act : New Rules For UK Companies

New EU rules on who can access and share data from connected products and cloud services are now live, with major implications for UK firms selling into the bloc.

What Is the EU Data Act?

The EU Data Act is a sweeping piece of digital legislation designed to reshape how data is accessed, shared, and transferred across the European Union. Proposed in February 2022 and adopted in late 2023, it formally came into force on 11 January 2024. Its main provisions, however, only became applicable from 12 September 2025, marking a major shift in Europe’s digital policy landscape.

The Focus

The law’s focus is on non-personal data, particularly that generated by connected devices, such as smart fridges, cars, factory machinery, wearable tech (and suchlike), and the digital services linked to them. It aims to ensure that users, whether individuals or businesses, can access the data generated by their devices and services, and share it with third parties, if they choose.

Its introduction forms part of the EU’s wider strategy to build a fair, innovative, and competitive data economy. It also addresses longstanding concerns over vendor lock-in, contractual imbalances, and a lack of transparency, especially in the cloud computing market.

Why the EU Introduced It

The European Commission has made clear its ambition to create a “single market for data.” With the rapid expansion of the Internet of Things (IoT), vast volumes of data are being produced but often remain locked within platforms controlled by manufacturers or service providers.

EU Commissioner Thierry Breton described the regulation as “a landmark in Europe’s digital decade,” saying it would ensure that “data is fairly shared, stored, and used, and that users have access to the value they help create.”

According to Commission estimates, the volume of industrial data in the EU is expected to increase fivefold between 2018 and 2030. The aim is to open up this data to support innovation across sectors, particularly for small businesses and the public sector.

Who It Applies To and Why UK Businesses Should Pay Attention

Although the Data Act is EU legislation, it has extraterritorial effect, i.e. UK companies can still fall within its scope if they:

– Sell connected products or provide related digital services to users in the EU.

– Offer cloud, edge, or data processing services (such as SaaS, PaaS, or IaaS) to EU-based customers.

– Hold or process non-personal data generated by EU users.

In short, any UK business that interacts with EU clients through connected products or cloud services may need to comply.

Which Are Affected Sectors?

The affected sectors are broad and include:

– Manufacturing (especially smart machinery and industrial equipment).

– Agriculture (IoT-enabled farming tools).

– Transport and logistics (connected vehicles, telematics/vehicle data tracking).

– Consumer tech (smart home devices, wearables).

– Cloud and SaaS providers.

– Facility and building management (smart meters, BMS systems).

What Just Came into Force on 12 September 2025?

From 12 September, many of the Act’s central provisions are now legally applicable across the EU, including:

– The right to access data. Users of connected devices, whether consumers or businesses, can request access to the data those products generate, free of charge and in a usable format.

– The right to share data. Users can also request that their data be shared with a third party of their choice, such as an independent repair provider or external analytics service.

– Fair contract rules. Contracts involving data access or sharing must not include unfair terms. The burden of proof lies with the data holder, who must demonstrate that the terms are fair and non-discriminatory.

– Cloud switching rights. Providers of data processing services must allow customers to switch to another provider more easily. This includes setting out clear porting terms and providing transparency around fees and procedures.

More Dates to Watch

While 12 September 2025 marks the beginning of formal obligations, businesses should also take note of two other key upcoming milestones:

– 12 September 2026. All new connected products placed on the EU market from this date must be designed to enable user access to the data they generate. This introduces a new “data access by design” requirement.

– 12 January 2027. Cloud providers will generally be banned from charging switching or data extraction (egress) fees, unless they can justify those charges objectively. This is likely to reshape the EU cloud market, which has faced repeated criticism over anti-competitive fee structures.

What UK Businesses Should Do Now

UK businesses that are affected need to take the following steps to comply:

– Assess applicability. First, determine whether the business sells connected products or offers relevant digital services within the EU. It is also vital to understand whether the data processed meets the definition of non-personal data generated through usage.

– Map data flows. A clear inventory of data flows is essential, i.e. what data is generated, who generates it, where it is stored, and how it is used or shared. This includes understanding which parties hold what rights over the data.

– Review contracts. Data sharing agreements and cloud service contracts must be updated to reflect new user rights. Any clauses that could be considered unfair, restrictive, or non-transparent may need to be removed or revised to ensure compliance.

– Build access infrastructure. Technical systems must allow users and authorised third parties to access data securely, quickly, and in machine-readable formats. Businesses should also start planning now for September 2026, when connected products must be built with user access in mind.

– Clarify cloud terms. Cloud providers must publish clear switching procedures, exit timelines, and any related fees. Some have already acted. Google Cloud, for example, announced it would waive egress fees to support compliance with the new rules.

– Protect trade secrets. Where businesses have a legitimate reason (e.g. the protection of trade secrets or user safety), they may refuse to share certain data. However, such refusals must be properly justified, and documented procedures should be in place.

– Penalties and Enforcement. Each EU member state is required to appoint a national regulator to enforce the rules. These authorities will have the power to investigate and impose penalties on businesses that fail to comply. The exact penalty levels vary by country, but the Act specifies that enforcement must be “effective, proportionate and dissuasive.” For larger organisations with complex operations, this could mean significant exposure if non-compliance is discovered.

Businesses are also required to keep records demonstrating how they comply with the Act. To support implementation, the European Commission has published model contract clauses and launched a dedicated Data Act Legal Helpdesk for practical support.

Criticism and Challenges

While the Act has been broadly welcomed as a long-overdue update to Europe’s fragmented data landscape, it will come as no surprise that it has not escaped criticism.

For example, some industry voices argue that compliance will be costly, particularly for small businesses that may lack the resources to adapt infrastructure and contracts at pace.

Others have raised concerns about cybersecurity and intellectual property. The ability for third parties to access usage data, even with safeguards in place, has prompted questions about how effectively sensitive information can be protected.

Concerns have also been raised about uneven enforcement. For example, as each EU country sets up its own supervisory regime, multinational businesses may face inconsistency in how the rules are applied or interpreted.

That said, supporters appear to believe that these are reasonable trade-offs in building a more equitable and open data economy. As the European Commission noted in its official guidance, “The Data Act provides a horizontal framework for unlocking data value, while protecting rights and ensuring fairness in the data-driven economy.”

What Does This Mean For Your Business?

For UK companies operating in the EU, the immediate priority is to ensure contracts, systems and internal processes reflect the new rights granted to users. This is particularly relevant for manufacturers of connected products and providers of cloud, edge and data processing services. Organisations that fail to prepare could face compliance risks, contractual disputes or even restricted access to key EU markets.

Those that act early may be better positioned to compete. Building in user data access, transparency and portability could strengthen customer relationships and support future product development. For cloud providers, the pressure to enable smooth switching and eliminate unreasonable fees will only increase as the 2027 deadline approaches.

Beyond UK businesses, the regulation is likely to affect a broad range of stakeholders. Public sector bodies may benefit from greater access to data for emergency response and infrastructure planning. Smaller firms across the EU could gain new opportunities by accessing usage data that was previously unavailable to them. At the same time, larger players may face greater scrutiny over how they manage contractual fairness and protect trade secrets.

While enforcement consistency remains a concern, the main message is that any business interacting with EU customers through connected products or cloud services will need to align with these rules. The next key dates are already set. Those preparing now will be in a stronger position to meet them, reduce legal risk, and remain competitive in a rapidly evolving digital market.

Featured Article : Grok Blocked! Quarter Of EU Firms Ban Access

New research shows that one in four European organisations have banned Elon Musk’s Grok AI chatbot due to concerns over misinformation, data privacy and reputational risk, making it far more widely rejected than rival tools like ChatGPT or Gemini.

A Trust Gap Is Emerging in the AI Race

The findings from cybersecurity firm Netskope point to a growing shift in how European businesses are evaluating generative AI tools. While platforms like ChatGPT and Gemini continue to gain traction, Grok’s higher rate of rejection suggests that organisations are becoming more selective and are prioritising transparency, reliability and alignment with company values over novelty or brand recognition.

What Is Grok?

Grok is a generative AI chatbot developed by Elon Musk’s company xAI and built into X, the social media platform formerly known as Twitter. Marketed as a bold, “truth-seeking” alternative to mainstream AI tools, Grok is designed to answer user prompts in real time with internet-connected responses. However, a series of controversial and misleading outputs (along with a lack of transparency about how it handles user data and trains its model) have made many organisations wary of its use.

Grok’s Risk Profile Raises Red Flags

While most generative AI tools are being rapidly adopted in European workplaces, Grok appears to be the exception. For example, Netskope’s latest threat report reveals that 25 per cent of European organisations have now blocked the app at network level. In contrast, only 9.8 per cent have blocked OpenAI’s ChatGPT, and just 9.2 per cent have done the same with Google Gemini.

Content Moderation Issue

Part of the issue appears to lie in Grok’s content moderation, or lack thereof. For example, the chatbot has made headlines for spreading inflammatory and false claims, including the promotion of a “white genocide” conspiracy theory in South Africa and casting doubt on key facts about the Holocaust. These incidents appear to have deeply shaken confidence in the platform’s ethical safeguards and prompted scrutiny around how the model handles prompts, training data and user inputs.

Companies More Selective About AI Tools

Gianpietro Cutolo, a cloud threat researcher at Netskope, said the bans on Grok highlight a growing awareness of the risks linked to generative AI. As he explained, organisations are starting to draw clearer lines between different platforms based on how they handle security and compliance. “They’re becoming more savvy that not all AI is equal when it comes to data security,” he said, noting that concerns around reputation, regulation and data protection are now shaping AI adoption decisions.

Privacy and Transparency

Neil Thacker, Netskope’s Global Privacy and Data Protection Officer, believes the trend is indicative of a broader shift in how European firms assess digital tools. “Businesses are becoming aware that not all apps are the same in the way they handle data privacy, ownership of data that is shared with the app, or in how much detail they reveal about the way they train the model with any data that is shared within prompts,” he said.

This appears to be particularly relevant in Europe, where GDPR sets strict requirements on how personal and sensitive data can be used. Grok’s relative lack of clarity over what it does with user input, especially in enterprise contexts, appears to have tipped the scales for many firms.

It also doesn’t help that Grok is closely tied to X, a platform currently under EU investigation for failing to tackle disinformation under the Digital Services Act. The crossover has raised uncomfortable questions about how data might be shared or leveraged across Musk’s various companies.

Not The Only One Blocked

Despite its controversial reputation, it seems that Grok is far from alone in being blocked. The most blacklisted generative AI app in Europe is Stable Diffusion, an image generator from UK-based Stability AI, which is blocked by 41 per cent of organisations due to privacy and licensing concerns.

However, Grok’s fall from grace stands out because of how stark the contrast is with its peers. ChatGPT, for instance, remains by far the most widely used generative AI chatbot in Europe. Netskope’s report found that 91 per cent of European firms now use some form of cloud-based GenAI tool in their operations, suggesting that the appetite for AI is strong, but users are choosing carefully.

The relative trust in OpenAI and Google reflects the degree to which those platforms have invested in transparency, compliance documentation, and enterprise safeguards. Features such as business-specific data privacy settings, clearer disclosures on training practices, and regulated API access have helped cement their position as ‘safe bets’ in regulated industries.

Musk’s Reputation

There’s also a reputational issue at play, i.e. Elon Musk has become a polarising figure in both tech and politics, particularly in Europe. For example, Tesla’s EU sales dropped by more than 50 per cent year-on-year last month, with some industry analysts attributing the decline to Musk’s increasingly vocal support of far-right politicians and his role in the Trump administration.

It seems that the backlash may now be spilling over into his other ventures. Grok’s public branding as an unfiltered “truth-seeking” AI has been praised by some users, but in a European context, it risks triggering compliance concerns around hate speech, misinformation, and AI safety.

‘DOGE’ Link

Also, a recent Reuters investigation found that Grok is being quietly promoted within the US federal government through Musk’s (somewhat unpopular) Department of Government Efficiency (DOGE), thereby raising concerns over potential conflicts of interest and handling of sensitive data.

What Are Businesses Doing Instead?

With Grok now off-limits in one in four European organisations, it appears that most companies are leaning into AI platforms with clearer data control options and dedicated enterprise tools. For example, ChatGPT Enterprise and Microsoft’s Copilot (powered by OpenAI’s models) are increasingly popular among large firms for their security features, audit trails, and compatibility with existing workplace platforms like Microsoft 365.

Meanwhile, companies with highly sensitive data are now exploring private GenAI solutions, such as running open-source models like Llama or Mistral on internal infrastructure, or through secured cloud environments provided by AWS, Azure or Google Cloud.

Others are looking at AI governance platforms to sit between employees and GenAI tools, offering monitoring, usage tracking and guardrails. Tools like DataRobot, Writer, or even Salesforce’s Einstein Copilot are positioning themselves not just as generative AI providers, but as risk-managed AI partners.

At the same time, it shows how quickly sentiment can shift. Musk’s original pitch for Grok as an edgy, tell-it-like-it-is alternative to Silicon Valley’s AI offerings found some traction among individual users. But in a business setting, particularly in Europe, compliance, reliability, and reputational alignment seem to matter more than iconoclasm.

Regulation Reshaping the Playing Field

The surge in bans against Grok also reflects a change in how generative AI is being governed and evaluated at the institutional level. Across Europe, regulators are moving to tighten rules on artificial intelligence, with the EU’s landmark AI Act expected to set a global precedent. This new framework categorises AI systems by risk level and could impose strict obligations on tools used in high-stakes environments like recruitment, finance, and public services.

That means tools like Grok, which are perceived to lack sufficient transparency or safety mechanisms, could face even greater scrutiny in the future. European firms are clearly starting to anticipate these regulatory pressures, and adjusting their AI strategies accordingly.

Grok’s Market Position May Be Out of Step

At the same time, the pattern of bans has implications for the competitive dynamics of the GenAI sector. For example, while OpenAI, Google and Microsoft have invested heavily in enterprise-ready versions of their chatbots, with controls for data retention, content filtering and auditability, Grok appears less geared towards business use. Its integration into a consumer social media platform and emphasis on uncensored responses make it an outlier in an increasingly risk-aware market.

Security and Deployment Strategies Are Evolving

There’s also a growing role for cloud providers and IT security teams in shaping how AI tools are deployed across organisations. Many companies are now turning to secure gateways, policy enforcement tools, or in some cases, completely air-gapped deployments of open-source models to ensure data stays within strict compliance boundaries. These developments suggest the AI market is maturing quickly, with an emphasis not only on innovation, but on operational control.

What Does This Mean For Your Businesses?

For UK businesses, the growing rejection of Grok highlights the importance of due diligence when selecting generative AI tools. With data privacy laws such as the UK GDPR still closely aligned with EU regulations, similar concerns around transparency, content reliability and compliance are just as relevant domestically. Organisations operating across borders, particularly those in regulated sectors like finance, healthcare or legal services, are likely to favour tools that not only perform well but also come with clear safeguards, documentation and support for enterprise-grade governance.

More broadly, the story of Grok is a reminder that in today’s AI landscape, branding and ambition are no longer enough. The success of generative AI tools increasingly depends on trust, i.e. trust in how data is handled, how outputs are generated, and how tools behave under pressure. For developers and vendors, that means security, transparency and adaptability must be built into the product from day one. For businesses, it means asking tougher questions before deploying any new tool into day-to-day operations.

While Elon Musk’s approach may continue to resonate with individual users who value unfiltered output or alignment with particular ideologies, enterprise buyers are clearly playing by a different rulebook. They’re looking for stability, accountability and risk management, not provocation. As regulation tightens, that divide is likely to widen.

An Apple Byte : Trump Says Apple CEO Called with EU Concerns

Former US President Donald Trump has claimed that Apple CEO Tim Cook recently called him to voice frustrations over financial penalties imposed by the European Union (EU) on the tech giant. According to Mr Trump, Cook is alarmed by the EU’s regulatory approach, including a significant tax penalty and other fines affecting Apple’s operations within the bloc.

The claim, made during Mr Trump’s appearance on the PBD Podcast, follows a contentious period for Apple and other tech companies under the EU’s stringent competition and digital service rules. For example, in September, Apple lost a significant legal battle over €13bn (£11bn) in unpaid taxes, with the EU’s highest court upholding the European Commission’s accusation of unlawful tax benefits provided by Ireland. Cook, as Mr Trump conveyed, criticised these findings as politically motivated.

Mr Trump recounted that Cook specifically highlighted a recent $15bn fine, with additional charges reportedly raising the total to around $17-18bn. This includes a €1.8bn fine issued earlier this year over alleged breaches in music streaming competition, favouring rival services like Spotify. Cook reportedly expressed frustration over the EU using these fines as revenue, accusing the bloc of building an “enterprise” out of antitrust penalties.

The European Commission, however, has defended its approach, stating that fines for competition breaches are not only punitive but also serve as a deterrent. A Commission spokesperson highlighted that the fines contribute to the EU’s general budget, indirectly reducing the tax burden on citizens. This response reflects the EU’s firm stance that companies operating in Europe must respect its laws and competition standards.

Mr Trump also mentioned ongoing conversations with other tech leaders, including Google’s Sundar Pichai and Meta’s Mark Zuckerberg, as part of his campaign outreach to prominent figures in the tech sector. Elon Musk, CEO of Tesla, and owner of X (formerly Twitter) has also shown support for Mr Trump, who has been vocal in his criticism of the EU’s stringent digital regulations, promising changes should he return to the White House.

As Mr Trump continues to engage with tech executives, regulatory pressures on tech companies in the EU are likely to remain a significant point of contention. With new regulations such as the Digital Markets Act and the Digital Services Act, the EU is signalling a continued commitment to reining in large tech platforms, which could lead to further scrutiny and financial repercussions for major firms operating within its borders.

Tech News : Headaches For MSPs As Microsoft Unbundles Teams

Microsoft’s announcement that it will sell its chat and video app Teams separately from its Office product globally is likely to cause considerable headaches for IT departments and managed service providers.

Why Unbundle? 

Teams is to be unbundled and sold separately globally (it’s been unbundled in the EU since last October) in response to an antitrust lawsuit and to avert the possible associated fine.

An antitrust lawsuit against Microsoft over its bundling of Teams with its Office suite in the EU was initiated based on a complaint from competitor Slack Technologies in 2020. Teams was originally bundled with Office 365 as a replacement for Skype back in 2017 and became popular during the pandemic.

However, rival Slack (now owned by Salesforce) alleged that Microsoft was illegally tying its Teams application to its dominant Office productivity suites, thereby leveraging its market dominance to stifle competition unfairly.

The European Commission said at the time: “Microsoft may grant Teams a distribution advantage by not giving customers the choice on whether or not to include access to that product when they subscribe to their productivity suites.” 

This led to The European Commission investigating Microsoft over its amalgamation of Office and Teams since 2020 and then to Microsoft separating Teams for Office 365 In October last year in the European Economic Area and Switzerland.

Pressure 

Continued pressure from the regulator and the desire to (understandably) avoid a fine that could potentially be up to 10 per cent of its global revenue has now led Microsoft to announce that it will now be unbundling Teams and selling it separately, globally.

How Much?

Starting from April 1, customers can either continue with their current licensing deal, renew, update or switch to the new offers. Unbundled Teams will be available for new customers as a standalone app for $5.25, whereas Office packages without Teams will range between $7.75 and $54.75.

It’s worth noting that these figures may vary by country and currency and Microsoft hasn’t yet disclosed prices for current packaged products.

Trouble For MSPs 

Unfortunately, although the move may be good news for Microsoft’s rivals, it’s not a welcome announcement from the perspective of the many managed service providers (MSPs) who are resellers of Microsoft’s packages and products. Indeed, for MSPs it is likely to mean headaches in several key areas, such as:

– Service delivery and integration. Unbundling may disrupt how MSPs bundle services, demanding changes in delivery models due to the deep integration of Teams with Office applications.

– Billing and subscription management Separate billing for Teams and Office could complicate financial operations, requiring more administrative effort to manage distinct subscriptions and compliance.

– Training and support. A standalone Teams setup might increase support queries and necessitate updated training materials, placing additional demands on MSP resources.

– Client satisfaction and retention. Crucially, the change could confuse clients who are accustomed to (and expect) the convenience of integrated packages, potentially affecting their satisfaction and loyalty (during the adjustment phase), lowering the barriers to exit from their supplier.

– Market competition. Facing competitors offering more cohesive solutions, MSPs may need to reevaluate their offerings and pricing to stay competitive.

What Does This Mean For Your Business? 

This is not an unexpected development, given Microsoft’s unbundling of Teams in the EU last October, continued regulator and competitor pressure, and the threat of a massive fine. It’s good news for Microsoft’s competitors like Slack, however, for Microsoft, some say that even this concession and change in its product strategy may not be enough to avoid a fine.

The complications and unsettling effects it could have on UK business customers could also cause some considerable problems for the UK’s many MSPs. For example, they may find themselves having to navigate a more complex service landscape, facing challenges in service integration, billing management, and customer support. This could mean that MSPs will have to now monitor the impacts carefully and adjust their strategies to minimise the likely negative effects on their business and client relationships.

This could mean having to adapt current offerings and trying their best to ensure seamless integration and support for both Teams and Office applications independently – an extra challenge in an already difficult market.

Tech News : EU’s AI Regulations Agreed

Following 36 hours of talks, EU officials have finally reached a historic provisional deal on laws to regulate the use of artificial intelligence.

The Artificial Intelligence Act 

The Council presidency and the European Parliament’s negotiators’ provisional agreement relates to the proposal on harmonised rules on artificial intelligence (AI), the so-called artificial intelligence act.

The EU says the main idea behind the rules is to regulate AI based on its capacity to cause harm to society, i.e. following a ‘risk-based’ approach: the higher the risk, the stricter the rules.

Protection & Stimulating Investment 

The comprehensive, world-first draft regulation aims to ensure that AI systems placed on the European market and used in the EU are safe and respect fundamental rights and EU values. The hope is that this will also help stimulate investment and innovation in AI within Europe.

The Key Elements 

Some of the key elements in the draft AI act include:

– Rules relating to high-impact general-purpose AI models that can cause systemic risk in the future, as well as on high-risk AI systems.

– A revised system of governance with some enforcement powers at EU level.

– The extension of a list of prohibitions but with the possibility to use remote biometric identification by law enforcement authorities in public spaces, subject to safeguards.

– Improved protection of rights through the obligation for deployers of high-risk AI systems to conduct a fundamental rights impact assessment prior to putting an AI system into use.

The Key Aspects

The new EU Artificial Intelligence Act covers several key aspects:

– Clarifying the definitions and scope of the proposed act. For example, the definition of an AI system aligns with the Organisation for Economic Co-operation and Development’s (OECD) approach, providing clear criteria to distinguish AI from simpler software. The regulation excludes areas outside EU law, national security, military/defence purposes, and AI used solely for research, innovation, or non-professional reasons.

– The classification of AI systems and prohibited practices. AI systems are classified into high-risk and limited-risk categories. High-risk AI systems must meet certain requirements and obligations for EU market access, while limited-risk ones have lighter transparency obligations. The act bans AI practices considered unacceptable, like cognitive behavioural manipulation and untargeted facial image scraping.

– Any law enforcement exceptions. For example, the draft rules include any specific provisions allowing law enforcement to use AI with safeguards, including emergency deployment of high-risk AI tools and restricted use of real-time remote biometric identification.

– New rules addressing general-purpose AI (GPAI) systems and foundation models, with specific transparency obligations and a stricter regime for high-impact foundation models.

– A new governance architecture. An AI Office within the Commission will oversee advanced AI models, supported by a scientific panel. The AI Board, comprising member states’ representatives, will coordinate and advise, complemented by an advisory forum for stakeholders.

– Penalties. Fines for violations are set as a percentage of the offending company’s global annual turnover or a predetermined amount, with caps for SMEs and startups.

– Rules around transparency and protection of fundamental rights. For example, high-risk AI systems require a fundamental rights impact assessment before market deployment, while increased transparency is mandated, especially for public entities using such systems.

– Measures in support of innovation including AI regulatory sandboxes for real-world testing and specific conditions and safeguards for AI system testing. The act also aims to reduce the administrative burden for smaller companies.

EU Pleased 

The comments of Carme Artigas, Spanish secretary of state for digitalisation and artificial intelligence, highlight how pleased the EU is that it’s managed to be first to at least put a provisional, draft set of regulations together. As she says on the EU’s Council of the EU pages: “This is a historical achievement, and a huge milestone towards the future! Today’s agreement effectively addresses a global challenge in a fast-evolving technological environment on a key area for the future of our societies and economies. And in this endeavour, we managed to keep an extremely delicate balance: boosting innovation and uptake of artificial intelligence across Europe whilst fully respecting the fundamental rights of our citizens.” 

More Than Two Years Away 

However, despite the three days of negotiations and the announced provisional rules it’s understood that the AI act (which they will lead to) won’t apply until two years after it comes into force (with some exceptions for specific provisions). Given that it’s just over a year since ChatGPT was released and that in that short time we’ve also seen the release of OpenAI’s Dall-E,  Microsoft’s Copilot, Google’s Bard and Duet (and now its Gemini AI model), X’s Grok, and Amazon’s Q, you can’t help thinking that effective regulation of AI looks like it will stay some way behind the rapidly advancing and evolving technology for some time yet.

Criticism

The idea of putting the AI act together for the EU got a negative response back in June when it was criticised by 150 executives in an open letter representing many well-known companies including Renault, Heineken, and Airbus. Some of the criticisms included were that the rules are too strict, are ineffective, and could negatively impact competition and opportunity and undermine the EU’s technological ambitions.

What Does This Mean For Your Business?

The provisional agreement on the EU’s Artificial Intelligence Act is a double-edged sword for businesses in the AI sector. On one hand, it establishes a framework for regulating AI technologies, yeton the other, its long gestation period and potential for stringent regulations have raised concerns about its possible impact on innovation and competition for the EU.

The Act’s implementation timeline is actually a crucial factor for businesses. For example, the new regulations won’t come into force until at least two years after being finalised, thereby creating a window of uncertainty. During this period, AI technology will continue to evolve rapidly, most likely outpacing the regulations being put into place. This could all lead to a regulatory framework that is outdated by the time it is implemented, potentially stifling innovation and putting the EU at a technological disadvantage compared to other regions that may have more agile or less restrictive approaches.

Also, the Act’s stringent rules, particularly for high-risk AI systems, could impose significant compliance burdens on businesses. While these measures are intended to ensure safety and ethical use of AI, there is a risk that they might be too restrictive, hampering the ability of European companies to innovate and compete globally. Over-regulation, therefore, could deter investment in the AI sector, hindering the EU’s technological ambitions and possibly leading to a competitive disadvantage in the global AI landscape.

The balance between regulation and innovation is therefore a delicate one. While (what will become) the Act aims to protect fundamental rights and ensure the ethical use of AI, it also needs to foster an environment conducive to technological advancement. If the regulations are perceived as overly burdensome or inflexible, they could inhibit the growth and competitiveness of EU-based AI companies, impacting the broader European technology sector.

The EU’s AI Act may be a significant step towards regulating emerging technologies, but its success will largely depend on its ability to strike the right balance between safeguarding ethical standards and supporting innovation and competitiveness in the AI industry. Businesses must, therefore, prepare for a landscape that could change significantly in the coming years, staying agile and adaptable to navigate these upcoming regulatory challenges effectively.