The EU AI Act is about to become more powerful
Europe doesn't need to make its own models for regulatory leverage

I’ve heard a lot of talk, including from people I ordinarily respect, about Europe’s place in the geopolitics of AI. “They don’t have their own models, how will they have any leverage?”
I’d like to offer a counterpoint to this. As covered by a recent Politico article, Europe is ahead in the AI regulation game, and it’s about to exercise significant enforcement power over US and Chinese AI companies, despite not having leading models of its own.
The reason? Europe is a huge market and companies won’t want to lose it. But to get access to European customers, non-European companies need to comply with the EU’s AI Act, which requires providers of the most advanced AI models to “assess and mitigate possible systemic risks.” The European Commission has identified four of these: bioattacks, loss of control, cyberattacks, and manipulation at scale. Its AI Act has been in effect for about a year, but as of Sunday, the enforcement powers kick in. Europe’s AI Office will have, at least on paper, the power to “monitor and supervise” how well AI companies are handling these risks, which includes requesting that companies submit models for evaluation.
Politico is skeptical companies will comply, repeating a familiar talking point:
Will the U.S.-based frontier models open up their closed models to EU regulators? And how will Brussels deal with the rise of Chinese open-source alternatives? These are both regulatory unknowns, and yet another reminder of Europe trailing on the development front.
The implication is that if Europe regulates too hard, the AI companies will decide the market isn’t worth it. Without its own models, Europe will be forced to lighten things up, lest it lose access. But I think the article misses an important point: competition between China and the US will likely keep the European market extremely relevant. And with no direct competitor of its own, Europe can regulate more freely. In contrast, the US has been hesitant to regulate without China doing the same.
In light of the recent Hugging Face attack, a thankfully low-stakes instance of two major risks that have the potential to be incredibly high stakes (loss of control and cyberattacks), an increase in European regulatory power is pretty timely. Sure, AI companies might choose to pay the fines instead of complying. But if Europe plays its cards right, the AI Act could significantly improve the current state of affairs. Adding some much-needed regulation won’t be enough on its own, but it’s certainly welcome.
The analyses and opinions expressed on AI StopWatch reflect the views of the individual contributors and the sources they cover, and should not be taken as official positions of the Machine Intelligence Research Institute.


