Skip to content
Tyche Institute

News · 16 August 2026

Tyche Institute files a position with the European Commission on the Cloud and AI Development Act

On 16 August 2026 Tyche Institute submitted written feedback on the proposed Cloud and AI Development Act, COM(2026)502, through the European Commission's public feedback procedure. Feedback received on an adopted proposal is summarised by the Commission and presented to the European Parliament and the Council.

Our argument is one sentence long: the proposal plans for AI capacity — compute, cloud, secure processing, sovereignty — but not for the evidence that capacity produces. When an AI system or agent acts on European infrastructure, nothing durable and independently checkable is currently required about what it did, on whose authority, and on what runtime. Capacity without evidence cannot be governed after the fact.

The submission makes three asks, each resting on standards already in force rather than on a new trust root: that supported infrastructure be able to produce standards-based remote attestation (IETF RFC 9334) of the runtime executing an AI workload; that delegated authority be expressed and checked through the existing eIDAS and European Digital Identity Wallet attestation-of-attributes machinery instead of a second, incompatible notion of an authorised workload; and that evidence of automated action be portable between providers, since sovereignty is weakened if the record of what an agent did stays locked inside the provider that ran it.

Chosen against the record, not in a vacuum

Before writing, we harvested the published responses to this file and fifteen adjacent eIDAS, wallet and trust-service consultations, and released the result as an open dataset: 2,244 responses across sixteen initiatives, CC BY 4.0, personal names removed. It is browsable at says.eatf.eu.

The corpus decided what we argued. Portability and lock-in are already engaged by 166 responses, so we did not restate them — we asked only that portability extend to the object the file omits, the evidence itself. Attestation of the acting runtime, counted with word-bounded technical phrase lists, appears in 4 responses corpus-wide and 3 of the 464 filed on this initiative — 15 organisational responses when secure-hardware vocabulary such as HSM and WSCD is admitted; machine delegation in 84 and 13. Evidence that survives the action for later verification appears in 7 responses out of 2,244. Academic and research institutions account for 1.4% of the corpus. We spent a scarce academic voice on the emptiest question rather than the most crowded one.

Correction, 17 August 2026: this page previously reported attestation of the acting runtime in 76 responses corpus-wide and 2 on this initiative, and delegation in 80. Those counts matched the bare token “attestation”, which in this corpus overwhelmingly denotes the regulation’s own attestation-of-attributes vocabulary rather than runtime attestation. The corrected, word-bounded method and the full phrase lists are documented with the dataset. The finding the numbers support — near-absence of the runtime-attestation argument — is unchanged, and is in fact stronger.

One caution belongs in the same breath, and we put it in the submission itself: 1,193 of those 2,244 responses come from Slovakia and 1,190 of them are citizens — a national mobilisation opposing digital identity, and 53% of the raw corpus. Read as a whole the record would misdescribe the professional debate, which is the 786 non-citizen responses. Counts are a keyword floor over response text, so arguments made only inside uploaded attachments are undercounted and every figure above is a lower bound.

Documents

What this is not

Feedback to a public consultation is a policy contribution, not a peer-reviewed publication, and we do not list it as one. It is not advice to the Commission, an endorsement of Tyche Institute's work by any institution, or evidence that our position will be adopted. The technical claims carry their own limits: the prototype root of trust behind our apparatus is a software TPM, not a manufacturer-backed hardware root; this is evidence infrastructure, not proof of compliance, and it certifies no product. The corpus figures are visibility observations of public data at a snapshot, not a claim about representativeness or influence. Tyche Institute has no commercial interest in any cloud, compute or trust-service provider.