David Benhamou
David Benhamou is a lawyer with more than 20 years of experience in Luxembourg, specializing in contract law, information technology, intellectual property, data protection, and artificial intelligence. He currently serves as Sandbox Lead at the CNPD (Commission nationale pour la protection des données), where he supports organizations in navigating compliance with the EU AI Act and the GDPR through the AI Sandkëscht, Luxembourg’s regulatory sandbox initiative for artificial intelligence. In this role, he works closely with companies to address regulatory challenges, foster trustworthy innovation, and translate legal requirements into practical compliance solutions. Combining extensive legal expertise with a strong focus on emerging technologies, David is actively involved in initiatives such like REMI, Regulation Meets Innovation that bring together regulators, businesses, and innovation stakeholders to promote the responsible development and deployment of AI in Luxembourg.
Session
Panel discussion: The role of open source and cyber commons for preparing for regulatory compliance.
The EU AI Act introduces regulatory sandboxes (Articles 57–59) to help organisations develop, test and validate innovative AI under supervision before market entry. This panel asks how open source and the emerging cyber commons can make this bridge between innovation and compliance more accessible, especially for SMEs, startups, researchers and public bodies.
Bringing together regulators, standardisation and cybersecurity actors, and open-source practitioners, the discussion will explore how shared assets such as datasets, testing tools, reference implementations and conformity-assessment know-how can reduce compliance barriers, and how sandboxes and open commons can reinforce each other: sandboxes provide supervised spaces to experiment, while the commons provides reusable building blocks.
Key questions include: What can a cyber commons realistically offer organisations preparing for AI Act compliance? Where does open source strengthen trust, reproducibility and auditability and where are its limits? How can sandboxes, standards and open commons ensure that lessons learned become shared resources? And how should Europe’s strategic autonomy agenda shape what is built collectively versus procured?
Expected outcome: Attendees will leave with a concrete picture of how open-source tooling and a cyber commons can shorten the path to regulatory readiness, practical entry points for participating in or contributing to these resources, and an understanding of how sandboxes and the commons fit within the broader EU standardisation and compliance landscape.
