Dr. Carlo Harpes
Dr Carlo Harpes is an expert in information and computer security, with 32 years of experience in consulting, research, education, and standardization. He is the founder (in 2007) and managing director of itrust consulting.
Carlo Harpes holds a PhD in information techniques and cryptography, acted as PKI expert for ILNAS, External 27001 lead auditor, and assistant professor associated to the University of Luxembourg, national representative of ISO/IEC JTC1 SC27 for almost 20 years, now being=s Chairman of the NSC01 National Standardization committee – Information Security.
Carlo drafted security and continuity policies of the State of Luxembourg and multiple public and private entities, assessed and treated risks, or audited management systems. In his most relevant current research project CyFORT, he acts as the architect of OpenTRICK a risk assessment tool used dozens of times for his customers. He is appointed CISO for more than 10 customers.
Session
Panel discussion: The role of open source and cyber commons for preparing for regulatory compliance.
The EU AI Act introduces regulatory sandboxes (Articles 57–59) to help organisations develop, test and validate innovative AI under supervision before market entry. This panel asks how open source and the emerging cyber commons can make this bridge between innovation and compliance more accessible, especially for SMEs, startups, researchers and public bodies.
Bringing together regulators, standardisation and cybersecurity actors, and open-source practitioners, the discussion will explore how shared assets such as datasets, testing tools, reference implementations and conformity-assessment know-how can reduce compliance barriers, and how sandboxes and open commons can reinforce each other: sandboxes provide supervised spaces to experiment, while the commons provides reusable building blocks.
Key questions include: What can a cyber commons realistically offer organisations preparing for AI Act compliance? Where does open source strengthen trust, reproducibility and auditability and where are its limits? How can sandboxes, standards and open commons ensure that lessons learned become shared resources? And how should Europe’s strategic autonomy agenda shape what is built collectively versus procured?
Expected outcome: Attendees will leave with a concrete picture of how open-source tooling and a cyber commons can shorten the path to regulatory readiness, practical entry points for participating in or contributing to these resources, and an understanding of how sandboxes and the commons fit within the broader EU standardisation and compliance landscape.
