Open Source Conference Luxembourg

AI Regulatory Sandboxes and Cyber Commons

Panel discussion: The role of open source and cyber commons for preparing for regulatory compliance.

The EU AI Act introduces regulatory sandboxes (Articles 57–59) to help organisations develop, test and validate innovative AI under supervision before market entry. This panel asks how open source and the emerging cyber commons can make this bridge between innovation and compliance more accessible, especially for SMEs, startups, researchers and public bodies.

Bringing together regulators, standardisation and cybersecurity actors, and open-source practitioners, the discussion will explore how shared assets such as datasets, testing tools, reference implementations and conformity-assessment know-how can reduce compliance barriers, and how sandboxes and open commons can reinforce each other: sandboxes provide supervised spaces to experiment, while the commons provides reusable building blocks.

Key questions include: What can a cyber commons realistically offer organisations preparing for AI Act compliance? Where does open source strengthen trust, reproducibility and auditability and where are its limits? How can sandboxes, standards and open commons ensure that lessons learned become shared resources? And how should Europe’s strategic autonomy agenda shape what is built collectively versus procured?

Expected outcome: Attendees will leave with a concrete picture of how open-source tooling and a cyber commons can shorten the path to regulatory readiness, practical entry points for participating in or contributing to these resources, and an understanding of how sandboxes and the commons fit within the broader EU standardisation and compliance landscape.

David Benhamou

David Benhamou is a lawyer with more than 20 years of experience in Luxembourg, specializing in contract law, information technology, intellectual property, data protection, and artificial intelligence. He currently serves as Sandbox Lead at the CNPD (Commission nationale pour la protection des données), where he supports organizations in navigating compliance with the EU AI Act and the GDPR through the AI Sandkëscht, Luxembourg’s regulatory sandbox initiative for artificial intelligence. In this role, he works closely with companies to address regulatory challenges, foster trustworthy innovation, and translate legal requirements into practical compliance solutions. Combining extensive legal expertise with a strong focus on emerging technologies, David is actively involved in initiatives such like REMI, Regulation Meets Innovation that bring together regulators, businesses, and innovation stakeholders to promote the responsible development and deployment of AI in Luxembourg.

Dr. Carlo Harpes

Dr Carlo Harpes is an expert in information and computer security, with 32 years of experience in consulting, research, education, and standardization. He is the founder (in 2007) and managing director of itrust consulting.
Carlo Harpes holds a PhD in information techniques and cryptography, acted as PKI expert for ILNAS, External 27001 lead auditor, and assistant professor associated to the University of Luxembourg, national representative of ISO/IEC JTC1 SC27 for almost 20 years, now being=s Chairman of the NSC01 National Standardization committee – Information Security.
Carlo drafted security and continuity policies of the State of Luxembourg and multiple public and private entities, assessed and treated risks, or audited management systems. In his most relevant current research project CyFORT, he acts as the architect of OpenTRICK a risk assessment tool used dozens of times for his customers. He is appointed CISO for more than 10 customers.

Dr. Emilia Tantar

Dr. Emilia Tantar is Chief Artificial Intelligence Officer at the Luxembourg House of Cybersecurity and Head of the Luxembourg Cybersecurity Factory. She spearheaded the launch of Europe’s first cybersecurity data space in 2026, providing open-access cybersecurity datasets to strengthen AI innovation, threat intelligence and cyber resilience across Europe. A recognised leader in trustworthy AI, she chairs as President the Luxembourg National Standardisation Committee for Artificial Intelligence and as convenor CEN/CENELEC JTC 21 WG 2 on “Operational aspects and shapes practical frameworks for AI conformity assessment, as editor of the CEN/CLC/TR 17894:2024 Artificial Intelligence Conformity Assessment and upcoming European norm on AI conformity assessment. Since 2023, she acts as SBS representative, representing the interests of EU SMEs in AI standardisation activities at European and international level. With more than 20 years of experience across research, industry and public-interest innovation, she brings a clear mission to the Summit: make AI not only powerful, but include cybersecurity capabilities for AI systems as an accessible must for trustworthy and genuinely useful AI for society.

Dr. Roy Sugimura

Roy Sugimura is Chief Collaboration Officer at AIST and Chair of Japan's ISO/IEC JTC 1/SC 42 National Committee, leading international AI standardization efforts. He received the Minister of Economy, Trade and Industry Award for his contributions to standards development, accreditation, and certification.

Previously, he was Director of Strategy at NTT DOCOMO and Chair of the TIZEN Association, a global consortium including Samsung, Orange, Vodafone, NEC, and Panasonic. At Panasonic, he led development of the world's first Linux-based 3G mobile phone, earning recognition from the Linux Foundation. He also serves as an advisor for the Linux Foundation.
He participated in Japan's Fifth Generation Computer Project and specializes in natural language processing. He holds an MA from Lancaster University and a PhD in Engineering from Kyoto University.

His professional scope and research management focus heavily on AI safety, machine learning quality management guidelines, formal verification technologies for system risk analysis, and digital architecture development. Through these efforts, Dr. Sugimura bridges innovative research, industry collaboration, and global technical standards.

Lisa Toni Burke

Lisa combines a background in natural sciences with classical singing and a career in media. This combination of delving into technical detail, sieving it for the necessary details, and matching it to the audience is her USP.

​With well over two decades of experience on global stages, Lisa is a trusted presenter for live television, conferences, and cultural events. She is known for her ability to guide engaging, intelligent conversation.

Lisa has tackled all sorts of topics and industries, but has an abiding passion for science, space, high-tech, AI, health, brain health and the arts.

Moderator