Also published as The AI Edge on LinkedIn.
Covering: Satya Nadella's Reverse Information Paradox · EU Cloud and AI Development Act · Agentic Commerce Goes Live in Europe · Malta's iGaming AI Charter
This Week at a Glance
- Satya Nadella published an essay this week arguing enterprises "pay for AI twice" — once in dollars, once in the proprietary know-how they leak into a model as "intelligence exhaust." His five-part fix — Control, Capability, Choice, Cost, Compound — is now the most-discussed AI strategy framework of the year.
- Brussels published a second major AI-adjacent law this week: the Cloud and AI Development Act enters the Official Journal on 15 July, two days from now, introducing a four-tier cloud sovereignty framework that will reshape which providers financial institutions and critical infrastructure operators can use.
- CaixaBank and Visa completed Europe's first live, AI-agent-initiated card transaction — and roughly 30 European banks, including Barclays, BBVA, HSBC UK, ING, Revolut, and Nordea, are already running on the same rails.
- Malta Gaming Authority is setting the pace on iGaming AI governance, its voluntary AI Gaming Charter, developed with the Malta Digital Innovation Authority, is emerging as the reference text before any EU-level gaming-specific AI rule exists.
Section 1: The Big Story
Nadella Says You Pay for AI Twice. He's Also Selling the Second Payment Back to You.
Satya Nadella used a lengthy post on X this week to introduce what he calls the "Reverse Information Paradox," and it has become the most-discussed piece of AI strategy writing this year for good reason. His argument: economist Kenneth Arrow's classic information paradox held that sellers risk losing knowledge the moment they reveal it to make a sale. AI inverts that. Now it's the buyer — the enterprise — that risks giving away its own proprietary knowledge simply by using the technology well. "You essentially pay for intelligence twice," Nadella wrote, "once with money, and again with something even more valuable: the proprietary knowledge you must reveal to make that intelligence useful."
His prescription is a five-part framework: Control (retain ownership of enterprise memory, evaluations, and decisions), Capability (build private environments to customise models without exposing proprietary knowledge), Choice (decouple the orchestration layer from any single model), Cost (combine models and workflows efficiently), and Compound (turn the first four into a continuous learning loop that belongs to the firm, not the vendor).
That lineage is worth sitting with. This is now two of the industry's most prominent CEOs, in consecutive weeks, independently converging on the same diagnosis: the real risk in enterprise AI isn't the model, it's who controls the learning layer sitting behind it. When the CEO of Palantir and the CEO of Microsoft agree on a problem, the problem is almost certainly real.
The question for any executive currently negotiating an AI vendor contract is concrete and answerable this quarter: does the contract give the vendor rights to train on your prompts, corrections, and evaluation data, and if so, on what terms can you claw that back?
Section 2: Regulation & Governance
Brussels Just Published a Second AI Law. This One Is About Where Your Infrastructure Sits, Not What Your Model Does.
The Cloud and AI Development Act enters the Official Journal of the EU on 15 July, tomorrow, with formal entry into force following on 4 August. Unlike the AI Act, this regulation says nothing about model risk or transparency. It is a cloud sovereignty framework, and it will determine which providers public sector bodies and critical infrastructure operators are permitted to procure from.
The Act defines four sovereignty tiers. Level 1 requires that data processing and storage occur within EU infrastructure. Level 2 requires demonstrated independence from third countries. Levels 3 and 4 require EU ownership and control, with full transparency over the software supply chain and no third-country interference. The first tier applies from February 2028; the highest tier becomes mandatory by 2029.
Action item: task procurement and legal teams this month with mapping current and pipeline cloud and AI vendor contracts against the four tiers, before locking into an agreement with a provider unable to meet the tier your sector will eventually require.
Section 3: Enterprise & Industry
AI Agents Are Now Spending Money in Europe. Nobody Has Settled Who's Liable When They Get It Wrong.
CaixaBank and Visa announced this week that they have completed the first transaction in Europe initiated entirely by an AI agent acting on a cardholder's behalf, using real card data and standard merchant systems through Visa's Intelligent Commerce infrastructure. Close to 30 banks across Europe, among them Barclays, BBVA, HSBC UK, ING, Revolut, Nordea, Commerzbank, PKO Bank Polski, Bank of Cyprus, and Piraeus Bank, have joined Visa's Agentic Ready programme.
The governance framing is not settled. An AI agent authorising a purchase is a materially different event from a customer clicking "buy," and card networks have decades of dispute-resolution frameworks built around a human pressing that button, not an autonomous agent. Boards at any institution on that list should already have answers to what their customer agreement says about agent-initiated transactions and whether fraud teams have a distinct escalation path for agent-initiated disputes.
Section 4: EMEA Lens
Malta Is Writing the iGaming AI Rulebook Before Brussels Gets There
Malta Gaming Authority is setting the pace on B2B AI governance for iGaming. The AI Gaming Charter, developed jointly with the Malta Digital Innovation Authority following a targeted industry consultation opened in May, sets out principles on transparency, data protection, human oversight of key decisions, algorithm testing, and supervision of third-party technology providers. No EU-level, gaming-specific AI rule exists yet. In its absence, Malta's charter is functioning as the reference text operators are already building against.
For operators in Malta specifically, and for any EMEA institution watching agentic commerce from the sidelines, the practical move is the same: treat the voluntary frameworks in front of you now as the version of the rulebook you will eventually be required to follow, and get ahead of it while it still costs nothing to comply.
Watch List
| Date | Event |
|---|---|
| 15 July 2026 | EU Cloud and AI Development Act — Official Journal publication |
| 2 August 2026 | EU AI Act — Article 50 transparency obligations become applicable |
| 4 August 2026 | EU Cloud and AI Development Act — formal entry into force |
| Ongoing, 2026 | MGA AI Gaming Charter — consultation feedback and finalisation |
| 2 December 2027 | EU AI Act — Annex III high-risk AI systems compliance deadline |
| 2 August 2028 | EU AI Act — AI embedded in regulated products (Annex I) |
My Take
This week may be remembered as the moment the conversation around AI shifted from capability to control.
Nadella called it the "Reverse Information Paradox." Brussels is addressing it through cloud sovereignty regulation. Banks are confronting it through agentic commerce. Malta is moving early through sector-specific governance.
At first glance, these appear to be separate developments but they are not. They all point to the same underlying question: who remains in control once AI becomes embedded in how an organisation learns, decides and operates?
For the last two years, executives have focused primarily on what AI can do. Increasingly, the more important question is who owns the value created by those capabilities, who governs the learning generated by them, and who ultimately carries accountability when autonomous systems act on behalf of customers, employees or institutions.
The organisations that create the most value from AI over the next decade may not be those with access to the most powerful models. They will be those that establish the strongest control over their knowledge, governance and decision-making frameworks.
Because the real risk is no longer being left behind by AI. It's deploying AI successfully and discovering too late that someone else owns the learning.
George
The AI Edge is published weekly by George Kakouras for informational purposes only and does not constitute legal, financial, or investment advice. Each edition covers enterprise AI deployment, strategy, and regulation for executives operating in EMEA.