Author: Arantxa Herranz
The comparison between the technology sector and the automotive industry is not new. Indeed, there have been many occasions when the similarities and differences between the two have been put on the table to discuss various issues.
Once again, at the Huawei European Cybersecurity Workshop, some speakers drew parallels between technology and cars when discussing security, reliability, and trust. The conclusion was clear: despite all the risks, costs, and inconveniences, legislation is necessary when developing cybersecurity and AI tools.
Today, just as no one would buy a car without carefully reviewing key metrics such as fuel consumption, energy use, and safety, perhaps no one should rely on AI systems without a common framework to evaluate which option is best. While the AI Act and CRA set a regulatory baseline for safety and trust, Sebastian Hallensleben argued that the next frontier will be market‑ and needs‑driven AI quality, based on clear, comparable metrics. He invited the audience to imagine buying a car covered with a cloth, with a salesperson repeating that it is “a really perfect car,” but without providing any figures for speed, fuel consumption, braking distance or safety.
Because of that, the event brought together policymakers, industry leaders, and academics with a clear objective: to move beyond a bureaucratic view of regulation and turn it into a competitive advantage for the European Union. The sessions highlighted the urgent need to move from mere regulatory compliance toward the active construction of trust and quality metrics in Artificial Intelligence (AI) and industrial systems.
Mind the gap
One of the central points of the debate was the gap between the enthusiasm surrounding AI and its actual implementation in the corporate fabric. Anna Spitznagel, Co-founder and CEO of trail presented revealing data from Eurostat indicating that only twenty percent of businesses currently use AI. Spitznagel attributed this disparity to the risks inherent in new technologies and the complexity of internal compliance. “We can only use technology we feel safe about,” Spitznagel asserted, arguing that efficient governance is not a brake, but the key to enabling innovation. “Knowing your AI first can dramatically minimize the compliance workload,” she added. Strategically, the argument was to use AI to govern AI. In a proof of concept with Huawei EU, she said, this approach offered “a clear advantage of up to 95% of efficiency increase when it comes to AI classification, evidence collection and reporting for audit readiness.” In other words, compliance can turn from pure cost into a competitive edge if you can prove speed, traceability and quality.

The tension between regulation and practical utility was addressed bluntly by Alex Leadbeater, Technical Security Director at GSMA and chair of the technical committee at TC Cyber of ETSI. Leadbeater questioned the philosophy behind the new European regulations, urging attendees not to lose sight of the ultimate goal. “If what you are doing does not end with a purpose for the end user, why did you bother?” he reflected. Leadbeater warned about the massive scope of the Cyber Resilience Act (CRA), noting ironically that technically “a mechanical alarm clock with an LED backlight counts as a product with a digital element.” However, his warning was serious regarding the deadlines and the lack of industry preparation. “Those who do not participate now will find themselves with an immovable reality by the end of the year,” he advised referring to the harmonization of standards.

The industrial sector also had a prominent space, where the “assurance competition” was discussed. Experts warned that self-assessments, although permitted in some categories of the CRA, will be rejected by a market demanding higher certainty. “The market will not accept self-assessments just like that,” noted Josué González Pariente, from Bureau Veritas, predicting that vendors will race to obtain third-party certifications, such as IEC 62443, to win tenders. “Those who cannot run fast enough, those who cannot invest… will have to retire,” was the stark warning regarding the future of industrial competitiveness.

Although he offered a more skeptical view of the current CRA categorization, González Pariente also emphasized transparency as the human core of trust, and reinforced the idea that companies should embrace strong vulnerability management (“everyone has vulnerabilities; there is no need to hide them”) with clear disclosure channels and fix roadmaps, and combine penetration and functional testing as part of the standard and as a way for customers to verify that controls actually work in their environment. Certificates, he said, are “a very good starting point” but will likely need to be complemented with evidence about what was tested and how.
Engineering trust
Roland Atoui, CEO of Red Alert Labs, reinforced this idea by stating that “trust is something that the humans behind the technology must choose to earn.” Atoui presented the EUCC certification scheme as a crucial tool to harmonize the digital single market and offer a competitive advantage, noting that trust must be “engineered, tested, and certified; not just promised.”

In his view, the common mistake is to reduce “digital trust” to security controls alone, when in fact it rests on three pillars: technical, social and legal means. Certification, and especially independent third‑party schemes, combine these pillars: laboratories prove their technical competence and methodologies, accreditation bodies harmonise how trust is granted, and legal frameworks define liability and responsibility. Within this framework, the EU has created a cybersecurity certification system under the Cybersecurity Act, assigning ENISA the task of developing schemes.
Atoui described EUCC as a “high quality tool” to demonstrate conformity with CRA essential requirements, particularly for critical sectors such as energy where certain components may, de facto, be expected to have EUCC‑level certification. He also acknowledged the downsides: complexity, high cost, long timelines and the risk of redundant assessments for different markets. But he gave an advice to the audience: engage early with certification bodies and experts, build both security and compliance “by design,” and leverage automation and collaborative platforms like CyberPass to speed up evidence gathering and improve transparency.
Finally, Tim Hatt from GSMA Intelligence offered a macroeconomic vision of the risks, revealing that the telecommunications industry faces an annual risk of one hundred billion dollars due to security breaches. GSMA estimates that around 100 billion dollars of revenue are at risk each year from security incidents, out of a total of 1.3 trillion dollars. That figure includes not only direct financial losses and litigation, but also indirect costs such as churn, brand damage and lost security‑as‑a‑service revenues.

Within this landscape, AI appears as both a powerful support tool and a source of new risks. Indeed, Hatt highlighted the paradox of AI as both a threat and a defense tool and warned about the “blind spot” of quantum computing, pointing out that ninety percent of IoT devices are currently vulnerable to a quantum attack. “I wouldn’t sleep that easy as a chief executive knowing that is hanging out there,”
Beyond technology, Hatt stressed that governance and culture are critical. When asked what had worked best in mobile security over the past three years, operators’ most common answer was culture change, ahead of testing improvements or risk management techniques. That shift is visible in the rapid rise of “secure by design” approaches: whereas only about 20% of the industry had adopted secure‑by‑design models two years ago, close to 70% do so today. “If we’re going to really mitigate the threats here, we have to work with our vendor partners to instill security so that it’s not a forgotten about priority,” he said.
A panel discussion
The last part of the event was a discussion panel with several experts, who share their vision from different perspective (economic, legal, technical). There were lot of topics covered, as the emerging trends in AI implementation, the significant cybersecurity challenges these technologies present, as well as the complexities of navigating new regulations like the AI Act and the Cyber Resilience Act (CRA). The panel aimed to bridge the gap between technical defense, strategic objectives, and legal compliance, offering to the audience insights into building trust and fostering innovation in a rapidly changing digital environment.
Tim Hatt pointed to recent high‑profile breaches, noting that “nobody wants to be in the newspapers for having exposed their customers to this type of breach,” and insisting that governance has become “an executive priority” because the financial and reputational costs are now impossible to ignore.
In that sense, Anna Spitznagel argued that firms can no longer “govern AI without AI,” especially once next‑generation systems are involved, and must work with specialized partners because “if you try to keep up with AI developments, it’s a full‑time job, and we all have a full‑time job.
The regulatory backdrop, centered on the EU AI Act and a growing list of cybersecurity laws, was described as both necessary and destabilizing. Stefano Da Empoli pointed to the so‑called Digital Omnibus as “a good effort to simplify the digital regulation” that nonetheless “is not clarifying too much the situation,” leaving especially small and medium‑sized companies “a little bit confused on what they should do.”While there was broad agreement that regulation is indispensable to create a market for trustworthy AI and security, several speakers questioned whether new frameworks truly break new ground. Alex Leadbeater considered that harmonized standards may lower the cost of market entry, but they risk overlapping obligations(AI Act, CRA, a forthcoming Digital Networks Act, future cloud schemes under draft of CSA2) that operators “are going to end up having to certify” against, raising questions about “how that’s going to add value and which one of those you would want to pick.”
Industrial environments, with long‑lived physical assets, were portrayed as both vulnerable and late to the cybersecurity conversation. Certification demand, Josué González Pariente said, is “growing, especially among the top players,” but many others still see no “full business case” because their systems are “not there for five years but for twenty‑five,” and “decisions are taking longer” with “millionaires” investments. In that scenario, vulnerability management and penetration testing are “still mainly not done in the market” for most industrial actors, although he sees “a positive move from the regulation” and believes that frameworks like the Cyber Resilience Act “are helping” to push gradual change and education of corporate buyers.
Certification itself was presented as a useful but insufficient instrument for trust. Roland Atoui called the European certification scheme “a tool” whose effectiveness is “relative to what it applies on, what it covers,” and linked it directly to the EU’s broader cybersecurity strategy “to augment the level of cyber resilience in the EU and all the different member states.”
The panel also examined how national implementation choices can amplify or soften regulatory pressures. Justyna Wójcik‑Skibińska called for “proportionality not only when executing the provisions, but also when drafting the regulation,” posing three questions on whether mandatory certification across broad product categories is “justified by evidence‑based risk,” whether geopolitical risk criteria are “applied transparently and objectively,” and whether compliance costs “disproportionately affect SMEs.” At the same time, several participants argued that companies cannot wait for all standards to settle before acting, and should instead develop internal governance and assurance models that can adapt. Hendrik A. Reese proposed viewing the landscape through three dimensions: “ecosystem,” “governance, controls, assurance,” and “sovereignty principles.”
Throughout the discussion, the panel returned to the idea that technology, regulation and market forces must evolve together if Europe is to maintain both security and competitiveness. Speakers agreed that AI is “the challenge but also the opportunity,” in Spitznagel’s words, capable of powering both threat prevention and new forms of abuse. They also converged on the notion that “without a clear regulatory environment you don’t have a market,” that legal frameworks are a precondition for a mature European AI and security industry, even if new rules arrive late and create bottlenecks. At the same time, they warned that over‑complex or disproportionate regulation risks confusing companies, slowing adoption and placing undue burdens on smaller players, making proportionality, education and practical governance as central to Europe’s AI future as any specific statute or standard.








Leave a Reply