|
||
A peer-reviewed study of European Union AI policy argues that the bloc’s regulatory system is giving major technology companies an increasingly important role in implementing the rules meant to govern them, raising concerns about regulatory capture and dependence on private infrastructure.
Published August 21 in Internet Policy Review, the research by Alvaro Oleart of Université libre de Bruxelles and Alejandro Flores Moleón of Universidad Autónoma de Madrid compares the EU’s 2024 AI Act, the 2025 General-Purpose AI Code of Practice and the 2019 Ethics Guidelines for Trustworthy AI. The authors characterize the resulting system as a hybrid governance model in which technology companies are both regulated entities and participants in defining how regulation works.
The General-Purpose AI Code gives providers a formal route to demonstrate compliance with the AI Act. Under the law, providers can rely on approved codes of practice until relevant harmonized standards are available; providers that do not use a code or applicable standard must demonstrate alternative means of compliance to the European Commission. The voluntary GPAI Code covers transparency, copyright, and safety and security requirements.
The European Commission says the code was prepared by independent experts through a process involving nearly 1,000 stakeholders, including industry, civil society, academics and EU member-state representatives. Its current signatories include Amazon, Anthropic, Google, Microsoft, Mistral AI and OpenAI, among others. A task force of signatories, chaired by the EU AI Office, has also been established to support consistent implementation.
Oleart and Flores Moleón argue that this arrangement goes beyond ordinary consultation. In their interpretation, large technology companies increasingly become “co-stewards” of AI governance because providers help operationalize risk assessment, safety practices and other technical processes while supplying much of the underlying infrastructure and expertise on which AI deployment depends. They warn that such dependence can strengthen incumbent companies’ ability to shape regulatory practices and narrow the scope for democratic intervention.
The researchers also link the governance model to dependence on privately controlled infrastructure. They argue that the concentration of compute, cloud infrastructure and technical expertise among a small number of large providers can leave public authorities reliant on the same companies whose AI systems they are responsible for overseeing.
The researchers’ conclusions are an interpretation of the EU framework rather than a finding that companies have displaced regulators. The AI Office remains responsible for facilitating the codes, assessing compliance and enforcing the AI Act. The law also explicitly allows providers to demonstrate compliance without joining the voluntary code.
Sponsored byVerisign
Sponsored byIPv4.Global
Sponsored byRadix
Sponsored byWhoisXML API
Sponsored byDNIB.com
Sponsored byCSC
Sponsored byVerisign