A well-known issue has been resurfacing in novel forms in the conference rooms of the European Parliament in Strasbourg and Brussels. To help manage the volume of work, staff members who draft legislative texts and briefing documents have been turning to generative AI tools, which are accessible to anyone with a browser. Errors can occasionally be found in the outputs. unconfirmed information. statistics that don’t add up. The kind of false information that seems credible and spreads as a draft before anyone considers verifying the source. Officials from the European Parliament took note. In order to lessen reliance on external systems while retaining some control over what the tools do and what data they touch, they are developing their own internal AI platform, the EPGenAI Hub.
The fact that a legislative body must develop its own AI system in order to safeguard the integrity of its own work is a minor but significant example of the extraordinary haste with which European regulators have been advancing generative AI governance. The most extensive attempt by any state to govern AI as a category rather than addressing particular applications one at a time is the EU AI Act, which went into effect in 2024 and is being implemented gradually. However, regulators who are attempting to develop regulations for a technology that undergoes significant changes between the drafting and publication of any particular section are experiencing real anxiety due to the rapid advancement of capabilities.

As frontier AI models have improved their technical analytical skills, the cybersecurity aspect has grown much more acute. The issue is real; sophisticated AI systems are actually more adept than previous tools at spotting trends and abnormalities in complicated systems. Because the vital infrastructure supporting banking, power distribution, and telecommunications throughout the continent includes systems that were constructed decades ago, have known vulnerabilities, and have historically been partially shielded by their obscure architecture, European regulators are keeping a close eye on that capability. The security model is altered in ways that legacy infrastructure was never intended to handle by an AI system that can analyze systems at scale and find exploitable flaws.
The geopolitical issue became apparent when the US government temporarily restricted the export of several frontier AI models, which had an immediate impact on users and businesses in Europe. The experience illustrated what European officials had been debating in theory: that the most powerful AI systems are primarily created and managed by American corporations, and that European access to those systems depends on US policy choices. The dependence would immediately become apparent if such access were restricted, either by export restrictions, sanctions, or business decisions. In part, this awareness has prompted the EU to promote European AI development and establish internal alternatives.
While they coexist with cybersecurity concerns, deepfake and disinformation are separate issues. A sophisticated attack on infrastructure is not necessary to address issues like the non-consensual creation of realistic images and video, the production of politically targeted misinformation at a scale and speed that fact-checking organizations cannot match, and the potential for AI-generated content to erode public confidence in genuine political communications. They need to have unrestricted access to tools and be willing to misuse them. It is difficult for European regulators to simultaneously deal with the ambient threat and the sophisticated one.
The real conflict in all of this is that Europe wants to control AI without irreparably lagging behind in its advancement. The bigger AI businesses, whose legal teams are scaled to manage regulatory complexity, are better able to absorb the requirements, but the tightest interpretations of the AI Act’s provisions will impose compliance costs that largely affect smaller developers and startups. The framework as structured may ultimately lead to the consolidation of AI development among the very large companies that the law was intended to oversee in part. European regulators are aware of the irony of that result, which they have yet to fully resolve.
As the European regulatory dialogue progresses, it appears that the worries are valid and the urgency is real. It will take several more years to adequately evaluate whether the specific mechanisms in the AI Act are well-calibrated to meet the real threats rather than the risks that were most apparent when the legislation began.
