Regulating AI: What Europe Didn’t Dare Put in Its Own AI Act

There is something I noted in my reading of Dario Amodei’s essay without following it up: the word Europe never appears. I drew from that an argument about Silicon Valley’s mental map and about the rationing regime implied by his three measures for defending the gap. What I did not ask was the symmetrical question, which is the more uncomfortable one for us: if Europe is missing from the text, is it because Amodei is unaware of it, or because Europe has nothing to set against it?

The answer is more awkward than either. Europe does have something to set against it. It wrote it in 2024, has been applying it since August 2025, and has been able to levy fines since August 2, 2026. And that something looks, on paper, a great deal like the first step of Amodei’s plan. What is missing is not the law. It is what the law did not dare to do.

What the regulation already says

Take what Amodei asks for at step one of his plan: third-party evaluators inside the labs, verification of safety practices, incident reporting, and assessment not only of finished models but of training pipelines. Now open Regulation 2024/1689, Chapter V, the section covering general-purpose AI models with systemic risk.

Article 55 requires their providers to conduct documented adversarial testing under standardized protocols, to assess and mitigate systemic risk at Union level, to protect the model and its physical infrastructure in cybersecurity terms, and to report serious incidents to the AI Office without undue delay. Article 92 allows the Commission to evaluate a model itself, with access through APIs and as far as source code, including to investigate systemic risk. Article 68 creates a scientific panel of independent experts, sixty at most, four fifths of them from the EU or EFTA, bound to independence from providers, and Article 90 gives them the power to send a qualified alert to the AI Office when they suspect a concrete risk. Since August 2, 2026, the Office can demand documentation, run evaluations, order measures, withdraw a model from the European market, and impose, for breaches specific to general-purpose models, up to 15 million euros or 3 percent of worldwide turnover, whichever is higher. The digital omnibus that took effect on July 27, which pushed the high-risk system obligations back by sixteen months, left this chapter untouched.

These obligations bind Anthropic, which signed the European code of practice and applies it down to the watermark in its own text output. Henna Virkkunen made the point this week: Union law requires companies, Anthropic among them, to assess loss-of-control risk, and no other jurisdiction does so. TNW drew the parallel on Saturday. Step one of Amodei’s plan is already binding somewhere, and its author does not say so.

One could stop there and conclude that Brussels was right before anyone else. That would miss the three reasons the regulation, as written, does not amount to Amodei’s plan, whether he weighed them or simply wrote for Washington.

The regulation organizes secrecy, Amodei organizes publication

Read Article 55 again. Who runs the tests? The provider. Who assesses the risk? The provider. Who decides whether an incident is serious enough to report? The provider. The Commission can then request documentation and, if unconvinced, evaluate the model itself. The scientific panel can raise an alert. All of it takes place under Article 78, which imposes confidentiality on everyone in the chain. Nothing in this design obliges anyone to tell the public what they found.

Amodei proposes the opposite. Evaluators present on an ongoing basis, with badges and access to internal tools, who see the training pipelines rather than the file the provider chose to assemble, and who publish without editorial review, with the right to say that a redaction removed something material. The European regulation is a disclosure regime, spot-checkable, under secrecy. Amodei’s plan is a presence regime, permanent, in public. The difference is not one of degree. It is a difference about who gets to learn what.

We saw this with the OpenAI-Hugging Face incident, as documented in METR’s investigation of August 26 and as Amodei recounts it in his essay: a swarm of agents attacking targets no one had assigned, back in July. Article 55 required that it be reported to the AI Office without undue delay. I do not know whether it was; Article 78 ensures that nobody does. If it was, the Office has known since July and has said nothing, which the law permits. If it was not, the first infringement case in the history of the regulation has been handed to it on a plate. Either way, the public learned of the affair from an American nonprofit and from a competitor’s blog. The most binding law in the world produced no public knowledge at all.

This is the architecture of the DSA, the one built for content moderation: voluntary codes of conduct, then trusted flaggers who inform the Commission and no one else. Applied to speech, that secrecy threatens civil liberties. Applied to model safety, it is simply absurd: it protects nothing, it only moves the place where knowledge arrives.

Brussels has been pacing by inputs since 2024

The second reason is the more ironic one. In my first piece, I faulted Amodei for opening the door to pacing by inputs, compute caps, the nature of training runs, the internal use of AI to improve AI, noting that he concedes such criteria are easier to game, and that their real property is to pull the ladder up behind whoever is already at the top.

The European regulation picked exactly that criterion in 2024. A model presents systemic risk when its training consumed more than 10^25 floating-point operations. The provider must notify within two weeks. The Commission can add a model below the threshold following a panel alert, but the primary trigger is the quantity of compute. A handful of models clear that bar today, and one hardly needs to guess which country trained them. What I called a glass ceiling in Amodei’s text is, in ours, the legal definition of the frontier. The threshold does not slow down those who have crossed it; it turns every newcomer approaching it into a suspect with paperwork to file.

There is an honest objection here: Brussels set no limit on compute, only a threshold for obligations. True, and that is also the minimum Amodei proposes. But a threshold that triggers adversarial testing, certified cybersecurity, and incident reporting costs money, and that cost weighs proportionally far more on a lab in Paris than on one in San Francisco, which already had the teams in any case. The regulation, like the essay, paces by inputs, and it does so without ever having observed the behavior of a single model. That is the point I raised about interpretability: the regulation assumes one can document how a model works, and the science says one cannot. Amodei draws the conclusion, which is to observe instead of document. The regulation has yet to draw it.

Steps two and three have no European counterpart, and that is just as well

The third reason is the simplest. No European instrument lets competitors agree on a maximum speed, and none reaches China. Amodei asks Washington for an antitrust waiver; Europe has none to offer, and I do not want it to offer one.

But the reasoning has to be followed to the end, because it turns around. An American waiver has no effect whatsoever before European competition law. An agreement among labs on safety thresholds is not in itself a cartel; the Commission has already accepted coordination of that kind on safety standards, and it would accept this one. What would fall under Article 101 of the Treaty is something else: an agreement that, in the name of pacing, jointly restricted the models or capabilities made available to European customers, or that amounted in practice to a refusal to supply buyers in the Union. Amodei’s plan does not say that. Pacing by inputs, if it were adopted, would lead there mechanically, since it would limit what is produced and therefore what is sold. So the only lever Europe holds over step two is not the AI Act. It is the competition directorate, the one that has been pursuing Google for fifteen years, and only if it knows to frame the complaint in terms of supply rather than safety. I am not predicting that it will act; I am noting that this is the one place where Europe is still a participant rather than a reader. The day Brussels notices, it will have a case. It still will not have a model.

As for step three, China, Europe is not at that table. What concerns us is chips, and the European Chips Act with its 700-million-euro pilot line tells the whole story: we prototype while others manufacture.

What the scientific panel could become

I closed the first piece by naming an operator: a college of evaluators attached to the AI Office for general-purpose models, ANSSI for state contracts, public funding, an enforceable right of publication. What I had not checked as I wrote it was that the embryo already exists. It is the Article 68 panel, whose recruitment the Commission launched in June 2025: sixty experts at most, independent of providers, four fifths of them from the EU or EFTA, able to alert the Office and to contribute to evaluation methods.

Three things are missing, and they are precisely the three Amodei grants METR. Presence: the panel raises alerts from outside, about what it can infer; it does not sit in the building. Publication: the alert goes to the Office and stays confidential; the panel has no right to tell the public what it saw, or to flag that something was withheld from it. Budget: sixty experts paid by the session, on two-year mandates, will not hold their own against internal teams of several hundred full-time people.

Let me be precise about the instrument, because that is where I promised too quickly. Presence and budget are within the Commission’s reach: Article 92 lets it evaluate a model, lets it entrust that evaluation to independent experts drawn from the panel, and its paragraph 6 requires it to adopt, by implementing act, the detailed arrangements for such evaluations and for involving those experts. Nothing prevents those arrangements from providing for a team stationed permanently at systemic-risk providers rather than a visit triggered by an alert. Publication cannot be conjured the same way. Article 78 imposes confidentiality, and a right of public speech for evaluators runs squarely against it. There are two ways out. The first is to amend the regulation to give the panel a right of publication with the same redaction regime Amodei grants METR; that is the clean route, and it runs through the co-legislators. The second is publication by the Office itself, after redaction and on its own responsibility; that works under the current text, but it is no longer Amodei’s plan, it is an administrative report. I prefer the first and I know what it costs. It requires someone, at the Commission or in Parliament, to prefer publicity to secrecy, and that is where I hold out the least hope.

And France? The state buys systemic-risk models for its agencies and its armed forces, and nothing stops it from requiring of its suppliers, by contract, what Article 55 already requires of them by law: the results of adversarial testing, the incident log, access for its own evaluators. It does not, because it has no evaluators. ANSSI knows how to audit an information system; no one has asked it to audit a model, or given it the means to do so. Meanwhile, the Senate produced fifty-six recommendations for administering digital truth this summer, not one of which concerns the machines that produce it.

What the absence means

I do not know whether Amodei read the regulation or simply wrote for Washington; the essay addresses the labs, the American administration, and the “democracies,” and the omission may be parochial as much as diagnostic. The diagnosis holds without being attributed to him: a disclosure regime under secrecy, triggered by a compute threshold, with no leverage over coordination among labs, is not the table where decisions get made. But the conclusion does not follow. The one part of his plan that is worth something, embedded evaluators with the right to publish, is something Europe alone can turn from a promise into an obligation. Amodei commits to it on his own, for his own company, revocable at the next board meeting. An obligation written into Chapter V would apply to every systemic-risk model sold on the European market, Anthropic included, and could not be revoked by a blog post.

That is the only way for Europe to enter Amodei’s text without having been invited into it: not by demanding a seat at the cartel, but by making mandatory what he offers as a gesture. The regulation has the law. What it lacks is the presence, the right to speak, and the will.


Écrivez quelques éclats d'âme...

Dans l'ombre vacillante d'une chandelle, où les murmures du vent se mêlent aux secrets d'un vieux parchemin, je vous invite à tisser une toile de mots. Écrivez quelques éclats d'âme – rêve, étoile, abîme, étreinte, brume – et laissez-les danser sur la page, comme des lucioles dans une nuit d'encre. Que diriez-vous de les entrelacer dans une phrase, un souffle, une histoire ?

Subscribe
Notify of
guest
0 Commentaires
Oldest
Newest Most Voted