On 2 August, a new EU rule about AI transparency lands — and most of our industry hasn’t clocked what it means yet. We saw it coming. That’s exactly why we got a room talking about it in London, weeks before the deadline.
In a few days, a small but real piece of the EU AI Act takes effect. From 2 August, businesses using AI have to tell people when they’re talking to one, and label content that AI has generated. It sounds procedural. It isn’t. It’s the first hard transparency obligation of the AI era to actually land, anywhere — and most of the industry hasn’t clocked what it means. Not the contact-centre world. Not the platforms. Not much of anyone, on either side of the Atlantic.
We saw it coming. A few weeks ago now, before Cavell CX, we sat down to dinner in London — hosted by Gamma — specifically to talk about regulation, and what it’s actually worth in the age of AI. It turned out to be the most important question in the room.
Two threads ran through the evening, and they’re the same two threads we keep coming back to at CPaaSAA. Trust — regulation, identity, sovereignty, who gets believed. And Intelligence — what gets built with AI once that trust exists, and who has the nerve to build it. At the table, the two were impossible to separate.
There’s a simple test underneath it all, and it’s the reason for this piece’s title: are you playing, or are you paving? Forming a view of where this goes and placing bets on it — or laying track for someone else to drive their business down? Nobody said those words until the evening was most of the way through. But it was the question the whole night was really circling.
Credit to Gamma for the evening — the only operator at the table, but a generous host of one: channel and technology partners, three hours straight, far better than these things usually are. Three of us anchored it by name — Mike Mills (Gamma’s MD), Tim Banting (a CPaaSAA advisory partner) and Rob Kurver (CPaaSAA’s founding partner) — while the rest of the room, a dozen strong, disagreed enthusiastically under Chatham House rules.
Regulation is clarity, not a cage
The point wasn’t “it’s regulated, so be careful.” It was the opposite: regulation is clarity. Guardrails tell you whether you’re heading the right way. Without boundaries, you’re guessing. And this happens to be the telco’s native language — decades of operating inside clear rules, at scale, across borders. When conversations can be faked and identities spoofed, knowing what “compliant” even means becomes one of the most valuable things you can offer. The telco already has it.
The advantage we don’t use
Here’s the uncomfortable part. The hard, regulated bit of all this isn’t what telcos should fear — it’s what we do. It’s the muscle. We complain about it, then fail to recognise it for the advantage it’s just become. We’re not stopped by the difficulty. We’re expert in it. We’re just not leveraging it.
Enterprises won’t move without clarity. A business in a regulated industry can’t commit to AI until it knows the rules, that it’s on the right side of them, and that someone trustworthy stands behind that. Strip away the abstraction: buyers aren’t asking “is AI impressive,” they’re asking what it does for their business, and immediately behind that — can I trust the answers, can I trust it not to leak my data, can I see why it did what it did? That’s logging, auditability, explainability. Unglamorous words a telco already knows how to do.
It should be us. We understand the EU AI Act, the Cloud Act, the real operational meaning of “compliant” — and we’re regional by definition, which makes us the natural local partner. Hyperscalers have the models and the momentum; they don’t have decades of regional regulatory heritage, and that isn’t something you buy in a quarter.
Providing that clarity is concrete: guiding customers through the channel on what’s actually possible, working with regulators proactively rather than just receiving the rules, and turning “here’s what’s safe” into the confidence that unblocks adoption.
So why aren’t we converting that head start into anything? Too often the instinct is to wait — for the hyperscalers to move first. Mike Mills said plainly this is genuinely difficult, and he’s right. But difficulty is the moat, not the barrier — the people going to Mars know it’s absurdly hard, that’s why they go. On the day of our dinner, the market showed what conviction actually costs: Salesforce paid $3.6bn for Fin; SpaceX priced the largest IPO in history at ~$1.75 trillion; a year ago NICE paid $955m for Cognigy, in our own CCaaS backyard. None of that money went to a telco. Tim asked the room the sharpest version of it: when did a major telco last buy a technology company that actually mattered — never mind one that would have turned a regulatory head start into an actual product? Nobody could name one.
The walls are real — and one lands next week
The timing handed the cautious instinct plenty of ammunition. In a single fortnight, Apple’s rebuilt AI Siri got blocked from EU launch by the Digital Markets Act; the Dutch government blocked Kyndryl from buying the operator behind DigiD on sovereignty grounds — a story we unpacked here; and Anthropic switched off its newest models worldwide after a US export-control order.
And there’s a fourth one — the deadline we opened with. On 29 June, Brussels deferred the heaviest part of the EU AI Act — the high-risk system obligations — from this August to December 2027 and 2028. But Article 50, the transparency requirement — telling people when they’re talking to an AI, labelling AI-generated content — stays exactly on schedule for 2 August 2026. Even the regulators drew the same line we’re drawing: defer the heavy compliance machinery, keep the trust obligation intact. That’s not a coincidence. That’s the whole argument.
Some numbers Tim put on the table (cited by Tim Banting)
- Telecom fraud cost the world ~$38.9bn in 2023; SIM-swap fraud up ~400% across Europe, deepfake voice scams up ~3,000%.
- Nearly three-quarters of EU businesses rank data sovereignty in their top three concerns; only ~1 in 5 trust US tech to handle the rules.
- EU citizens have started winning lawsuits against operators for weak fraud security — fraud is now a legal liability, not just a cost.
The hand telcos aren’t playing
Trust came up hard — one guest said, flatly, they trust Tim Cook more than Keir Starmer. It got a laugh, then it got serious: when trust is the scarce resource, who’s earned it?
The telco’s claim isn’t sentimental, it’s technical. A mobile network knows which SIM you hold, binds device to identity, knows you’re genuinely on the network. A corporate SIP trunk does none of that. Tim’s analogy stuck: telcos own the land and the cables, act like builders assembling the service, yet say they want to be the architects who design what comes next. The trouble is they want to be architects while behaving like builders. “We’re the trusted rails” is one short step from “we’re just the road.”
Shadow AI, and the builders who don’t wait
A senior, fluent table discussing the biggest shift in a generation — and most of the room talked about AI with more familiarity than hands-on experience. (It also skewed fifty-plus and telco-heavy, its own quiet echo-chamber problem.) One person was the exception, quietly building an agentic platform for a new venture. There’s a structural reason the gap persists: in a large enterprise you can’t just experiment with AI — the CISO won’t sign off, so it happens anyway — underground. Shadow IT, then shadow cloud. Now shadow AI, everywhere.
Meanwhile the people without the telco reflex just build — the same pattern at MVNO summits and startup showcases on the fringes of our own events. The network still matters. Increasingly, nobody’s buying the network; they’re buying what gets built on it.
What playing looks like
The table landed somewhere sane: consumer protection is good, not maximal regulation but the right rules, clearly drawn. And playing needn’t mean a moonshot. If AI governance is going to hold, it has to live in the network itself, where it can’t be bypassed — the only real answer to shadow AI. Tim pointed to vCon, an open standard for securely wrapping and storing conversations, as exactly the kind of tool that already exists. What’s missing is the will to pick it up.
Build only the road, and a road is all you’ll ever be.
Where else we’re seeing it
It would be easy to file this as one good dinner and move on. It isn’t. That dinner sat in the cloud communications world — CPaaS, CCaaS, the channel — where the same instinct keeps surfacing everywhere we look this summer: the channel’s job now is helping customers implement AI, not just talk about it. A week later, a different world entirely gathered in Copenhagen for TM Forum’s DTW Ignite, the operator side of the industry. These worlds rarely mix — we don’t know an analyst who covers both. CPaaSAA exists, in part, because we think that’s a mistake.
At DTW, “trust” was, by the organisers’ own account, the literal word of the event — used fifty-plus times in one keynote. New research there found 72% of operators believe their AI is trustworthy; only 14% can prove it. Around the same time, Sinch shared research with us from its AI Production Paradox study (2,527 decision-makers, ten countries): enterprises now rank trust, security and compliance above AI development itself, 75% to 63%. Two worlds, surveyed independently, arriving at the identical answer. The same study found three in four enterprises have already rolled back a live AI agent after a governance failure — Sinch calls the resulting overhead the guardrail tax, which sits comfortably next to our own thinking on the “missing middle”: capability without infrastructure, or the reverse.
Why we keep leaning into this
None of this is new to CPaaSAA — that’s the point. Our AI Voice report made the first version of this argument for voice specifically. Andrew Collinson’s Network API research, out this summer, asks the same question of the network layer. And it’s exactly why Trust, Intelligence and Acceleration are the three pillars structuring CASA26 in Amsterdam this September — including what Article 50 actually means in practice once it lands, and how telcos and their partners turn “transparent” into a genuine commercial advantage rather than a box to tick. That’s a September conversation, done properly, not a rushed one now.
In the meantime, credit where it’s due. Gamma showed this kind of leadership already, simply by hosting the conversation this piece is built on, weeks before most of the industry was having it. They were our Gold sponsor at CASA25, and an evening like this shows exactly why that pairing made sense — a company that treats the regulatory and trust side of the business as a serious commercial question, not an afterthought.
This industry, on both its sides, is deciding right now whether it’s going to play, or pave. CPaaSAA is built to sit where those two conversations meet.
Our thanks to Gamma for hosting, to Mike and Tim, and to everyone around the table who disagreed well. We should do it again.
My lifetime in IT and telecoms has been dedicated to innovation, building bridges and creating change. From the early days of cloud communications to working with operators on innovations and business development, and currently emphasizing APIs, CPaaS/CX and AI, my journey has been one of continuous evolution.
As founding partner at CPaaS Acceleration Alliance and The Next Cloud I'm privileged to help global telcos and techcos thrive in a fast changing world - through events, community building, strategy and global business development. I thrive on challenges and change, strategizing in cloud communications, and bringing people together for mutual success. Travel and continuous learning are my passions.
I believe the global communications industry is pivoting to prioritize customer experience and impactful solutions over mere technology and platforms, and we can tackle societal challenges by merging the strengths of corporates and innovators within new ecosystems.

Comments are closed