EU AI Act
EU AI Act, systemic-risk models. Article 55 plus the Code of Practice: evaluations, external evaluators, incident reporting, cybersecurity, and a model report before market.
What it does
Europe's rules for the most powerful models, enforceable since August 2026. Labs must test for serious risks, give outside testers time with the model, report incidents, and file a report before release.
Applies to: General-purpose AI models above 10^25 FLOP or designated by the Commission.
- Notify the Commission within two weeks of a model meeting the threshold (Article 52).
- Perform state-of-the-art evaluations including adversarial testing; assess and mitigate systemic risk; report serious incidents without undue delay; ensure adequate cybersecurity (Article 55).
- Code of Practice signatories: adopt a Safety and Security Framework at least two weeks before market; complete a Model Report before placing a model on the market; use qualified independent external evaluators unless the model is no more capable than existing ones; give evaluation teams at least 20 business days where appropriate.
- Serious incidents reported within 2, 5, 10 or 15 days depending on severity.
- Fines up to 3% of global turnover or €15M.
What's in it: Safety plan, Safety tests, Outside safety tests, 4-week test period, Transparency report, Incident reports, Lock up the weights
Where things stand
Anthropic, OpenAI, Google, Amazon and Microsoft signed the full Code; xAI signed the safety chapter; Meta did not sign. GovAI found no model release delayed or withheld from the EU in the first five months of 2026, before fines applied. The obligations are now enforceable and it is too early to see their effect.
Why it gains ~1 day
Its testing and paperwork cost under a day of U.S. progress, and its security rules make theft slightly harder. On net it slightly widens the lead.
Biggest unknown: How strictly the AI Office reads the 20-business-day evaluation period and the pre-market Model Report once fines apply.
Why it lowers p(doom) by ~0.66%
Europe's rules: testing, outside evaluators, incident reports and security for the most powerful models.
The strongest case that it costs more
Fines only became enforceable on August 2, 2026, so the no-delays finding covers a period when the Code was voluntary. A regulator that treats "at least 20 business days" as a floor and the Model Report as a hard gate has a five-week release delay in its hands, and the AI Office can demand model access for its own evaluation on top. If labs do not want to ship the U.S. first and the EU five weeks later, the whole delay lands on the global release.
The debate
For
- Anthropic, OpenAI, Google, Microsoft and others signed the EU's code of practice for the biggest models, 2025.
Against
Sources
- EU AI Act, Article 55: obligations for GPAI models with systemic risk
- EU AI Act, Article 52: notification within two weeks
- EU AI Act, Article 113: application dates
- GPAI Code of Practice, Safety and Security chapter (July 10, 2025): Appendix 3.4: at least 20 business days; Appendix 3.5: independent external evaluators; Measure 9.3: incident deadlines
- Commission page listing Code signatories
- GovAI, Delays to Frontier AI in the EU and UK (June 2026)
Rough starting points, not precise forecasts. Lead costs assume China doesn't depend on U.S. models, the case least favorable to safety laws, and count 3 years. On the menu you can change every assumption and put in your own numbers. Last priced 2026-09-26.