The European model of regulating artificial intelligence risks consolidating the power of large technology companies even as it attempts to control them, according to an academic study published in Internet Policy Review. The research compares the AI Act, the Code of Conduct for general-purpose AI models, and the European guidelines for "trustworthy AI" from 2019, and argues that the EU has evolved towards a hybrid form of governance in which Big Tech is not only the subject of regulation but also participates in defining standards, monitoring risks, and implementing obligations.
In short
1. The study compares three stages of European AI policy: the ethical guidelines from 2019, the AI Act from 2024, and the Code of Conduct for general-purpose AI models from 2025.
2. The authors argue that the EU has built a mixed model, with mandatory rules and voluntary commitments, in which large AI providers become central actors in documenting, assessing, and managing systemic risks.
3. The research identifies risks of regulatory capture, dependence on private infrastructure and expertise, and the transformation of political conflicts about AI into issues presented as technical and manageable through audits and procedures.
4. The study criticizes the use of terms like "human-centric AI" and "trustworthy AI," arguing that they can obscure questions about who controls the infrastructure, who benefits economically, and who bears the social, labor, and environmental costs.
5. The authors do not claim that the AI Act is without constraints or that the EU has abandoned regulation. Their conclusion is that European regulation coexists with an increasing dependence on the companies it attempts to oversee.
The study, authored by Alvaro Oleart from the Université libre de Bruxelles and Alejandro Flores Moleón from the Universidad Autónoma de Madrid, starts from one of the central contradictions of European policy for artificial intelligence. The EU has adopted the world's first comprehensive legislative framework for AI, but its implementation depends at the same time on the cooperation of the companies that develop the most advanced models and control a significant part of the technological infrastructure.
The authors analyze this relationship through the concept of "sociotechnical imaginary," used to describe collective visions of the desired future of technology, the risks to be avoided, and the actors considered legitimate to manage these risks. From this perspective, the research does not focus only on concrete legal obligations but also on how European documents describe AI, innovation, safety, and the role of industry.
The first document examined is the 2019 set of guidelines from the high-level expert group on artificial intelligence. It defined "trustworthy AI" by respecting human autonomy, preventing harm, ensuring fairness, and providing explainability, linking European competitive advantage to the development of technology considered ethical.
The second milestone is the AI Act, adopted in 2024, which establishes legal obligations based on risk levels. Some uses are prohibited, high-risk systems must meet strict requirements, and other categories fall under transparency obligations or lighter rules.
The third is the Code of Conduct for general-purpose AI models, which translates some of the obligations regarding general-purpose models into operational commitments regarding transparency, copyright, safety, and security.
The authors believe that the transition between these documents shows a progressive shift from a more open ethical debate towards an architecture in which safety is increasingly managed through reporting, assessments, documentation, and technical procedures.
In the case of the code for general-purpose models, adhering providers must create and update their own safety and systemic risk frameworks, establish acceptable risk levels, document assessments, and define internal responsibilities. The AI Office oversees the system, but a significant part of the evaluation and control process remains within the organizations that develop the models.
For the authors, this is the essential form of co-regulation. Companies do not solely decide the legal framework but become responsible for building many of the tools through which compliance and risk are demonstrated to authorities.
The study does not claim that European legislation is purely voluntary. The AI Act remains a mandatory regulation, with prohibitions, requirements for high-risk systems, and obligations for providers and users. The argument of the research is that this legal component functions alongside mechanisms in which the industry contributes to defining enforcement practices.
This combination can create a problem when the public authority depends on the technical expertise of the companies it must oversee. Providers have more information about their own models, infrastructures, testing methods, and technical limits than authorities or civil society, which can give them a privileged position in discussions about standards and implementation.
The authors place this relationship in the context of the broader power of the technology industry in Brussels. The study cites literature on lobbying activities and observes that the tech sector ranks among the most powerful and well-funded interest groups present in European policy-making.
Their conclusion is that the expertise and resources of the industry can allow companies to present themselves as indispensable technical partners for authorities, which reduces the distance between the regulated actor and the actor that contributes to the development or interpretation of standards.
The study describes this relationship using the term "technosolutionism." The concept refers to the tendency to transform complex social, political, or economic problems into technical issues that can be solved through tools, standards, algorithms, and procedures.
The authors believe that this logic is visible in the way the EU talks about AI. Technology is presented simultaneously as a source of risk and as a tool capable of providing benefits in health, agriculture, climate, public services, energy, education, and other areas.
In the architecture of the AI Act, risks are classified and associated with different levels of control. For the authors, this structure implicitly assumes that most risks can be identified, measured, and managed, allowing technology to continue to be developed and used.
The Code for general-purpose AI models takes this logic into an even more technical area through continuous monitoring, model assessments, safety testing, reporting changes, and documenting residual risk. The provider can continue development and launch when the risk is reduced to an acceptable level within the applicable framework.
However, the study criticizes the idea that all AI-related issues can be treated in this manner. Conflicts regarding the distribution of economic power, surveillance, data use, working conditions, or environmental impact are not necessarily problems that can be resolved solely through a technical test or a documentation obligation.
One of the strongest criticisms concerns the European concept of "human-centered AI." The authors argue that the formulation is too broad and does not clarify which human interests are prioritized when there are conflicts between the companies developing the technology, users, workers, or affected communities.
In this logic, the fact that a system is designed and documented as "human-centric" does not automatically resolve questions about the distribution of benefits and costs. The study pays attention to workers involved in data labeling and content moderation, especially those in lower-income countries, who may remain invisible in the description of AI as a software product.
The authors also assert that the material dimension of artificial intelligence is insufficiently present in the current framework. The development and operation of models require data centers, servers, energy, water, and raw materials, and the research considers that these costs are much less visible in the AI Act and in the code for general-purpose models than the risks associated with the use of software.
The study sees the 2019 ethical guidelines as a more explicit approach to social and environmental welfare than in subsequent tools. The expert group spoke about environmental impact, surveillance, manipulation, discrimination, and the need for broader involvement of societal actors.
However, the authors do not present the evolution from 2019 to 2025 as a total rupture. They believe that there is continuity between the three documents, but that the emphasis has progressively shifted towards administrative and technical control mechanisms.
The AI Act strengthens the risk-based legal framework, and the Code of Conduct for general-purpose AI models transforms it into a system of continuous monitoring and reporting. For researchers, the result is a form of "administrative humanism," in which trust is increasingly demonstrated through documentation, audits, and procedural traceability.
This transformation can be useful for oversight, as authorities need comparable and auditable information about models. The study's criticism is that such procedures can also become a substitute for broader political questioning about whether certain uses, business models, or infrastructures should be accepted in their current form.
In conclusion, the AI Act and the Code for general-purpose models reinforce a hybrid model in which public authority and private infrastructure are closely interdependent. Big Tech remains subject to European obligations but is simultaneously necessary for developing standards, providing data, assessing systems, and implementing certain aspects of control.
The authors link this trend to the more recent direction of the Commission towards competitiveness and simplifying digital regulation. The study mentions the Digital Omnibus proposed in 2025 and interprets it not as a complete change of direction but as an acceleration of an already existing trend of prioritizing innovation and cooperation with the industry.
This interpretation belongs to the authors and does not represent the official position of the European Commission. The research is a peer-reviewed academic article published on August 21, 2026, in Internet Policy Review, and the authors declare that they have not received funding for the study and that they have no conflicts of interest that could have influenced the results.
The study does not directly measure the influence of a particular company on a specific article of the AI Act and does not demonstrate that a certain obligation was introduced as a result of lobbying by a private actor. The method consists of a comparative analysis of documents and political discourse, supplemented by academic literature on regulation, lobbying, and the power of platforms.
The authors coded the documents according to eight dimensions, including the desired future, geopolitics, the justification for regulation, responsible actors, how AI is described as a problem or solution, identified risks, and functions attributed to technology.
Their conclusion is that the EU continues to present itself as a global leader in a form of safe and rights-based AI, but also exercises this leadership in a system in which dominant American companies maintain control over a significant part of the models, infrastructure, and expertise necessary for enforcing the rules.
The study proposes that the European debate should allow more space for alternatives that reduce dependence on large platforms, strengthen democratic control, and explicitly address the economic, labor, and environmental dimensions of artificial intelligence.
The AI Act came into force in 2024 and introduces a European system based on risk levels, with prohibited practices, rules for high-risk systems, and transparency obligations for other categories of AI. For general-purpose models, the framework is complemented by the GPAI Code of Conduct, designed to help providers demonstrate compliance with obligations regarding transparency, copyright, safety, and systemic risk.
The study published in Internet Policy Review does not contest the existence of these obligations but argues that the way they are implemented creates a form of co-governance between European authorities and industry. Big Tech is simultaneously regulated and necessary for providing expertise, documentation, and infrastructure used in the oversight process.
This conclusion is the authors' analysis and not an institutional finding of the EU. The article is peer-reviewed and examines European AI policy from 2019 to 2025 through a theoretical framework centered on power, discourse, and "sociotechnical imaginaries."
Latest News
20:34
20:32
20:12
20:05
19:55
See more news