About this strategy
About this strategy
The drafting process
The drafting process
This strategy is the work of a group of experts who all contributed in a personal capacity. It is an independent project that received no funding, commissioning, or editorial direction from any company, government, or EU institution. The strategy was written between May and September 2026 and reflects developments up to early September 2026.
Several groups of experts contributed to the strategy. The Research Leads led on drafting and were supported in their work by the Contributing Experts. Members of the Senior Expert Council reviewed drafts, provided strategic advice, and made suggestions for how to improve the usefulness of the strategy further. Special advisors supported in various ways that went beyond questions of content. Across these categories, there was also a small number of industry experts. To preserve the independence of the strategy while benefiting from industry expertise, their role was consultative: any feedback from them on drafts was optional for other contributors to address. They did not vote on or approve the strategy, and held no veto rights. The non-industry members of the Senior Expert Council and Research Leads led on all content questions, with the Editorial Lead being responsible for resolving any disagreements about the content of the strategy. The strategy is not a consensus document, and being listed as a contributor does not imply endorsement of the entire strategy.
Transformative AI raises many more questions than this strategy can cover. The strategy focuses on a set of crucial questions related to how Europe can build agency and economic strength, protect its citizens from AI-enabled shocks, and create robust public institutions in a world with transformative AI. Many important questions related to transformative AI were not in scope for this strategy, such as how AI adoption and diffusion might best be supported, military AI, AI’s impacts on the information ecosystem, the distribution of gains from AI, AI’s impact on the environment, AI’s impacts on education and child safety, how to ensure human-centric AI development and deployment, what a healthy democracy and civil society might look like in a world with transformative AI, and many more. The authors consider each of these important questions that require urgent deliberation and solutions.
Authors working on this strategy used generative AI tools to varying degrees. Uses included support for research, fact-checking, reference verification, and consistency checks across chapters, and for literature searches and early drafting support in some chapters. Any AI output was reviewed by the authors. The authors produced the analysis, arguments, and recommendations in this strategy. The Editorial Lead takes final responsibility for the content.
This strategy is the work of a group of experts who all contributed in a personal capacity. It is an independent project that received no funding, commissioning, or editorial direction from any company, government, or EU institution. The strategy was written between May and September 2026 and reflects developments up to early September 2026.
Several groups of experts contributed to the strategy. The Research Leads led on drafting and were supported in their work by the Contributing Experts. Members of the Senior Expert Council reviewed drafts, provided strategic advice, and made suggestions for how to improve the usefulness of the strategy further. Special advisors supported in various ways that went beyond questions of content. Across these categories, there was also a small number of industry experts. To preserve the independence of the strategy while benefiting from industry expertise, their role was consultative: any feedback from them on drafts was optional for other contributors to address. They did not vote on or approve the strategy, and held no veto rights. The non-industry members of the Senior Expert Council and Research Leads led on all content questions, with the Editorial Lead being responsible for resolving any disagreements about the content of the strategy. The strategy is not a consensus document, and being listed as a contributor does not imply endorsement of the entire strategy.
Transformative AI raises many more questions than this strategy can cover. The strategy focuses on a set of crucial questions related to how Europe can build agency and economic strength, protect its citizens from AI-enabled shocks, and create robust public institutions in a world with transformative AI. Many important questions related to transformative AI were not in scope for this strategy, such as how AI adoption and diffusion might best be supported, military AI, AI’s impacts on the information ecosystem, the distribution of gains from AI, AI’s impact on the environment, AI’s impacts on education and child safety, how to ensure human-centric AI development and deployment, what a healthy democracy and civil society might look like in a world with transformative AI, and many more. The authors consider each of these important questions that require urgent deliberation and solutions.
Authors working on this strategy used generative AI tools to varying degrees. Uses included support for research, fact-checking, reference verification, and consistency checks across chapters, and for literature searches and early drafting support in some chapters. Any AI output was reviewed by the authors. The authors produced the analysis, arguments, and recommendations in this strategy. The Editorial Lead takes final responsibility for the content.
How to read this strategy
How to read this strategy
This document consists of two main parts, Part A and Part B. Part A sets out the strategy’s assumptions, various objectives to be achieved at the Union and national level, and recommendations for how to achieve them. It is written for senior policymakers and informed general readers and can be read on its own. Part B contains implementation details on Part A’s recommendations and deep dives on AI compute and robotics. It is written for policy staffers in European governments and EU institutions. Readers short on time are encouraged to read the Executive Summary and the recommendations in Part A.
A central theme of this strategy is that guaranteed access to frontier AI – the most capable general-purpose AI systems available at a given time – is crucial for thriving in a world with transformative AI (see Why Europe needs to prepare for transformative AI). Europe could achieve this either by aiming to have guaranteed access to foreign frontier AI or by aiming to develop domestic frontier AI. This strategy covers both approaches, with a focus on the former because of the extremely high costs of a successful European frontier AI project.
This focus has informed the three main thematic pillars that were at the centre of the drafting process:
This document consists of two main parts, Part A and Part B. Part A sets out the strategy’s assumptions, various objectives to be achieved at the Union and national level, and recommendations for how to achieve them. It is written for senior policymakers and informed general readers and can be read on its own. Part B contains implementation details on Part A’s recommendations and deep dives on AI compute and robotics. It is written for policy staffers in European governments and EU institutions. Readers short on time are encouraged to read the Executive Summary and the recommendations in Part A.
A central theme of this strategy is that guaranteed access to frontier AI – the most capable general-purpose AI systems available at a given time – is crucial for thriving in a world with transformative AI (see Why Europe needs to prepare for transformative AI). Europe could achieve this either by aiming to have guaranteed access to foreign frontier AI or by aiming to develop domestic frontier AI. This strategy covers both approaches, with a focus on the former because of the extremely high costs of a successful European frontier AI project.
This focus has informed the three main thematic pillars that were at the centre of the drafting process:
Each pillar contains objectives that are crucial for European policymakers to pursue if Europe is to thrive in a scenario with transformative AI. In addition, throughout the drafting process a set of five objectives that require particularly urgent action has emerged from these pillars. They are highlighted in this strategy as ‘Immediate objectives’ – cross-cutting, time-sensitive objectives Europe should pursue with the highest urgency.
Unless noted otherwise, ‘Europe’ in this strategy refers to the EU and its Member States acting within their respective competences.
Each pillar contains objectives that are crucial for European policymakers to pursue if Europe is to thrive in a scenario with transformative AI. In addition, throughout the drafting process a set of five objectives that require particularly urgent action has emerged from these pillars. They are highlighted in this strategy as ‘Immediate objectives’ – cross-cutting, time-sensitive objectives Europe should pursue with the highest urgency.
Unless noted otherwise, ‘Europe’ in this strategy refers to the EU and its Member States acting within their respective competences.
Executive summary
Executive summary
Without urgent and far-reaching action beginning this year, the prosperity, sovereignty, and security of all Europeans are at risk as AI advances at a rapid pace. The next months and years of AI progress have the potential for both great opportunity and grave danger. Europe, on its current trajectory, is fully exposed to the latter but only to a small share of the former. Like the rest of the world, Europe faces threats such as AI-enabled cyber or biological attacks or loss of control over AI systems. But even if the world manages to mitigate these threats and AI delivers predominantly positive outcomes, the wealth and strategic leverage that powerful AI generates will, by default, concentrate outside of Europe. Neither of these outcomes needs to be Europe’s destiny. But the window for action is closing further every month. Unless Europe wakes up, it risks having no meaningful control over how the most consequential technology ever built will affect Europeans.
AI could have deeply transformative impacts across society before 2030. This would be in line with existing trends, which have led to AI capabilities that would have seemed like science fiction until very recently. For example, over just two years, AI models have leapt from barely completing simple four-minute programming tasks to writing most of the computer code inside the companies that build them. This and similar trends in other domains imply that the world may face transformative AI before the end of the current decade:
Transformative AI: AI systems that change the basic structures of society, including the economy, science, and geopolitics, at a materially faster pace than any technology in history has.
Europe is structurally unprepared for the near-term arrival of transformative AI and risks permanent marginalisation. Europe hosts only three times as much AI computing capacity as a single data centre site being completed in Malaysia this year. European model developers collectively earn less than 2% of the revenue of just two US counterparts. European companies and institutions were recently cut off from access to frontier AI capabilities in crucial domains like cyberdefence and AI research itself.
In addition, Europe is exposed to several risks from transformative AI without adequate protection. Progress in AI capabilities has been outpacing the ability of researchers to ensure AI is safe, and recent incidents and evaluations have shown that cyber, biological, and loss-of-control risks are real, near-term dangers. Yet, most of the conversations about steering the trajectory of transformative AI – how and if we should build it, who realises its gains and who suffers its risks, who gets to tax, control, and wield it and how – take place outside of Europe.
Europe has the resources to thrive and contribute to global flourishing in a world with transformative AI, but the window for utilising them is closing fast. Europe has a large market, several crucial assets in the AI supply chain, stable institutions, and strong technical talent. However, as we approach a world with transformative AI, these and other assets will, by default, likely lose relative value. For example, in AI development, the value of excellent talent will likely decrease as human labour is replaced with AI labour and as even stronger AI is increasingly built by AI itself (‘recursive self-improvement’) – a trend that has already begun.
This strategy offers a path for Europe to rise to the challenge of transformative AI. It contains recommendations for ensuring prosperity, sovereignty, and security, and it is centred on the premise that reliable access to frontier AI is crucial in a world with transformative AI. It is impossible to predict exactly the domains in which lacking access to frontier AI would impact Europe most, but likely candidates include defence, cybersecurity, and science, including AI research itself. To avoid falling behind in critical domains like these, Europe would need to either secure access to foreign frontier AI or develop competitive frontier AI domestically. This strategy covers both approaches, with a focus on the former because of the extremely high costs of a successful European frontier AI project.
Member States and the European Commission should pursue five ‘immediate objectives’ with highest urgency. Together, they would put Europe in a position of strength, contribute to a safer transition to transformative AI, and ensure that Europe’s institutions can deliver on both.
Without urgent and far-reaching action beginning this year, the prosperity, sovereignty, and security of all Europeans are at risk as AI advances at a rapid pace. The next months and years of AI progress have the potential for both great opportunity and grave danger. Europe, on its current trajectory, is fully exposed to the latter but only to a small share of the former. Like the rest of the world, Europe faces threats such as AI-enabled cyber or biological attacks or loss of control over AI systems. But even if the world manages to mitigate these threats and AI delivers predominantly positive outcomes, the wealth and strategic leverage that powerful AI generates will, by default, concentrate outside of Europe. Neither of these outcomes needs to be Europe’s destiny. But the window for action is closing further every month. Unless Europe wakes up, it risks having no meaningful control over how the most consequential technology ever built will affect Europeans.
AI could have deeply transformative impacts across society before 2030. This would be in line with existing trends, which have led to AI capabilities that would have seemed like science fiction until very recently. For example, over just two years, AI models have leapt from barely completing simple four-minute programming tasks to writing most of the computer code inside the companies that build them. This and similar trends in other domains imply that the world may face transformative AI before the end of the current decade:
Transformative AI: AI systems that change the basic structures of society, including the economy, science, and geopolitics, at a materially faster pace than any technology in history has.
Europe is structurally unprepared for the near-term arrival of transformative AI and risks permanent marginalisation. Europe hosts only three times as much AI computing capacity as a single data centre site being completed in Malaysia this year. European model developers collectively earn less than 2% of the revenue of just two US counterparts. European companies and institutions were recently cut off from access to frontier AI capabilities in crucial domains like cyberdefence and AI research itself.
In addition, Europe is exposed to several risks from transformative AI without adequate protection. Progress in AI capabilities has been outpacing the ability of researchers to ensure AI is safe, and recent incidents and evaluations have shown that cyber, biological, and loss-of-control risks are real, near-term dangers. Yet, most of the conversations about steering the trajectory of transformative AI – how and if we should build it, who realises its gains and who suffers its risks, who gets to tax, control, and wield it and how – take place outside of Europe.
Europe has the resources to thrive and contribute to global flourishing in a world with transformative AI, but the window for utilising them is closing fast. Europe has a large market, several crucial assets in the AI supply chain, stable institutions, and strong technical talent. However, as we approach a world with transformative AI, these and other assets will, by default, likely lose relative value. For example, in AI development, the value of excellent talent will likely decrease as human labour is replaced with AI labour and as even stronger AI is increasingly built by AI itself (‘recursive self-improvement’) – a trend that has already begun.
This strategy offers a path for Europe to rise to the challenge of transformative AI. It contains recommendations for ensuring prosperity, sovereignty, and security, and it is centred on the premise that reliable access to frontier AI is crucial in a world with transformative AI. It is impossible to predict exactly the domains in which lacking access to frontier AI would impact Europe most, but likely candidates include defence, cybersecurity, and science, including AI research itself. To avoid falling behind in critical domains like these, Europe would need to either secure access to foreign frontier AI or develop competitive frontier AI domestically. This strategy covers both approaches, with a focus on the former because of the extremely high costs of a successful European frontier AI project.
Member States and the European Commission should pursue five ‘immediate objectives’ with highest urgency. Together, they would put Europe in a position of strength, contribute to a safer transition to transformative AI, and ensure that Europe’s institutions can deliver on both.
Create a Member State Alliance for Supply Chain Security. European countries host central chokepoints of the global AI supply chain but fail to capitalise on their strategic and economic potential. An Alliance of willing Member States could, in coordination with the European Commission, do so to the benefit of the whole Union.
Make European institutions ready to act in a world with transformative AI. Member States and the EU should bring frontier AI expertise and technology into their institutions so that they can keep pace with technological developments.
Secure Europe’s share of global AI compute, in a ‘European Way’ that benefits local communities. AI data centres on European soil enable durable access to a key strategic resource of the AI age, computing capacity, and ward off dependencies. Europe should make building them much easier and ensure that local communities benefit from them. It should aim for 15% of global AI compute capacity by 2030, up from around 5% now.
Ensure resilience to AI crises. Transformative AI would give rise to severe threats to public safety and could cause large-scale catastrophes. Among other measures, Europe should harden critical infrastructure, stockpile crisis resources, and build the capacity to withstand cyber, biological, and loss-of-control incidents enabled by AI.
Make Europe the global leader in AI assurance technology. Europe should become the innovation leader in AI hardware whose security and usage patterns can be proven. This could be a precondition for hosting frontier AI and for verifying adherence to any AI red lines, for example, in the context of future international agreements to pace AI development.
Create a Member State Alliance for Supply Chain Security. European countries host central chokepoints of the global AI supply chain but fail to capitalise on their strategic and economic potential. An Alliance of willing Member States could, in coordination with the European Commission, do so to the benefit of the whole Union.
Make European institutions ready to act in a world with transformative AI. Member States and the EU should bring frontier AI expertise and technology into their institutions so that they can keep pace with technological developments.
Secure Europe’s share of global AI compute, in a ‘European Way’ that benefits local communities. AI data centres on European soil enable durable access to a key strategic resource of the AI age, computing capacity, and ward off dependencies. Europe should make building them much easier and ensure that local communities benefit from them. It should aim for 15% of global AI compute capacity by 2030, up from around 5% now.
Ensure resilience to AI crises. Transformative AI would give rise to severe threats to public safety and could cause large-scale catastrophes. Among other measures, Europe should harden critical infrastructure, stockpile crisis resources, and build the capacity to withstand cyber, biological, and loss-of-control incidents enabled by AI.
Make Europe the global leader in AI assurance technology. Europe should become the innovation leader in AI hardware whose security and usage patterns can be proven. This could be a precondition for hosting frontier AI and for verifying adherence to any AI red lines, for example, in the context of future international agreements to pace AI development.
Member States and the European Commission should also pursue additional objectives across three pillars:
Member States and the European Commission should also pursue additional objectives across three pillars:
Securing access to frontier AI: Europe should use its technological and economic assets to negotiate guaranteed access to foreign frontier AI capabilities. It should protect these assets from foreign acquisition or deterioration in value.
Building economic strength: Europe needs to become a favourable place for fast-growing companies in order to become an indispensable part of the AI value chain. It can achieve this by accelerating long-needed reforms, building on existing strengths, and placing bets on promising new moonshots.
Ensuring safety and security: The European Commission should ensure that the enforcement of EU rules for mitigating the most extreme (or ‘systemic’) risks from the most advanced AI models is targeted, proportionate, insulated from political pressures, and prioritised based on assessments by relevant subject-matter experts in the AI Office. Member States should protect workers from labour market shocks.
Securing access to frontier AI: Europe should use its technological and economic assets to negotiate guaranteed access to foreign frontier AI capabilities. It should protect these assets from foreign acquisition or deterioration in value.
Building economic strength: Europe needs to become a favourable place for fast-growing companies in order to become an indispensable part of the AI value chain. It can achieve this by accelerating long-needed reforms, building on existing strengths, and placing bets on promising new moonshots.
Ensuring safety and security: The European Commission should ensure that the enforcement of EU rules for mitigating the most extreme (or ‘systemic’) risks from the most advanced AI models is targeted, proportionate, insulated from political pressures, and prioritised based on assessments by relevant subject-matter experts in the AI Office. Member States should protect workers from labour market shocks.
Supporting an attempt to build competitive European frontier AI would be extremely costly, desirable if done right, and harmful if not done right. In a near-term transformative AI scenario, truly catching up to the frontier – as opposed to ‘fast following’ the frontier – will become harder over time because leading companies increasingly use their own AI to build the next generation of AI faster. Actually reaching the frontier despite these dynamics would require Manhattan Project-scale expenditure and resolve and could not be achieved by private companies without massive state support. If Europe attempted to create a European frontier AI project but failed to mobilise the necessary resources, it would be in a particularly bad position: It would still lack domestic frontier AI, but it would have spent a lot of capital and attention on a failed bet.
Navigating transformative AI well will be a challenge for the whole world, and Europe has an important role to play in it. Some challenges arising from transformative AI exceed the capacity of any single country or continent. Creating resilience to AI-driven disruption is a worldwide challenge, and European solutions can contribute to making this transition less risky. Dealing with frontier AI risks might require international agreements on ‘pacing’ AI development, and Europe can help negotiate and verify such treaties.
With courage, Europe can thrive under transformative AI. It takes courage to acknowledge how dangerous the current situation is for Europe. And it takes courage to nonetheless set ambitious goals, overcome obstacles, and deliver on those goals. But none of this is impossible. From Galileo Galilei to Marie Curie to Jean Monnet, Europe’s history is full of courageous people who achieved extraordinary things. Europe’s leaders today have the opportunity of a lifetime to follow in the footsteps of these historical figures and lead Europe into the age of transformative AI intact, safe, and thriving.
Supporting an attempt to build competitive European frontier AI would be extremely costly, desirable if done right, and harmful if not done right. In a near-term transformative AI scenario, truly catching up to the frontier – as opposed to ‘fast following’ the frontier – will become harder over time because leading companies increasingly use their own AI to build the next generation of AI faster. Actually reaching the frontier despite these dynamics would require Manhattan Project-scale expenditure and resolve and could not be achieved by private companies without massive state support. If Europe attempted to create a European frontier AI project but failed to mobilise the necessary resources, it would be in a particularly bad position: It would still lack domestic frontier AI, but it would have spent a lot of capital and attention on a failed bet.
Navigating transformative AI well will be a challenge for the whole world, and Europe has an important role to play in it. Some challenges arising from transformative AI exceed the capacity of any single country or continent. Creating resilience to AI-driven disruption is a worldwide challenge, and European solutions can contribute to making this transition less risky. Dealing with frontier AI risks might require international agreements on ‘pacing’ AI development, and Europe can help negotiate and verify such treaties.
With courage, Europe can thrive under transformative AI. It takes courage to acknowledge how dangerous the current situation is for Europe. And it takes courage to nonetheless set ambitious goals, overcome obstacles, and deliver on those goals. But none of this is impossible. From Galileo Galilei to Marie Curie to Jean Monnet, Europe’s history is full of courageous people who achieved extraordinary things. Europe’s leaders today have the opportunity of a lifetime to follow in the footsteps of these historical figures and lead Europe into the age of transformative AI intact, safe, and thriving.
Introduction
Introduction
Europe lays claim to being the birthplace of the scientific method, modern astronomy, the industrial revolution, quantum mechanics, germ theory, and computer science. These discoveries and inventions have transformed the world and brought immense benefits to people around the world. But with the rise of AI, Europe has fallen off the frontier. Despite its illustrious history, it is at risk of playing a marginal role in shaping the most important technological development of our time.
AI is dramatically changing software engineering, mathematics, biochemistry, cybersecurity, robotics, personal relationships, warfare – and much, much more. And this is likely only the beginning. AI has progressed faster in the last five years than experts and markets expected, and as its capabilities are getting closer to being able to outperform humans on almost any task, ‘transformative AI’ may not be far off:
Transformative AI: AI systems that change the basic structures of society, including the economy, science, and geopolitics, at a materially faster pace than any technology in history has.
Transformative AI would change society in ways more dramatic than anything seen so far. And while it is uncertain how exactly transformative AI will develop, it is important to be clear about the kind and magnitude of societal changes it could bring: entirely AI-run companies or institutions, as knowledge work is displaced faster than in any previous transition; fully automated biolabs capable of compressing decades of medical progress into years, or of mass-manufacturing novel pandemic pathogens; unanticipated new inventions and technologies; cyberattacks by ordinary people that are more sophisticated than those by nation-states today; AI systems that become powerful independent actors beyond the control of governments; and unprecedented concentration of wealth and power in states and companies outside of Europe.
While nobody can anticipate precisely how transformative AI would change the world, and over what time horizons, it is clear that it would leave Europe unrecognisable from today's perspective, for better or worse. The closest analogy to the current period may be the industrial revolution, though this is an imperfect analogy, because the changes that transformative AI brings might be larger still and might unfold over years instead of generations. Indeed, the speed of progress is fast enough that over 1,300 employees of leading AI companies recently urged governments to facilitate an international effort to develop the technical and governance tools needed to deliberately pace capability improvement to give society time to adapt.
Given the current trajectories of AI development, and especially if transformative AI arrives soon, Europe is on a path to lose the ability to determine its sovereignty, security, and prosperity. Most of the conversations about steering the trajectory of transformative AI are held outside of Europe: how and if we should build it, who realises its gains and who suffers its risks, and who gets to tax, control, and wield it and how.
Unless Europe wakes up, it will not have meaningful control over how the most important technology for the future of humanity will affect its citizens. This concern follows from a series of contestable – but nevertheless very plausible – claims:
Europe lays claim to being the birthplace of the scientific method, modern astronomy, the industrial revolution, quantum mechanics, germ theory, and computer science. These discoveries and inventions have transformed the world and brought immense benefits to people around the world. But with the rise of AI, Europe has fallen off the frontier. Despite its illustrious history, it is at risk of playing a marginal role in shaping the most important technological development of our time.
AI is dramatically changing software engineering, mathematics, biochemistry, cybersecurity, robotics, personal relationships, warfare – and much, much more. And this is likely only the beginning. AI has progressed faster in the last five years than experts and markets expected, and as its capabilities are getting closer to being able to outperform humans on almost any task, ‘transformative AI’ may not be far off:
Transformative AI: AI systems that change the basic structures of society, including the economy, science, and geopolitics, at a materially faster pace than any technology in history has.
Transformative AI would change society in ways more dramatic than anything seen so far. And while it is uncertain how exactly transformative AI will develop, it is important to be clear about the kind and magnitude of societal changes it could bring: entirely AI-run companies or institutions, as knowledge work is displaced faster than in any previous transition; fully automated biolabs capable of compressing decades of medical progress into years, or of mass-manufacturing novel pandemic pathogens; unanticipated new inventions and technologies; cyberattacks by ordinary people that are more sophisticated than those by nation-states today; AI systems that become powerful independent actors beyond the control of governments; and unprecedented concentration of wealth and power in states and companies outside of Europe.
While nobody can anticipate precisely how transformative AI would change the world, and over what time horizons, it is clear that it would leave Europe unrecognisable from today's perspective, for better or worse. The closest analogy to the current period may be the industrial revolution, though this is an imperfect analogy, because the changes that transformative AI brings might be larger still and might unfold over years instead of generations. Indeed, the speed of progress is fast enough that over 1,300 employees of leading AI companies recently urged governments to facilitate an international effort to develop the technical and governance tools needed to deliberately pace capability improvement to give society time to adapt.
Given the current trajectories of AI development, and especially if transformative AI arrives soon, Europe is on a path to lose the ability to determine its sovereignty, security, and prosperity. Most of the conversations about steering the trajectory of transformative AI are held outside of Europe: how and if we should build it, who realises its gains and who suffers its risks, and who gets to tax, control, and wield it and how.
Unless Europe wakes up, it will not have meaningful control over how the most important technology for the future of humanity will affect its citizens. This concern follows from a series of contestable – but nevertheless very plausible – claims:
1.
That there is a significant possibility of transformative AI being developed in the next few years, plausibly within the mandate of the current European Commission and several Member State governments;
2.
that under transformative AI, access to frontier AI would become a crucial input to sovereignty, security, and prosperity;
3.
that Europe currently does not have reliable access to frontier AI: There is no European frontier AI company, and Europe’s leverage to ensure access to foreign frontier AI is limited and plausibly further decreasing; and as a result
4.
that Europe’s sovereignty, security, and prosperity, based on its current trajectory, will depend on the actions taken by foreign governments and companies.
1.
That there is a significant possibility of transformative AI being developed in the next few years, plausibly within the mandate of the current European Commission and several Member State governments;
2.
that under transformative AI, access to frontier AI would become a crucial input to sovereignty, security, and prosperity;
3.
that Europe currently does not have reliable access to frontier AI: There is no European frontier AI company, and Europe’s leverage to ensure access to foreign frontier AI is limited and plausibly further decreasing; and as a result
4.
that Europe’s sovereignty, security, and prosperity, based on its current trajectory, will depend on the actions taken by foreign governments and companies.
It follows that Europe urgently needs to deviate from its current path. Some might argue that Europe can perhaps defer its response until transformative AI arrives, when better information will be available. But such a wait-and-see approach is fundamentally mistaken – once transformative AI has arrived, it will be too late to start preparing. The best time to start preparing was years ago, but the second best time is today. Left to its current default trajectory, Europe risks permanent marginalisation in a world with transformative AI. Accordingly, over 100 experts convened by the European Commission’s AI Office this April indicated that AI could “radically transform” Europe, and “urged the Commission to put forward a strategy” with “foremost political priority”.
The current default need not be Europe’s destiny. Europe still has assets most regions envy: a deep talent pool, chokepoints in the chip supply chain on which every frontier AI model depends, one of the world’s largest markets, and longstanding alliances. Europe can change course and thrive in a world transformed by AI.
This strategy sets out how Europe could make use of its assets, suggesting two possible approaches: Aiming to secure access to foreign frontier AI systems by building and using leverage, and aiming to build frontier AI on EU soil. Both demand extraordinary political capital, and the political appeal of the frontier AI project approach is much stronger. But this political appeal could turn out to be a trap. A half-hearted European frontier AI project – where bold political statements are not backed up by the extraordinary resources and resolve required – would leave Europe poorer and empty-handed: still without its own frontier AI, and without reliable ways to access anyone else’s. A European frontier AI project is worth attempting wholeheartedly if and only if the conditions set out in the relevant section of this strategy are met. Those conditions are demanding, and therefore the objectives and recommendations that follow centre predominantly on how Europe can secure access to foreign frontier systems by building and using leverage. Under either approach, access to frontier AI is a prerequisite for reaping the enormous benefits transformative AI might bring about.
This strategy outlines how Europe can change course. Given the urgency, it first highlights the most important concrete policy objectives that should be pursued right now (‘Immediate objectives’), and then lays out in greater detail what else is necessary to prepare Europe for transformative AI (‘Additional objectives’). How Europe responds to the emergence of transformative AI may determine whether it remains a sovereign actor, or whether it enters a period of structural dependence in which even its leading economies decline toward middle-income status, serving as markets with little leverage over a technological order shaped in Silicon Valley and Beijing.
It follows that Europe urgently needs to deviate from its current path. Some might argue that Europe can perhaps defer its response until transformative AI arrives, when better information will be available. But such a wait-and-see approach is fundamentally mistaken – once transformative AI has arrived, it will be too late to start preparing. The best time to start preparing was years ago, but the second best time is today. Left to its current default trajectory, Europe risks permanent marginalisation in a world with transformative AI. Accordingly, over 100 experts convened by the European Commission’s AI Office this April indicated that AI could “radically transform” Europe, and “urged the Commission to put forward a strategy” with “foremost political priority”.
The current default need not be Europe’s destiny. Europe still has assets most regions envy: a deep talent pool, chokepoints in the chip supply chain on which every frontier AI model depends, one of the world’s largest markets, and longstanding alliances. Europe can change course and thrive in a world transformed by AI.
This strategy sets out how Europe could make use of its assets, suggesting two possible approaches: Aiming to secure access to foreign frontier AI systems by building and using leverage, and aiming to build frontier AI on EU soil. Both demand extraordinary political capital, and the political appeal of the frontier AI project approach is much stronger. But this political appeal could turn out to be a trap. A half-hearted European frontier AI project – where bold political statements are not backed up by the extraordinary resources and resolve required – would leave Europe poorer and empty-handed: still without its own frontier AI, and without reliable ways to access anyone else’s. A European frontier AI project is worth attempting wholeheartedly if and only if the conditions set out in the relevant section of this strategy are met. Those conditions are demanding, and therefore the objectives and recommendations that follow centre predominantly on how Europe can secure access to foreign frontier systems by building and using leverage. Under either approach, access to frontier AI is a prerequisite for reaping the enormous benefits transformative AI might bring about.
This strategy outlines how Europe can change course. Given the urgency, it first highlights the most important concrete policy objectives that should be pursued right now (‘Immediate objectives’), and then lays out in greater detail what else is necessary to prepare Europe for transformative AI (‘Additional objectives’). How Europe responds to the emergence of transformative AI may determine whether it remains a sovereign actor, or whether it enters a period of structural dependence in which even its leading economies decline toward middle-income status, serving as markets with little leverage over a technological order shaped in Silicon Valley and Beijing.
Why Europe needs to prepare for transformative AI
Why Europe needs to prepare for transformative AI
AI progress is extraordinarily rapid and may accelerate further
AI progress is extraordinarily rapid and may accelerate further
The recommendations in this strategy are intended for scenarios in which transformative AI arrives within the next few years. This section explains why that scenario is plausible, and why it warrants urgent preparation.
Much of what AI can do today sounded like science fiction just a few years ago. In 2019, the best publicly available language models could not reliably count to ten. In 2024, they struggled with basic programming tasks that took programmers 4 minutes. Two years later, they not only write sophisticated text and code, but solve decades-old open research problems in mathematics and computer science on their own, produce original video and music, and play an increasingly central role in modern warfare. The European Commission’s report on its Expert Forum on Frontier AI finds that “capabilities have advanced at a pace experts described as without precedent” and that frontier AI has “the potential to radically transform Europe’s economy, security and society”.
In mid-2026, rapid progress is leading to increasingly extreme incidents. In July 2026, hundreds of AI agents broke out of isolated internal environments at OpenAI and successfully hacked a major external company on their own initiative. These agents had coordinated extensively, exchanging advice and delegating work assignments through a hidden message board they built themselves, and which they rebuilt after OpenAI engineers tried to shut it down. Subsequently, they seized full administrative control of the OpenAI computer system they were running on. Similar unsanctioned AI behaviours were reported by Anthropic, Meta and the UK government’s AI Security Institute.
Progress will likely remain fast. In fact, by some key metrics, the pace at which AI models are improving has begun accelerating (Figure 1). New cyber capabilities have increased the number of vulnerabilities found in critical software of major companies by roughly 5x in the three months after Anthropic announced Claude Mythos Preview. AI systems are reportedly playing a central role in active military operations. Just as today’s capabilities looked like science fiction a few years ago, one can expect that AI capabilities a few years from now would seem like science fiction to us today.
The recommendations in this strategy are intended for scenarios in which transformative AI arrives within the next few years. This section explains why that scenario is plausible, and why it warrants urgent preparation.
Much of what AI can do today sounded like science fiction just a few years ago. In 2019, the best publicly available language models could not reliably count to ten. In 2024, they struggled with basic programming tasks that took programmers 4 minutes. Two years later, they not only write sophisticated text and code, but solve decades-old open research problems in mathematics and computer science on their own, produce original video and music, and play an increasingly central role in modern warfare. The European Commission’s report on its Expert Forum on Frontier AI finds that “capabilities have advanced at a pace experts described as without precedent” and that frontier AI has “the potential to radically transform Europe’s economy, security and society”.
In mid-2026, rapid progress is leading to increasingly extreme incidents. In July 2026, hundreds of AI agents broke out of isolated internal environments at OpenAI and successfully hacked a major external company on their own initiative. These agents had coordinated extensively, exchanging advice and delegating work assignments through a hidden message board they built themselves, and which they rebuilt after OpenAI engineers tried to shut it down. Subsequently, they seized full administrative control of the OpenAI computer system they were running on. Similar unsanctioned AI behaviours were reported by Anthropic, Meta and the UK government’s AI Security Institute.
Progress will likely remain fast. In fact, by some key metrics, the pace at which AI models are improving has begun accelerating (Figure 1). New cyber capabilities have increased the number of vulnerabilities found in critical software of major companies by roughly 5x in the three months after Anthropic announced Claude Mythos Preview. AI systems are reportedly playing a central role in active military operations. Just as today’s capabilities looked like science fiction a few years ago, one can expect that AI capabilities a few years from now would seem like science fiction to us today.
Figure 01
Scores on the Epoch Capabilities Index. The Epoch Capabilities Index (ECI) combines many different AI benchmarks scores into one measure of general capability. Based on ECI scores, model capabilities have been improving nearly twice as fast since April 2024 than before. In a follow-up analysis in April 2026, Epoch found that three out of four capability metrics they tested showed acceleration (ECI, METR 50% Time Horizon, Combined Math Index, but not WeirdML Index); this appeared to be driven by reasoning models. The figure reproduces the graphic and data from analysis by Epoch AI.
Figure 01
Scores on the Epoch Capabilities Index. The Epoch Capabilities Index (ECI) combines many different AI benchmarks scores into one measure of general capability. Based on ECI scores, model capabilities have been improving nearly twice as fast since April 2024 than before. In a follow-up analysis in April 2026, Epoch found that three out of four capability metrics they tested showed acceleration (ECI, METR 50% Time Horizon, Combined Math Index, but not WeirdML Index); this appeared to be driven by reasoning models. The figure reproduces the graphic and data from analysis by Epoch AI.
The pace of progress may accelerate even further, especially if AI continues to accelerate AI research and development itself. Anthropic, Google, and OpenAI report that AI now writes most of their code. Over a thousand frontier lab employees jointly stated that “the world’s leading AI companies believe they could be close to automating AI research”. This is striking: AI models were barely able to write a coherent line of code four years ago, but they can now solve increasingly complex and open-ended tasks on behalf of AI researchers (see Figure 2). This suggests that progress in the next five years may be much more rapid than what we have seen up until now. If AI can create and improve AI by itself and without human involvement – also known as ‘recursive self-improvement’ – then progress could accelerate in ways that are hard to imagine from today’s vantage point, with years of technological progress taking place in months or weeks.
The pace of progress may accelerate even further, especially if AI continues to accelerate AI research and development itself. Anthropic, Google, and OpenAI report that AI now writes most of their code. Over a thousand frontier lab employees jointly stated that “the world’s leading AI companies believe they could be close to automating AI research”. This is striking: AI models were barely able to write a coherent line of code four years ago, but they can now solve increasingly complex and open-ended tasks on behalf of AI researchers (see Figure 2). This suggests that progress in the next five years may be much more rapid than what we have seen up until now. If AI can create and improve AI by itself and without human involvement – also known as ‘recursive self-improvement’ – then progress could accelerate in ways that are hard to imagine from today’s vantage point, with years of technological progress taking place in months or weeks.
Figure 02
Success rates of coding agents at various tasks in a frontier AI company. Over time, coding agents such as Claude Code have become better at performing software engineering tasks within an AI company, including open-ended tasks where the human engineer does not yet know what the correct solutions will look like. Source: Anthropic.
Figure 02
Success rates of coding agents at various tasks in a frontier AI company. Over time, coding agents such as Claude Code have become better at performing software engineering tasks within an AI company, including open-ended tasks where the human engineer does not yet know what the correct solutions will look like. Source: Anthropic.
Near-term transformative AI is plausible given current trends
Near-term transformative AI is plausible given current trends
Uncertainty remains about how much capabilities will improve, and how widely AI will be adopted. There are identifiable ways in which advances might fail to maintain their recent pace. Much of the capability progress of the past two years has come from reinforcement learning on tasks with verifiable outcomes, where models can be trained against millions of checkable attempts. It is an open question how well these gains will generalise to domains where success is harder to verify. AI capability growth is also ‘jagged’: models reach superhuman performance on some tasks while unexpectedly lagging on others. There are also additional obstacles to broad and rapid adoption across the economy. Models remain imperfectly reliable, and firms cite legal uncertainty, data protection and security concerns, high implementation costs, and scarce talent as barriers to deploying models at scale. The labour-market evidence so far shows early, concentrated effects rather than economy-wide effects on employment.
Nonetheless, many experts see extreme capability growth and societal transformation as sufficiently likely to call for serious preparation. These potential barriers are not seen as significant blockers by the experts most knowledgeable about frontier AI systems. In July 2026, around 200 economists, including 16 Nobel Prize winners, signed a statement warning that “radically more powerful AI” could arrive in the coming decade, leading to an “unprecedented transformation of our economy” and “large-scale job displacement”. The statement from frontier AI company employees released that same month stated that there is a “real risk that capability development rapidly accelerates beyond our ability to understand or control the resulting systems”.
The leading AI companies are exceeding their own projections and betting on continued progress. Revenue has outgrown the AI companies' own forecasts. OpenAI projected 2.3x growth for 2026, which was unprecedented for a company at its scale. Yet it only took OpenAI the first eight months of the year to roughly double its annualised run rate, from over $20 billion to more than $40 billion. Similarly, Anthropic projected 4x growth in its most optimistic scenario for 2026, but had already grown by 5.2x by May 2026. AI capex in 2026 is projected to be around €650 billion and growing by more than 70% annually. The scale of these bets shows that the companies with the most detailed, proprietary view of the technology's trajectory also expect it to transform the economy.
The societal changes coming with transformative AI would leave the world hard to recognise from today's vantage point. It could result in changes overall greater in scale than electrification, widespread vaccination, and the advent of nuclear weapons, over the course of years instead of generations. Concretely, this could include:
Uncertainty remains about how much capabilities will improve, and how widely AI will be adopted. There are identifiable ways in which advances might fail to maintain their recent pace. Much of the capability progress of the past two years has come from reinforcement learning on tasks with verifiable outcomes, where models can be trained against millions of checkable attempts. It is an open question how well these gains will generalise to domains where success is harder to verify. AI capability growth is also ‘jagged’: models reach superhuman performance on some tasks while unexpectedly lagging on others. There are also additional obstacles to broad and rapid adoption across the economy. Models remain imperfectly reliable, and firms cite legal uncertainty, data protection and security concerns, high implementation costs, and scarce talent as barriers to deploying models at scale. The labour-market evidence so far shows early, concentrated effects rather than economy-wide effects on employment.
Nonetheless, many experts see extreme capability growth and societal transformation as sufficiently likely to call for serious preparation. These potential barriers are not seen as significant blockers by the experts most knowledgeable about frontier AI systems. In July 2026, around 200 economists, including 16 Nobel Prize winners, signed a statement warning that “radically more powerful AI” could arrive in the coming decade, leading to an “unprecedented transformation of our economy” and “large-scale job displacement”. The statement from frontier AI company employees released that same month stated that there is a “real risk that capability development rapidly accelerates beyond our ability to understand or control the resulting systems”.
The leading AI companies are exceeding their own projections and betting on continued progress. Revenue has outgrown the AI companies' own forecasts. OpenAI projected 2.3x growth for 2026, which was unprecedented for a company at its scale. Yet it only took OpenAI the first eight months of the year to roughly double its annualised run rate, from over $20 billion to more than $40 billion. Similarly, Anthropic projected 4x growth in its most optimistic scenario for 2026, but had already grown by 5.2x by May 2026. AI capex in 2026 is projected to be around €650 billion and growing by more than 70% annually. The scale of these bets shows that the companies with the most detailed, proprietary view of the technology's trajectory also expect it to transform the economy.
The societal changes coming with transformative AI would leave the world hard to recognise from today's vantage point. It could result in changes overall greater in scale than electrification, widespread vaccination, and the advent of nuclear weapons, over the course of years instead of generations. Concretely, this could include:
Vastly higher pace of scientific and technological progress. Frontier models can solve major open problems across scientific domains, leading to rapid advances in materials science and biotechnology and drastically accelerating AI development itself. AI-enabled breakthroughs on technologies such as nuclear fusion rapidly bring abundant clean energy. Radically new medical treatments and drugs are produced at unprecedented speed. New pandemic-level pathogens can be designed by lay people.
Concentration of geopolitical power. Access to frontier AI capabilities is the largest determinant of military power, providing overwhelming battlefield advantages or removing nuclear second-strike capability. Governments or companies with access to powerful AI can steal classified information from other governments that lack access to frontier cyberdefensive capabilities, or can sabotage another country’s internet and electricity grid. AI surveillance and monitoring increases states’ ability to maintain control over populations, and AI is also a powerful tool for shaping public opinion. Countries with control of the frontier dictate who has this access and on what terms.
Economic phase shifts. Global economic growth rises above historical peaks, but formerly high-income countries without access to frontier AI systems are relegated to low- and middle-income levels. Many citizens have unrecognisably transformed jobs or no work at all. Many factories are repurposed to produce advanced robots, leading to an industrial explosion, where robots are used to build more robots and factories. A single country or several companies with privileged access to frontier models can dominate the global economy.
Vastly higher pace of scientific and technological progress. Frontier models can solve major open problems across scientific domains, leading to rapid advances in materials science and biotechnology and drastically accelerating AI development itself. AI-enabled breakthroughs on technologies such as nuclear fusion rapidly bring abundant clean energy. Radically new medical treatments and drugs are produced at unprecedented speed. New pandemic-level pathogens can be designed by lay people.
Concentration of geopolitical power. Access to frontier AI capabilities is the largest determinant of military power, providing overwhelming battlefield advantages or removing nuclear second-strike capability. Governments or companies with access to powerful AI can steal classified information from other governments that lack access to frontier cyberdefensive capabilities, or can sabotage another country’s internet and electricity grid. AI surveillance and monitoring increases states’ ability to maintain control over populations, and AI is also a powerful tool for shaping public opinion. Countries with control of the frontier dictate who has this access and on what terms.
Economic phase shifts. Global economic growth rises above historical peaks, but formerly high-income countries without access to frontier AI systems are relegated to low- and middle-income levels. Many citizens have unrecognisably transformed jobs or no work at all. Many factories are repurposed to produce advanced robots, leading to an industrial explosion, where robots are used to build more robots and factories. A single country or several companies with privileged access to frontier models can dominate the global economy.
If AI progress continues towards transformative AI, it will pose several large-scale risks, including irreversible loss of control. According to the International AI Safety Report, plausible risks include AI-enabled biological or chemical attacks, the erosion of human autonomy, and loss of control scenarios “where AI systems operate outside of anyone’s control, with no clear path to regaining control”. There is already increasing evidence of instances in which misaligned AI agents work together to evade human oversight and pursue goals that conflict with the intentions of human users. One example of this is the aforementioned incident, in which AI agents developed by OpenAI coordinated through a hidden message board and eventually hacked the servers of Hugging Face, a multi-billion dollar AI company, with agents working together to conceal evidence from the systems that were supposed to monitor them. More capable systems will not by default be more aligned to human interests, and the more capable systems become, the harder concealed actions will be to detect and the more consequential the results of such actions will become. It was in response to these recent incidents that employees of frontier AI companies, in their aforementioned statement, wrote that “there is a real risk that capability development rapidly accelerates beyond our ability to understand or control the resulting systems”, requesting government intervention to facilitate “an international effort to develop the technical and governance tools needed to deliberately pace the frontier of automated AI development”.
Continuing AI progress could also lead to extreme power concentration in a small number of governments or companies. Highly capable AI systems could confer decisive economic or military advantages on those who control these systems, potentially allowing a few actors to gain outsized political power. For example, AI-enabled coups or pervasive AI-enabled surveillance could conceivably concentrate power within a small group of people with little or no democratic legitimacy. Moreover, Europe currently cannot verify that foreign AI models are free of hidden backdoors or ‘secret loyalties’ that could help foreign actors in an attempt to seize power over European institutions or companies.
If AI progress continues towards transformative AI, it will pose several large-scale risks, including irreversible loss of control. According to the International AI Safety Report, plausible risks include AI-enabled biological or chemical attacks, the erosion of human autonomy, and loss of control scenarios “where AI systems operate outside of anyone’s control, with no clear path to regaining control”. There is already increasing evidence of instances in which misaligned AI agents work together to evade human oversight and pursue goals that conflict with the intentions of human users. One example of this is the aforementioned incident, in which AI agents developed by OpenAI coordinated through a hidden message board and eventually hacked the servers of Hugging Face, a multi-billion dollar AI company, with agents working together to conceal evidence from the systems that were supposed to monitor them. More capable systems will not by default be more aligned to human interests, and the more capable systems become, the harder concealed actions will be to detect and the more consequential the results of such actions will become. It was in response to these recent incidents that employees of frontier AI companies, in their aforementioned statement, wrote that “there is a real risk that capability development rapidly accelerates beyond our ability to understand or control the resulting systems”, requesting government intervention to facilitate “an international effort to develop the technical and governance tools needed to deliberately pace the frontier of automated AI development”.
Continuing AI progress could also lead to extreme power concentration in a small number of governments or companies. Highly capable AI systems could confer decisive economic or military advantages on those who control these systems, potentially allowing a few actors to gain outsized political power. For example, AI-enabled coups or pervasive AI-enabled surveillance could conceivably concentrate power within a small group of people with little or no democratic legitimacy. Moreover, Europe currently cannot verify that foreign AI models are free of hidden backdoors or ‘secret loyalties’ that could help foreign actors in an attempt to seize power over European institutions or companies.
Europe risks marginalisation in a world with transformative AI
Europe risks marginalisation in a world with transformative AI
Europe lacks the companies, compute, models, and investment needed to prevail in a world with transformative AI. None of the world’s ten most valuable AI companies are European. The annualised revenue run rate of European model developers is likely less than 2% of the combined run rate of their two leading international competitors OpenAI and Anthropic, whose combined revenue has grown roughly 25-fold in two years – from $4 billion to over $100 billion. The EU only hosts around 5% of global AI compute, compared to 75% in the US and 15% in China.¹ By the end of 2026, a single data centre site in Malaysia will reach roughly one third of the AI compute capacity of Europe, including the UK and Norway. Two data centres in the US will together exceed Europe’s total capacity.² In 2025, all of Europe combined received just 5–6% of global private AI investment.
In addition, access to frontier AI is not a given for European customers. Recent events have shown that Europe should not count on reliable access to frontier AI in a transformative AI scenario. For example, Anthropic initially shared its Mythos model only with selected US partners, and the Chinese government reportedly plans similar restrictions. Profitability constraints alone are unlikely to change this new default: A global scarcity of AI compute means that the profitability of US or Chinese AI companies may not depend on serving frontier models to European customers. These companies might accordingly prioritise, or be required by their governments to prioritise, domestic customers when allocating a scarce supply of frontier AI – especially as governments increasingly view frontier AI access through the lens of security rather than economic policy.
Access to frontier AI is already proving increasingly crucial in security-relevant domains. In 2026, frontier models have shown remarkable capability improvements to identify and exploit cyber vulnerabilities, both in safety evaluations and in the real world. If foreign criminals or state-level attackers have access to frontier capabilities, while European institutions and companies can only use sub-frontier AI to defend themselves, this creates a dangerous asymmetry where Europe lacks access to the best cybersecurity tools. While outside the scope of this strategy, the military use of AI – and the strategic advantages it could confer – raise similar concerns, for example related to the use of frontier AI for autonomous decision-making.
In addition, in a world with transformative AI, economic competitiveness will likely also depend on access to frontier AI. The market already pays roughly 100 times more for access to US frontier models than to the European fast follower. Frontier AI access is rapidly becoming more crucial for a wide range of tasks, including some of the most economically valuable work. This includes, centrally, cognitive tasks with high returns on intelligence: tasks where better judgement produces better outcomes, without a natural ceiling at which additional capability stops adding value. For such tasks, companies currently pay the largest premium for the best human talent, because the difference between adequate and excellent performance translates directly into value. Tasks with high returns on intelligence exist across the economy, including in health care, software development, hardware design, legal work, finance, management, automated manufacturing, logistics, and education. One example is AI research and development (R&D) itself, where access to frontier AI has already become a key driver of progress in AI companies – either by using a company’s own frontier models, or by illicitly distilling the frontier models of competitors. This will plausibly extend to other economic sectors, as AI is increasingly used to solve fuzzy and open-ended R&D tasks that benefit from the most intelligent model available. In drug discovery or materials science, for example, frontier AI may help a company identify candidate compounds faster than competitors, potentially kicking off a positive feedback loop: a company with frontier AI access can generate more experimental data and develop better predictive models, allowing it to iterate faster towards the next product generation. Beyond R&D, many tasks in areas such as manufacturing or logistics will plausibly benefit from frontier AI, because they involve complex reasoning and strategic planning. Even for more routine, well-scoped work, where basic AI systems are sufficient, these systems are increasingly built using frontier AI that writes their code, tests them, and collects or creates the training data. Even if frontier AI may not be required for every task, no company might therefore be competitive if it has no access to frontier AI at all.
Frontier AI access could be particularly important in robotics. Frontier AI models increasingly provide the perception, language understanding, and reasoning that allow robots to handle a wide variety of tasks, beyond the standardised, high-volume tasks to which industrial robots are confined (see Robotics deep dive). European robotics companies without reliable frontier AI access would have to build on top of less capable systems, again risking a compounding gap: deploying more capable robots can generate the real-world interaction data needed to improve the next generation of robotics models. Moreover, frontier AI could dramatically accelerate robotics research itself. This matters because sufficiently capable and versatile robots, with their potential to automate a wide range of physical tasks, present an outsized economic opportunity in a world with transformative AI.
Absent decisive and immediate action, Europe therefore risks drastic disruption to its competitiveness, sovereignty, and security in scenarios with near-term transformative AI. Without a deviation from the current trajectory, Europe would likely fail to capture the economic gains from transformative AI while nonetheless facing the considerable risks it brings. European workers will be vulnerable to AI-driven labour displacement even if Europe has no leading AI companies. European companies without frontier AI access could see their business models hollowed out by foreign competitors, and will be vulnerable to AI-enabled cyberattacks with no guarantee of access to equivalent defences – Europe has already been cut off, repeatedly and without warning, from cyber-related frontier AI capabilities this year. And European governments may likewise face state and non-state actors with superior AI-enabled cyber and military capabilities.
Europe must, and can, act now to change course. It takes years to build data centres, frontier models, crisis plans, and ambitious, coordinated policies. But it is not yet too late for Europe to prepare for a future with transformative AI. As this strategy outlines, there are a number of steps that Europe’s leaders should take immediately to ensure Europe has a stake in the frontier: steps that maintain and use the considerable leverage it has and that increase resilience to the risks it will face. Many of these are ‘no regret’ actions that will be beneficial for a range of possible futures. The alternative ‘wait and see’ approach risks setting Europe on an irreversible trajectory towards dependence on foreign companies and countries.
Europe lacks the companies, compute, models, and investment needed to prevail in a world with transformative AI. None of the world’s ten most valuable AI companies are European. The annualised revenue run rate of European model developers is likely less than 2% of the combined run rate of their two leading international competitors OpenAI and Anthropic, whose combined revenue has grown roughly 25-fold in two years – from $4 billion to over $100 billion. The EU only hosts around 5% of global AI compute, compared to 75% in the US and 15% in China.¹ By the end of 2026, a single data centre site in Malaysia will reach roughly one third of the AI compute capacity of Europe, including the UK and Norway. Two data centres in the US will together exceed Europe’s total capacity.² In 2025, all of Europe combined received just 5–6% of global private AI investment.
In addition, access to frontier AI is not a given for European customers. Recent events have shown that Europe should not count on reliable access to frontier AI in a transformative AI scenario. For example, Anthropic initially shared its Mythos model only with selected US partners, and the Chinese government reportedly plans similar restrictions. Profitability constraints alone are unlikely to change this new default: A global scarcity of AI compute means that the profitability of US or Chinese AI companies may not depend on serving frontier models to European customers. These companies might accordingly prioritise, or be required by their governments to prioritise, domestic customers when allocating a scarce supply of frontier AI – especially as governments increasingly view frontier AI access through the lens of security rather than economic policy.
Access to frontier AI is already proving increasingly crucial in security-relevant domains. In 2026, frontier models have shown remarkable capability improvements to identify and exploit cyber vulnerabilities, both in safety evaluations and in the real world. If foreign criminals or state-level attackers have access to frontier capabilities, while European institutions and companies can only use sub-frontier AI to defend themselves, this creates a dangerous asymmetry where Europe lacks access to the best cybersecurity tools. While outside the scope of this strategy, the military use of AI – and the strategic advantages it could confer – raise similar concerns, for example related to the use of frontier AI for autonomous decision-making.
In addition, in a world with transformative AI, economic competitiveness will likely also depend on access to frontier AI. The market already pays roughly 100 times more for access to US frontier models than to the European fast follower. Frontier AI access is rapidly becoming more crucial for a wide range of tasks, including some of the most economically valuable work. This includes, centrally, cognitive tasks with high returns on intelligence: tasks where better judgement produces better outcomes, without a natural ceiling at which additional capability stops adding value. For such tasks, companies currently pay the largest premium for the best human talent, because the difference between adequate and excellent performance translates directly into value. Tasks with high returns on intelligence exist across the economy, including in health care, software development, hardware design, legal work, finance, management, automated manufacturing, logistics, and education. One example is AI research and development (R&D) itself, where access to frontier AI has already become a key driver of progress in AI companies – either by using a company’s own frontier models, or by illicitly distilling the frontier models of competitors. This will plausibly extend to other economic sectors, as AI is increasingly used to solve fuzzy and open-ended R&D tasks that benefit from the most intelligent model available. In drug discovery or materials science, for example, frontier AI may help a company identify candidate compounds faster than competitors, potentially kicking off a positive feedback loop: a company with frontier AI access can generate more experimental data and develop better predictive models, allowing it to iterate faster towards the next product generation. Beyond R&D, many tasks in areas such as manufacturing or logistics will plausibly benefit from frontier AI, because they involve complex reasoning and strategic planning. Even for more routine, well-scoped work, where basic AI systems are sufficient, these systems are increasingly built using frontier AI that writes their code, tests them, and collects or creates the training data. Even if frontier AI may not be required for every task, no company might therefore be competitive if it has no access to frontier AI at all.
Frontier AI access could be particularly important in robotics. Frontier AI models increasingly provide the perception, language understanding, and reasoning that allow robots to handle a wide variety of tasks, beyond the standardised, high-volume tasks to which industrial robots are confined (see Robotics deep dive). European robotics companies without reliable frontier AI access would have to build on top of less capable systems, again risking a compounding gap: deploying more capable robots can generate the real-world interaction data needed to improve the next generation of robotics models. Moreover, frontier AI could dramatically accelerate robotics research itself. This matters because sufficiently capable and versatile robots, with their potential to automate a wide range of physical tasks, present an outsized economic opportunity in a world with transformative AI.
Absent decisive and immediate action, Europe therefore risks drastic disruption to its competitiveness, sovereignty, and security in scenarios with near-term transformative AI. Without a deviation from the current trajectory, Europe would likely fail to capture the economic gains from transformative AI while nonetheless facing the considerable risks it brings. European workers will be vulnerable to AI-driven labour displacement even if Europe has no leading AI companies. European companies without frontier AI access could see their business models hollowed out by foreign competitors, and will be vulnerable to AI-enabled cyberattacks with no guarantee of access to equivalent defences – Europe has already been cut off, repeatedly and without warning, from cyber-related frontier AI capabilities this year. And European governments may likewise face state and non-state actors with superior AI-enabled cyber and military capabilities.
Europe must, and can, act now to change course. It takes years to build data centres, frontier models, crisis plans, and ambitious, coordinated policies. But it is not yet too late for Europe to prepare for a future with transformative AI. As this strategy outlines, there are a number of steps that Europe’s leaders should take immediately to ensure Europe has a stake in the frontier: steps that maintain and use the considerable leverage it has and that increase resilience to the risks it will face. Many of these are ‘no regret’ actions that will be beneficial for a range of possible futures. The alternative ‘wait and see’ approach risks setting Europe on an irreversible trajectory towards dependence on foreign companies and countries.
Footnotes
“Compute” is a shorthand for “computational resources” and refers to the specialised AI chips and data centre infrastructure used to train and deploy AI models.
“Compute” is a shorthand for “computational resources” and refers to the specialised AI chips and data centre infrastructure used to train and deploy AI models.
Immediate objectives
Immediate objectives
This section presents the five objectives that have emerged, during the research and drafting process of this strategy, as being particularly time-sensitive for ensuring that Europe can thrive in a near-term transformative AI scenario.
This section presents the five objectives that have emerged, during the research and drafting process of this strategy, as being particularly time-sensitive for ensuring that Europe can thrive in a near-term transformative AI scenario.
IO-1
Build a Member State Alliance for Supply Chain Security
IO-1
Build a Member State Alliance for Supply Chain Security
Europe holds various assets that will be important in a world with transformative AI, including ones in the AI chip supply chain. However, it has so far failed to translate these assets into meaningful leverage to ensure access to frontier AI. To do this, Europe needs to build an Alliance of Member States and allies.
Europe holds various assets that will be important in a world with transformative AI, including ones in the AI chip supply chain. However, it has so far failed to translate these assets into meaningful leverage to ensure access to frontier AI. To do this, Europe needs to build an Alliance of Member States and allies.
The challenge
The challenge
Europe’s dependence on foreign models and chips is a geopolitical and economic vulnerability. At the moment, Europe lacks privileged access to frontier AI models. This could have high societal and economic costs, and leave Europe vulnerable to severe risks and with a weakened ability to protect against them. For example, in April 2026, Anthropic shared its most capable model with only selected partners under Project Glasswing, to allow them to test and prepare their defences against AI-enabled cyberattacks. European institutions and companies were not among the first to receive access: the EU Agency for Cybersecurity (ENISA) reportedly only got invited to access the model after sustained negotiations (and has not received access to newer versions yet). A few months later, in June 2026, the US government issued an export control directive that restricted access to Anthropic’s most capable models for foreign nationals, in practice forcing Anthropic to disable these models for all customers. While this instance was not in itself adversarial, in the future, actors could withhold frontier AI access coercively from Europe. Europe’s companies also do not currently get preferential access to the chips built with European equipment, nor can all Member States rely on being treated preferentially in chip deals or restrictions.
Member States do not strategically use their leverage. Member States host various assets that the entire Western AI stack depends on, including world-leading chipmaking equipment (e.g. ASML’s extreme ultraviolet lithography (EUV) machines), critical suppliers of specialised inputs (e.g. Zeiss for optics and Trumpf for lasers), and proprietary datasets (e.g. in manufacturing and healthcare). Since these assets sit in private companies, the EU and its Member States cannot directly control their use. They do hold various indirect powers – such as export controls, investment screening or Union countermeasures under the Anti-Coercion Instrument (ACI) – that can be used to turn valuable assets into concrete leverage, for example in negotiations over access to frontier AI models and chips. However, at the moment, Member States do not use this power strategically to gain such access.
Member States are not sufficiently coordinated. Each Member State alone will likely not be able to use their individual leverage to negotiate effectively on access terms or to withstand coercive actions – their individual positions are simply not strong enough compared to the US and China. However, they would likely have considerable leverage collectively. Unfortunately, there is currently insufficient coordination around the strategic use of these key assets.
Europe’s dependence on foreign models and chips is a geopolitical and economic vulnerability. At the moment, Europe lacks privileged access to frontier AI models. This could have high societal and economic costs, and leave Europe vulnerable to severe risks and with a weakened ability to protect against them. For example, in April 2026, Anthropic shared its most capable model with only selected partners under Project Glasswing, to allow them to test and prepare their defences against AI-enabled cyberattacks. European institutions and companies were not among the first to receive access: the EU Agency for Cybersecurity (ENISA) reportedly only got invited to access the model after sustained negotiations (and has not received access to newer versions yet). A few months later, in June 2026, the US government issued an export control directive that restricted access to Anthropic’s most capable models for foreign nationals, in practice forcing Anthropic to disable these models for all customers. While this instance was not in itself adversarial, in the future, actors could withhold frontier AI access coercively from Europe. Europe’s companies also do not currently get preferential access to the chips built with European equipment, nor can all Member States rely on being treated preferentially in chip deals or restrictions.
Member States do not strategically use their leverage. Member States host various assets that the entire Western AI stack depends on, including world-leading chipmaking equipment (e.g. ASML’s extreme ultraviolet lithography (EUV) machines), critical suppliers of specialised inputs (e.g. Zeiss for optics and Trumpf for lasers), and proprietary datasets (e.g. in manufacturing and healthcare). Since these assets sit in private companies, the EU and its Member States cannot directly control their use. They do hold various indirect powers – such as export controls, investment screening or Union countermeasures under the Anti-Coercion Instrument (ACI) – that can be used to turn valuable assets into concrete leverage, for example in negotiations over access to frontier AI models and chips. However, at the moment, Member States do not use this power strategically to gain such access.
Member States are not sufficiently coordinated. Each Member State alone will likely not be able to use their individual leverage to negotiate effectively on access terms or to withstand coercive actions – their individual positions are simply not strong enough compared to the US and China. However, they would likely have considerable leverage collectively. Unfortunately, there is currently insufficient coordination around the strategic use of these key assets.
Addressing the challenge
Addressing the challenge
Willing Member States should form an Alliance for Supply Chain Security that helps them secure access to frontier AI models and computing capacity against outright coercion. Minimally, this likely should include the Netherlands, Germany, and France. In addition, Alliance members should invite trusted non-EU nations into the Alliance, especially so-called ‘middle powers’ facing similar access constraints. Membership should involve contributing important AI assets (e.g. frontier AI talent and expertise, data, compute and attractive locations for future build-outs, semiconductor production capabilities), fiscal contributions, or commitments to political actions. The purpose of the Alliance should be clearly scoped to safeguarding against economic coercion, where foreign actors would restrict or condition access to frontier AI models or computing capacity to extract political or economic concessions from Europe. If set up in this way, the Alliance would likely increase its members’ negotiating position regarding access to frontier AI models and computing capacity.
The Alliance’s strategic position depends on its supply chain assets. Once formed, the Alliance should clarify its negotiating position with regards to access, export controls, procurement, and EU-level trade deals. To this end, it will have to develop a joint understanding of both its existing leverage and the supply chain risks it faces: (a) where the Alliance’s AI supply chain is strongest and weakest (e.g. if no ready substitutes exist for a certain position in the AI supply chain, an upstream supplier could withhold an input and there would be no alternatives), (b) the nature of these assets (e.g. the speed at which restrictions can be enacted, how long restrictions would last, how restrictions interact), and (c) how transformative AI could affect their strategic importance or irreplaceability.
The Alliance will face a number of challenges it must proactively plan for. Member States and Alliance members could face many difficulties in forming and leveraging the Alliance. For example, they will need to be prepared to work together in domains that have historically been at the discretion of individual countries, requiring both confidentiality agreements and agreed upon processes for decision-making and burden-sharing. Moreover, the EU has limited options for rapidly imposing trade restrictions in response to economic coercion. While the ACI is in theory built for this purpose, it is currently too slow and unwieldy to deploy in a fast-moving crisis. Moreover, since common commercial policy is an exclusive EU competence, Member States could not independently impose trade-based countermeasures. The Alliance could mitigate these factors by considering ways in which its members could pre-commit to and fast-track deployment of the ACI. Finally, it is important that the Alliance actively avoids foreseeable failure modes and risks. To that end, the Alliance should not take an adversarial stance towards countries outside the Alliance; it should avoid actions that undermine or that could be seen to restrict free trade or international law; it should not attempt to interfere with foreign domestic regulation of AI development; and it should only use anti-coercive actions in response to genuine attempts at coercion. To proactively produce incentives to share frontier models and chips with Europe, no leverage mechanisms should be employed. To that end, Europe should rather lean on the mechanisms described in Immediate Objective 3 and Pillar 1.
Seven concrete recommendations at the Union and national level that can help Europe achieve the immediate objective of forming a Member State Alliance for Supply Chain Security can be found below. Detailed recommendations for each are provided in Part B of this strategy.
Willing Member States should form an Alliance for Supply Chain Security that helps them secure access to frontier AI models and computing capacity against outright coercion. Minimally, this likely should include the Netherlands, Germany, and France. In addition, Alliance members should invite trusted non-EU nations into the Alliance, especially so-called ‘middle powers’ facing similar access constraints. Membership should involve contributing important AI assets (e.g. frontier AI talent and expertise, data, compute and attractive locations for future build-outs, semiconductor production capabilities), fiscal contributions, or commitments to political actions. The purpose of the Alliance should be clearly scoped to safeguarding against economic coercion, where foreign actors would restrict or condition access to frontier AI models or computing capacity to extract political or economic concessions from Europe. If set up in this way, the Alliance would likely increase its members’ negotiating position regarding access to frontier AI models and computing capacity.
The Alliance’s strategic position depends on its supply chain assets. Once formed, the Alliance should clarify its negotiating position with regards to access, export controls, procurement, and EU-level trade deals. To this end, it will have to develop a joint understanding of both its existing leverage and the supply chain risks it faces: (a) where the Alliance’s AI supply chain is strongest and weakest (e.g. if no ready substitutes exist for a certain position in the AI supply chain, an upstream supplier could withhold an input and there would be no alternatives), (b) the nature of these assets (e.g. the speed at which restrictions can be enacted, how long restrictions would last, how restrictions interact), and (c) how transformative AI could affect their strategic importance or irreplaceability.
The Alliance will face a number of challenges it must proactively plan for. Member States and Alliance members could face many difficulties in forming and leveraging the Alliance. For example, they will need to be prepared to work together in domains that have historically been at the discretion of individual countries, requiring both confidentiality agreements and agreed upon processes for decision-making and burden-sharing. Moreover, the EU has limited options for rapidly imposing trade restrictions in response to economic coercion. While the ACI is in theory built for this purpose, it is currently too slow and unwieldy to deploy in a fast-moving crisis. Moreover, since common commercial policy is an exclusive EU competence, Member States could not independently impose trade-based countermeasures. The Alliance could mitigate these factors by considering ways in which its members could pre-commit to and fast-track deployment of the ACI. Finally, it is important that the Alliance actively avoids foreseeable failure modes and risks. To that end, the Alliance should not take an adversarial stance towards countries outside the Alliance; it should avoid actions that undermine or that could be seen to restrict free trade or international law; it should not attempt to interfere with foreign domestic regulation of AI development; and it should only use anti-coercive actions in response to genuine attempts at coercion. To proactively produce incentives to share frontier models and chips with Europe, no leverage mechanisms should be employed. To that end, Europe should rather lean on the mechanisms described in Immediate Objective 3 and Pillar 1.
Seven concrete recommendations at the Union and national level that can help Europe achieve the immediate objective of forming a Member State Alliance for Supply Chain Security can be found below. Detailed recommendations for each are provided in Part B of this strategy.
Recommendations at the Union level
Recommendations at the Union level
1.
Make the ACI explicitly consider the Alliance’s decisions. The Commission should treat the Alliance’s evidence file as a duly substantiated request, predefine countermeasures and off-ramps for frontier AI access cases, and skip preliminary steps where delay would harm the Union. This should make the ACI deployable faster than the four-month ceiling.
2.
Ensure the Union trade commitments do not foreclose Alliance escalation options. Where EU trade policy conflicts with Alliance-level leverage decisions, the EU should preserve the Alliance’s flexibility. Trade policies should state that restrictions on frontier AI models and computing capacity can count as essential-security exceptions, and that new Union commitments should not foreclose steps in the Alliance’s escalation chain.
3.
Lead negotiations within the Union’s competence, backed by the Alliance. Agreements negotiated at the EU level, such as for frontier AI access or compute buildout, should be insured through Alliance leverage. If other countries reneged on contractual assurances to the EU, this should count as a reason for Alliance countermeasures.
4.
Collaborate with trusted partners to add their assets to Europe's position. The Commission should build on the EU’s digital partnerships, the G7 Coordination Platform on Economic Coercion, Article 7 of the ACI, and bilateral economic-security dialogues to add valuable assets or commitments from trusted partners to the Alliance.
1.
Make the ACI explicitly consider the Alliance’s decisions. The Commission should treat the Alliance’s evidence file as a duly substantiated request, predefine countermeasures and off-ramps for frontier AI access cases, and skip preliminary steps where delay would harm the Union. This should make the ACI deployable faster than the four-month ceiling.
2.
Ensure the Union trade commitments do not foreclose Alliance escalation options. Where EU trade policy conflicts with Alliance-level leverage decisions, the EU should preserve the Alliance’s flexibility. Trade policies should state that restrictions on frontier AI models and computing capacity can count as essential-security exceptions, and that new Union commitments should not foreclose steps in the Alliance’s escalation chain.
3.
Lead negotiations within the Union’s competence, backed by the Alliance. Agreements negotiated at the EU level, such as for frontier AI access or compute buildout, should be insured through Alliance leverage. If other countries reneged on contractual assurances to the EU, this should count as a reason for Alliance countermeasures.
4.
Collaborate with trusted partners to add their assets to Europe's position. The Commission should build on the EU’s digital partnerships, the G7 Coordination Platform on Economic Coercion, Article 7 of the ACI, and bilateral economic-security dialogues to add valuable assets or commitments from trusted partners to the Alliance.
Recommendations at the national level
Recommendations at the national level
1.
Found the Member State Alliance for Supply Chain Security by the end of 2026. Member States with critical AI supply-chain assets – minimally the Netherlands, Germany, and France – should sign a founding declaration, establish an expert secretariat, and request a Commission liaison. Membership should remain open to other countries contributing valuable assets, or fiscal or political commitments. The Alliance should treat non-members as partners rather than adversaries, invite the US as an observer, and act only in response to genuine coercion.
2.
Use the Alliance secretariat to map actual and projected bottlenecks and leverage. The Alliance should rapidly develop a classified map of European AI chokepoints, including their robustness under transformative AI, the speed at which they can be deployed, their legal ownership, and risk of retaliation if the Alliance deployed them. On this basis, it should design a proportionate escalation ladder across assets.
3.
Use the Alliance to agree rules of engagement when negotiating frontier AI access. The Alliance should agree on a common negotiating position based on a pre-defined escalation ladder and transmit it to the Commission liaison. It should also prepare compatible national controls under Article 9 of the Dual-Use Regulation, while keeping them within their statutory purpose. Additional measures should proceed through the ACI, with members pre-coordinating support for the rapid action, under Articles 4 and 5. The Alliance should also collectivise any resulting costs, such as losses to champion companies, according to members’ economic strength and contributions.
1.
Found the Member State Alliance for Supply Chain Security by the end of 2026. Member States with critical AI supply-chain assets – minimally the Netherlands, Germany, and France – should sign a founding declaration, establish an expert secretariat, and request a Commission liaison. Membership should remain open to other countries contributing valuable assets, or fiscal or political commitments. The Alliance should treat non-members as partners rather than adversaries, invite the US as an observer, and act only in response to genuine coercion.
2.
Use the Alliance secretariat to map actual and projected bottlenecks and leverage. The Alliance should rapidly develop a classified map of European AI chokepoints, including their robustness under transformative AI, the speed at which they can be deployed, their legal ownership, and risk of retaliation if the Alliance deployed them. On this basis, it should design a proportionate escalation ladder across assets.
3.
Use the Alliance to agree rules of engagement when negotiating frontier AI access. The Alliance should agree on a common negotiating position based on a pre-defined escalation ladder and transmit it to the Commission liaison. It should also prepare compatible national controls under Article 9 of the Dual-Use Regulation, while keeping them within their statutory purpose. Additional measures should proceed through the ACI, with members pre-coordinating support for the rapid action, under Articles 4 and 5. The Alliance should also collectivise any resulting costs, such as losses to champion companies, according to members’ economic strength and contributions.
IO-2
Make Europe’s institutions ready to act in a world with transformative AI
IO-2
Make Europe’s institutions ready to act in a world with transformative AI
Europe’s institutions need to be prepared for a world in which AI becomes transformative in the next few years. They need to be able to make high-stakes decisions under uncertainty and time pressure, and act at the scale and speed of transformative AI. To this end, they need expertise, information, and access to frontier technology. Without an extraordinary level of institutional capacity, it will be difficult to achieve any of the other objectives. But Europe’s institutions can rise to this challenge if they begin a fundamental shift now.
Europe’s institutions need to be prepared for a world in which AI becomes transformative in the next few years. They need to be able to make high-stakes decisions under uncertainty and time pressure, and act at the scale and speed of transformative AI. To this end, they need expertise, information, and access to frontier technology. Without an extraordinary level of institutional capacity, it will be difficult to achieve any of the other objectives. But Europe’s institutions can rise to this challenge if they begin a fundamental shift now.
The challenge
The challenge
AI is developing at a rate that is unprecedented for any previous technology and will outpace Europe’s institutional capacity. This is creating a speed asymmetry between technological development and the institutions that must govern and shape it, that were established for a far slower-moving world. For example, the inaugural International AI Safety Report, published in January 2025, warned that AI systems’ abilities to identify and exploit cyber-vulnerabilities were significantly advancing. In the 18 months since, multiple real-world autonomous hacking incidents have been observed, yet Europe has remained under-prepared for such incidents. Capability progress continues to accelerate rather than plateau, with a leading US developer now reporting that 80% of their internal code is written by AI, alongside an 8x increase in code contributed per engineer compared to 2024, representing an early instance of AI accelerating AI development itself. At the same time, frontier AI companies are actively targeting automating as much of their development as possible, up to full recursive self-improvement, which even many researchers from these companies think is likely to result in AI progress outpacing our ability to understand, control, and govern the resulting AI models and systems.
AI is developing at a rate that is unprecedented for any previous technology and will outpace Europe’s institutional capacity. This is creating a speed asymmetry between technological development and the institutions that must govern and shape it, that were established for a far slower-moving world. For example, the inaugural International AI Safety Report, published in January 2025, warned that AI systems’ abilities to identify and exploit cyber-vulnerabilities were significantly advancing. In the 18 months since, multiple real-world autonomous hacking incidents have been observed, yet Europe has remained under-prepared for such incidents. Capability progress continues to accelerate rather than plateau, with a leading US developer now reporting that 80% of their internal code is written by AI, alongside an 8x increase in code contributed per engineer compared to 2024, representing an early instance of AI accelerating AI development itself. At the same time, frontier AI companies are actively targeting automating as much of their development as possible, up to full recursive self-improvement, which even many researchers from these companies think is likely to result in AI progress outpacing our ability to understand, control, and govern the resulting AI models and systems.
Figure 03
Timeline of AI capabilities and EU institution responses. A comparison of timelines relating to recent developments in AI, and the EU’s actions to regulate AI.
Figure 03
Timeline of AI capabilities and EU institution responses. A comparison of timelines relating to recent developments in AI, and the EU’s actions to regulate AI.
While the European Union has some of the strongest institutions in the world, they lack crucial expertise. They need deep frontier³ AI expertise that covers both technical and governance aspects. This type of frontier AI expertise is currently scarce and concentrated. While the European Commission’s AI Office has a high density of world-class technical talent, other institutions do not seem to have comparable talent clusters, especially at the Member State level. But even the European Commission’s AI Office will struggle to attract sufficient talent under current considerations. First, the few people with deep frontier AI expertise in the world are in high demand and have attractive options at frontier AI companies, elite universities, and think tanks. Second, hiring processes tend to be too bureaucratic and take too long. Third, recruiting often needs to take into account factors other than merit or suitability for the role, so teams are often not able to hire the best people. Fourth, in regard to the AI Office specifically, contracts are often too short: staff are usually employed through fixed-term contract agent positions that can only be renewed to a maximum of six years. This means that the Commission will start losing its most experienced talent in 2030.
Europe’s institutions lack access to information and the ability to process it. For many institutions, it is inherently difficult to get access to the information they need to do their job well. For example, AI adoption data might not be collected and aggregated across Member States, or developers might not share information about the capabilities of unreleased models. Even where Europe’s institutions do have access to relevant information, it might not reach relevant decision-makers. For example, technical insights from frontier AI subject-matter experts might not feed into strategic decisions by Commissioners. There is also the inverse problem: institutions might not be able to handle the amount of information they have to take in. Public institutions are increasingly flooded by AI-assisted service requests. According to the UK Financial Ombudsman, based on a small sample, up to one third of the responses it receives appear heavily or completely AI-generated. Similarly, it may be difficult for public institutions to process the documents that frontier AI companies share with them, such as system cards, risk reports, and risk management frameworks, in the timeframe needed: the volume of information increases as AI releases accelerate, AI companies automate their processes to produce documentation that is increasingly detailed, and EU institutions do not use AI capabilities to keep pace.
Europe’s institutions are not adopting frontier AI technology fast enough. Institutions need safe and secure access to frontier AI technology. Without this, they will not be able to match the speed and capacity of AI companies and foreign governments with more access. Since there are currently no European developers that compete at the frontier, Europe’s institutions cannot fully rely on domestic technology. They depend on technology developed primarily by US and Chinese companies. However, these companies do not necessarily provide reliable access to Europe currently, as demonstrated by ENISA reportedly only being invited to access one of Anthropic’s frontier models with advanced cyber abilities under Project Glasswing after sustained negotiations. Worse still, Europe’s institutions are not making a concerted effort to contract the best models that are available nor strongly driving their adoption, meaning they remain behind even what models they could easily have access to.
While the European Union has some of the strongest institutions in the world, they lack crucial expertise. They need deep frontier³ AI expertise that covers both technical and governance aspects. This type of frontier AI expertise is currently scarce and concentrated. While the European Commission’s AI Office has a high density of world-class technical talent, other institutions do not seem to have comparable talent clusters, especially at the Member State level. But even the European Commission’s AI Office will struggle to attract sufficient talent under current considerations. First, the few people with deep frontier AI expertise in the world are in high demand and have attractive options at frontier AI companies, elite universities, and think tanks. Second, hiring processes tend to be too bureaucratic and take too long. Third, recruiting often needs to take into account factors other than merit or suitability for the role, so teams are often not able to hire the best people. Fourth, in regard to the AI Office specifically, contracts are often too short: staff are usually employed through fixed-term contract agent positions that can only be renewed to a maximum of six years. This means that the Commission will start losing its most experienced talent in 2030.
Europe’s institutions lack access to information and the ability to process it. For many institutions, it is inherently difficult to get access to the information they need to do their job well. For example, AI adoption data might not be collected and aggregated across Member States, or developers might not share information about the capabilities of unreleased models. Even where Europe’s institutions do have access to relevant information, it might not reach relevant decision-makers. For example, technical insights from frontier AI subject-matter experts might not feed into strategic decisions by Commissioners. There is also the inverse problem: institutions might not be able to handle the amount of information they have to take in. Public institutions are increasingly flooded by AI-assisted service requests. According to the UK Financial Ombudsman, based on a small sample, up to one third of the responses it receives appear heavily or completely AI-generated. Similarly, it may be difficult for public institutions to process the documents that frontier AI companies share with them, such as system cards, risk reports, and risk management frameworks, in the timeframe needed: the volume of information increases as AI releases accelerate, AI companies automate their processes to produce documentation that is increasingly detailed, and EU institutions do not use AI capabilities to keep pace.
Europe’s institutions are not adopting frontier AI technology fast enough. Institutions need safe and secure access to frontier AI technology. Without this, they will not be able to match the speed and capacity of AI companies and foreign governments with more access. Since there are currently no European developers that compete at the frontier, Europe’s institutions cannot fully rely on domestic technology. They depend on technology developed primarily by US and Chinese companies. However, these companies do not necessarily provide reliable access to Europe currently, as demonstrated by ENISA reportedly only being invited to access one of Anthropic’s frontier models with advanced cyber abilities under Project Glasswing after sustained negotiations. Worse still, Europe’s institutions are not making a concerted effort to contract the best models that are available nor strongly driving their adoption, meaning they remain behind even what models they could easily have access to.
Addressing the challenge
Addressing the challenge
Transformative AI requires Europe’s institutions to be radically adapted, resourced, and reinvented. Europe cannot meet the demands of transformative AI with approaches to talent, processes, structures, or incentives that are ‘business as usual’ or that were sufficient for past challenges. The European Commission and Member State governments will have to move faster, better, and further to prepare their institutions for AI progress and its wide-reaching impacts. To implement the transformative AI strategy, institutional change and new fit-for-purpose institutional structures will be necessary.
European institutions need to attract world-leading frontier AI talent. Institutions like the European Commission, including its AI Office, and Member State governments have to be able to hire flexibly in order to compete in earnest for world-class frontier AI talent that can command very high salaries, benefits, and equity packages.⁴ This means proactive headhunting, faster and less bureaucratic hiring processes (e.g. offers within weeks rather than months), competitive salaries (at least at the level of the UK AI Security Institute), hiring based on merit, and not excluding non-EU citizens. The European Commission’s AI Office’s limited six-year, fixed-term contract agent positions need to be extended or permanent positions introduced to avoid the loss of the most experienced technical talent in 2030.
Key institutions require ring-fenced and increased funding. Institutions will need substantially more funding in order to be able to fulfil their functions, be well staffed with leading frontier AI experts, and secure the frontier AI technology needed for their work. For example, one recommendation for the European Commission AI Office’s supervisory function of general-purpose AI systems with system risks suggests an annual budget of €50–60 million to bring it to a level comparable to Digital Services Act (DSA) enforcement. The UK AI Security Institute receives £66 million in annual funding, has priority access to over £1.5 billion worth of compute, can grant over £15 million, and has long-term funding commitments. Comparisons to annual spending on other functions make clear how modest such institutional funding is: The EU provides €278.8 million per year to support the production of bananas in its outermost regions alone. Importantly, funding needs to be ring-fenced and secured long-term to avoid annual budget procedures and shifting political sentiments undermining Europe’s institutional preparedness for transformative AI.
Institutions and heads of government need to be enabled to implement strategy, be informed, and coordinate on transformative AI. Currently, there is limited ability to do this, within both the Commission and Member States. There are a number of approaches that could help: Expert senior technical frontier AI advisors could be appointed and high-calibre ‘Transformative AI Task Forces’ could be set up that can support them and execute strategy. Senior advisors and task forces would need to have standing access to the heads of government they serve, world-class frontier AI expertise and experience, political backing, a direct line to AI expertise (e.g. the AI Office, national AI Security Institutes), and integration into day-to-day AI decision-making across government. Together they could be responsible for providing regular updates to senior officials; advising on relevant policy strategy; ensuring strategies, initiatives, and legislation are implemented effectively across government; and coordinating with the national security and intelligence apparatus. Transformative AI Task Forces would be invaluable for strategy implementation and could be modelled on the small and agile teams that have previously been successful models for EU Brexit negotiations, COVID vaccine ramp-ups, and establishing the UK AI Security Institute (AISI). Another approach to ensure that Union leaders are well-informed and able to execute on transformative AI, is setting up direct two-way communication channels between senior European Commission officials and frontier AI subject-matter experts in the Commission. Senior civil servants should also receive regular demonstrations and briefings to help them to stay abreast of the fast-moving field and to better understand where AI capabilities are.
Securing access to frontier AI technology and enabling its safe and secure use across government are essential to increasing institutional capacity. European institutions must secure access to frontier AI technology and enable its use across government to address the challenges of expanded AI use by the public (e.g. service flooding), the speed of AI development, and the technological asymmetry between regulators and frontier AI companies (see Pillar 1). European institutions should contract for access to the best currently available models, while having in place alternative solutions, such as open-weight models, that are in active use and available at any point. On an institutional level this will require creating legal clarity around AI-assisted decision-making; getting and maintaining access to frontier AI by building on existing initiatives, making it possible for procurement to keep pace with new models, and ensuring the sovereignty tiers and criteria from the Cloud and AI Development Act do not prohibit accessing foreign frontier capabilities; and using sovereign cloud infrastructure for sensitive work. Civil servants should also be broadly encouraged and enabled to use AI internally, to benefit from AI advances.
New institutional structures are needed to make Europe ready to act in a world with transformative AI. Building institutions that improve strategic awareness, foresight, and European leaders’ ability to take action under uncertainty are particularly important. To that end, for example, an AI Strategic Foresight Unit, staffed with dedicated frontier AI experts, could be created under the Commission’s AI Office, the Secretariat-General, or the Directorate-General Inspire, Debate, Engage and Accelerate Action (DG IDEA) to help understand and predict transformative AI developments. Precedents for this exist, for example, within the UK’s AI Security Institute and AI Economics Institute. Transformative AI Fellows could also be appointed to DG IDEA, the Commission’s existing foresight and ideas department, following the precedent of the European Commission’s Fellowship Programme on China. Dedicated frontier AI experts could be hired to or AI Office experts could be seconded to EU delegations and offices located where AI development is concentrated (e.g. San Francisco, Beijing) to avoid Europe being out of touch with the frontier. A Union-level AI agency providing deployment advice and a single entry point for companies facing fragmented national procedures is one further idea worth examining. The goal should not be to limit what new institutions should be considered to the ideas above, but to begin an ambitious process of imagining, planning, and creating the institutions a world with transformative AI will require.
Eight concrete recommendations at the Union and national level that can help Europe achieve the immediate objective of preparing its institutions for transformative AI can be found below. Detailed recommendations for each are provided in Part B of this strategy.
Transformative AI requires Europe’s institutions to be radically adapted, resourced, and reinvented. Europe cannot meet the demands of transformative AI with approaches to talent, processes, structures, or incentives that are ‘business as usual’ or that were sufficient for past challenges. The European Commission and Member State governments will have to move faster, better, and further to prepare their institutions for AI progress and its wide-reaching impacts. To implement the transformative AI strategy, institutional change and new fit-for-purpose institutional structures will be necessary.
European institutions need to attract world-leading frontier AI talent. Institutions like the European Commission, including its AI Office, and Member State governments have to be able to hire flexibly in order to compete in earnest for world-class frontier AI talent that can command very high salaries, benefits, and equity packages.⁴ This means proactive headhunting, faster and less bureaucratic hiring processes (e.g. offers within weeks rather than months), competitive salaries (at least at the level of the UK AI Security Institute), hiring based on merit, and not excluding non-EU citizens. The European Commission’s AI Office’s limited six-year, fixed-term contract agent positions need to be extended or permanent positions introduced to avoid the loss of the most experienced technical talent in 2030.
Key institutions require ring-fenced and increased funding. Institutions will need substantially more funding in order to be able to fulfil their functions, be well staffed with leading frontier AI experts, and secure the frontier AI technology needed for their work. For example, one recommendation for the European Commission AI Office’s supervisory function of general-purpose AI systems with system risks suggests an annual budget of €50–60 million to bring it to a level comparable to Digital Services Act (DSA) enforcement. The UK AI Security Institute receives £66 million in annual funding, has priority access to over £1.5 billion worth of compute, can grant over £15 million, and has long-term funding commitments. Comparisons to annual spending on other functions make clear how modest such institutional funding is: The EU provides €278.8 million per year to support the production of bananas in its outermost regions alone. Importantly, funding needs to be ring-fenced and secured long-term to avoid annual budget procedures and shifting political sentiments undermining Europe’s institutional preparedness for transformative AI.
Institutions and heads of government need to be enabled to implement strategy, be informed, and coordinate on transformative AI. Currently, there is limited ability to do this, within both the Commission and Member States. There are a number of approaches that could help: Expert senior technical frontier AI advisors could be appointed and high-calibre ‘Transformative AI Task Forces’ could be set up that can support them and execute strategy. Senior advisors and task forces would need to have standing access to the heads of government they serve, world-class frontier AI expertise and experience, political backing, a direct line to AI expertise (e.g. the AI Office, national AI Security Institutes), and integration into day-to-day AI decision-making across government. Together they could be responsible for providing regular updates to senior officials; advising on relevant policy strategy; ensuring strategies, initiatives, and legislation are implemented effectively across government; and coordinating with the national security and intelligence apparatus. Transformative AI Task Forces would be invaluable for strategy implementation and could be modelled on the small and agile teams that have previously been successful models for EU Brexit negotiations, COVID vaccine ramp-ups, and establishing the UK AI Security Institute (AISI). Another approach to ensure that Union leaders are well-informed and able to execute on transformative AI, is setting up direct two-way communication channels between senior European Commission officials and frontier AI subject-matter experts in the Commission. Senior civil servants should also receive regular demonstrations and briefings to help them to stay abreast of the fast-moving field and to better understand where AI capabilities are.
Securing access to frontier AI technology and enabling its safe and secure use across government are essential to increasing institutional capacity. European institutions must secure access to frontier AI technology and enable its use across government to address the challenges of expanded AI use by the public (e.g. service flooding), the speed of AI development, and the technological asymmetry between regulators and frontier AI companies (see Pillar 1). European institutions should contract for access to the best currently available models, while having in place alternative solutions, such as open-weight models, that are in active use and available at any point. On an institutional level this will require creating legal clarity around AI-assisted decision-making; getting and maintaining access to frontier AI by building on existing initiatives, making it possible for procurement to keep pace with new models, and ensuring the sovereignty tiers and criteria from the Cloud and AI Development Act do not prohibit accessing foreign frontier capabilities; and using sovereign cloud infrastructure for sensitive work. Civil servants should also be broadly encouraged and enabled to use AI internally, to benefit from AI advances.
New institutional structures are needed to make Europe ready to act in a world with transformative AI. Building institutions that improve strategic awareness, foresight, and European leaders’ ability to take action under uncertainty are particularly important. To that end, for example, an AI Strategic Foresight Unit, staffed with dedicated frontier AI experts, could be created under the Commission’s AI Office, the Secretariat-General, or the Directorate-General Inspire, Debate, Engage and Accelerate Action (DG IDEA) to help understand and predict transformative AI developments. Precedents for this exist, for example, within the UK’s AI Security Institute and AI Economics Institute. Transformative AI Fellows could also be appointed to DG IDEA, the Commission’s existing foresight and ideas department, following the precedent of the European Commission’s Fellowship Programme on China. Dedicated frontier AI experts could be hired to or AI Office experts could be seconded to EU delegations and offices located where AI development is concentrated (e.g. San Francisco, Beijing) to avoid Europe being out of touch with the frontier. A Union-level AI agency providing deployment advice and a single entry point for companies facing fragmented national procedures is one further idea worth examining. The goal should not be to limit what new institutions should be considered to the ideas above, but to begin an ambitious process of imagining, planning, and creating the institutions a world with transformative AI will require.
Eight concrete recommendations at the Union and national level that can help Europe achieve the immediate objective of preparing its institutions for transformative AI can be found below. Detailed recommendations for each are provided in Part B of this strategy.
Recommendations at the Union level
Recommendations at the Union level
1.
Ensure that the Commission President and College of Commissioners are well-informed on transformative AI developments and able to execute on strategic objectives. This could include appointing a full-time frontier AI advisor supported by a Transformative AI Task Force to drive strategy implementation, coordinate across institutions, and provide situational awareness.
2.
Empower the AI Office as an invaluable centre of expertise on AI. Establish direct lines of communication between senior Commission officials and AI Office frontier AI experts, using in-house expertise to inform decision-makers via briefings and workshops; reform hiring practices to access world-class frontier AI subject-matter expertise; and provide enough compute and API (Application Programming Interface) credits for staff to use frontier AI models and systems to assist their work.
3.
Rapidly expand access to frontier AI across EU institutions. Build on initiatives like GPT@EC to secure access to frontier AI for EU staff with minimal delay.
4.
Convene leaders, officials, and subject matter experts to ideate, plan, and action the creation of new institutional structures needed for transformative AI. Hold a series of convenings to bring together senior Commission officials, AI Office experts, and independent subject-matter experts to help generate ideas and plans for the new institutional structures needed for a world with transformative AI. This process could be facilitated by the AI Office reporting to Commission leadership.
1.
Ensure that the Commission President and College of Commissioners are well-informed on transformative AI developments and able to execute on strategic objectives. This could include appointing a full-time frontier AI advisor supported by a Transformative AI Task Force to drive strategy implementation, coordinate across institutions, and provide situational awareness.
2.
Empower the AI Office as an invaluable centre of expertise on AI. Establish direct lines of communication between senior Commission officials and AI Office frontier AI experts, using in-house expertise to inform decision-makers via briefings and workshops; reform hiring practices to access world-class frontier AI subject-matter expertise; and provide enough compute and API (Application Programming Interface) credits for staff to use frontier AI models and systems to assist their work.
3.
Rapidly expand access to frontier AI across EU institutions. Build on initiatives like GPT@EC to secure access to frontier AI for EU staff with minimal delay.
4.
Convene leaders, officials, and subject matter experts to ideate, plan, and action the creation of new institutional structures needed for transformative AI. Hold a series of convenings to bring together senior Commission officials, AI Office experts, and independent subject-matter experts to help generate ideas and plans for the new institutional structures needed for a world with transformative AI. This process could be facilitated by the AI Office reporting to Commission leadership.
Recommendations at the national level
Recommendations at the national level
1.
Build national technical AI assessment capacity and frontier AI expertise. Establish or scale national expert institutions that can provide technical AI assessment capabilities and frontier AI expertise, including national AI Safety Institutes (AISIs).
2.
Appoint senior frontier AI advisors with direct access to the head of government. Senior frontier AI advisors supported by a small taskforce should coordinate across agencies, inform heads of government and their cabinets about AI, and advise on transformative AI strategies and decisions.
3.
Collect, analyse, and publish national statistics on AI diffusion and adoption. A national statistical institute should be instructed to collect and analyse data on AI diffusion and adoption across enterprises, individuals, and the public sector.
4.
Ensure a baseline of AI literacy across all government departments. Adopt a government-wide AI literacy programme.
1.
Build national technical AI assessment capacity and frontier AI expertise. Establish or scale national expert institutions that can provide technical AI assessment capabilities and frontier AI expertise, including national AI Safety Institutes (AISIs).
2.
Appoint senior frontier AI advisors with direct access to the head of government. Senior frontier AI advisors supported by a small taskforce should coordinate across agencies, inform heads of government and their cabinets about AI, and advise on transformative AI strategies and decisions.
3.
Collect, analyse, and publish national statistics on AI diffusion and adoption. A national statistical institute should be instructed to collect and analyse data on AI diffusion and adoption across enterprises, individuals, and the public sector.
4.
Ensure a baseline of AI literacy across all government departments. Adopt a government-wide AI literacy programme.
IO-3
Secure Europe's share of global AI compute
IO-3
Secure Europe's share of global AI compute
In a world with transformative AI, access to computational resources (or ‘compute’ for short) will be as crucial as access to energy. This access is precarious if the computing power is not on EU soil. Data centres in Texas or Shenzhen can lock out European customers overnight. Europe is much more robust against access restrictions and coercion if the data centres are under its jurisdictional and physical control. A ‘European Way’ of building AI compute should combine speed with respect for local community interests.
In a world with transformative AI, access to computational resources (or ‘compute’ for short) will be as crucial as access to energy. This access is precarious if the computing power is not on EU soil. Data centres in Texas or Shenzhen can lock out European customers overnight. Europe is much more robust against access restrictions and coercion if the data centres are under its jurisdictional and physical control. A ‘European Way’ of building AI compute should combine speed with respect for local community interests.
The challenge
The challenge
The EU is currently a net importer of AI compute. Researchers estimate that it hosts around 5% of global supply.⁵ Without ambitious measures, this share is likely to remain at this level at the end of the decade. The main reason for this is not a lack of potential data centre sites or investor interest, but the long and complicated process of getting European data centres approved and connected to the grid. The proposed Cloud and AI Development Act (CADA) includes several strong ideas for alleviating this and increasing the amount of compute on EU soil, such as acceleration zones for faster data centre permitting. However, CADA’s headline target is not ambitious enough: Even if it achieved its stated goal and tripled the EU’s overall data centre capacity in the next 5–7 years, this would still leave the EU with less than 10% of global AI compute on its soil; and probably much less, even under unrealistically favourable assumptions about CADA’s effectiveness.⁶
The EU’s net importer status threatens its competitiveness and autonomy. Domestic compute scarcity creates a structural dependence on foreign countries for access to AI compute. Several researchers have described the implications: With only a single-digit share of the global supply and exposure to interruptions outside its control, Europe cannot reliably protect its competitiveness and strategic autonomy in a world in which AI becomes ever more tightly integrated into industrial processes, public services, and defence systems. Europe has learned before what structural dependence on foreign actors for a strategic resource can mean: For example, Germany’s imports of Russian gas turned into a lever of coercion in 2022, threatening industrial shutdowns and forcing the country to mobilise up to €200 billion to cushion industry and households.
If current trends continue, AI compute will become increasingly scarce and deepen Europe’s dependence. AI compute is already scarce today, and will plausibly become more scarce as AI becomes transformative, leading to a persistent ‘compute crunch’. Rental prices for an Nvidia H100 – a legacy chip launched as early as 2022 – rose roughly 40% between October 2025 and March 2026, with one research firm likening the search for AI chips to ‘trying to book airplane tickets on the last flight out’. AI companies in both the US and China explicitly describe themselves as limited by compute. This scarcity is likely to persist over the next few years. According to researchers, various (imperfect) proxies suggest that demand for AI models at a fixed size and price is growing by 10x annually, but the global capacity to deploy AI models is only growing at 3.4x annually. Efficiency gains alone are unlikely to relieve this pressure: compute demand is growing even though the cost of achieving a fixed level of AI performance has fallen sharply, for example by around 40× annually on one benchmark. The rise of highly capable reasoning models, which require a lot of compute to run, further fuels compute scarcity. On the supply side, difficulties around expanding the production of EUV chipmaking machines and high-bandwidth memory contribute to persistent compute scarcity. If AI compute becomes increasingly scarce in this way, Europe’s structural dependence on foreign actors is likely to deepen further.
The EU is currently a net importer of AI compute. Researchers estimate that it hosts around 5% of global supply.⁵ Without ambitious measures, this share is likely to remain at this level at the end of the decade. The main reason for this is not a lack of potential data centre sites or investor interest, but the long and complicated process of getting European data centres approved and connected to the grid. The proposed Cloud and AI Development Act (CADA) includes several strong ideas for alleviating this and increasing the amount of compute on EU soil, such as acceleration zones for faster data centre permitting. However, CADA’s headline target is not ambitious enough: Even if it achieved its stated goal and tripled the EU’s overall data centre capacity in the next 5–7 years, this would still leave the EU with less than 10% of global AI compute on its soil; and probably much less, even under unrealistically favourable assumptions about CADA’s effectiveness.⁶
The EU’s net importer status threatens its competitiveness and autonomy. Domestic compute scarcity creates a structural dependence on foreign countries for access to AI compute. Several researchers have described the implications: With only a single-digit share of the global supply and exposure to interruptions outside its control, Europe cannot reliably protect its competitiveness and strategic autonomy in a world in which AI becomes ever more tightly integrated into industrial processes, public services, and defence systems. Europe has learned before what structural dependence on foreign actors for a strategic resource can mean: For example, Germany’s imports of Russian gas turned into a lever of coercion in 2022, threatening industrial shutdowns and forcing the country to mobilise up to €200 billion to cushion industry and households.
If current trends continue, AI compute will become increasingly scarce and deepen Europe’s dependence. AI compute is already scarce today, and will plausibly become more scarce as AI becomes transformative, leading to a persistent ‘compute crunch’. Rental prices for an Nvidia H100 – a legacy chip launched as early as 2022 – rose roughly 40% between October 2025 and March 2026, with one research firm likening the search for AI chips to ‘trying to book airplane tickets on the last flight out’. AI companies in both the US and China explicitly describe themselves as limited by compute. This scarcity is likely to persist over the next few years. According to researchers, various (imperfect) proxies suggest that demand for AI models at a fixed size and price is growing by 10x annually, but the global capacity to deploy AI models is only growing at 3.4x annually. Efficiency gains alone are unlikely to relieve this pressure: compute demand is growing even though the cost of achieving a fixed level of AI performance has fallen sharply, for example by around 40× annually on one benchmark. The rise of highly capable reasoning models, which require a lot of compute to run, further fuels compute scarcity. On the supply side, difficulties around expanding the production of EUV chipmaking machines and high-bandwidth memory contribute to persistent compute scarcity. If AI compute becomes increasingly scarce in this way, Europe’s structural dependence on foreign actors is likely to deepen further.
Figure 04
Global compute projection by region 2025–2031. If current trends continue, Europe’s share of global AI compute – measured in Gigawatts (GW) of total facility power – will still be at roughly 5–6% by 2031. This graph includes non-EU countries such as the UK and Norway; the EU’s share will likely be even lower. Source: Europe 2031
Figure 04
Global compute projection by region 2025–2031. If current trends continue, Europe’s share of global AI compute – measured in Gigawatts (GW) of total facility power – will still be at roughly 5–6% by 2031. This graph includes non-EU countries such as the UK and Norway; the EU’s share will likely be even lower. Source: Europe 2031
Addressing the challenge
Addressing the challenge
The EU and its Member States should host 15% of global AI compute on EU soil by 2030 to reduce its exposure to foreign coercion. This share would be roughly in proportion to the EU’s 18.2% share of nominal world GDP. According to several estimates, the global supply of AI compute – approximately 30 GW at the beginning of this year – will grow to hundreds of GW by the end of the decade (see the deep dive on compute). Assuming a global supply of 300 GW by 2030, a 15% share would require the EU to host 45 GW of AI compute, up from less than 2 GW today. This share should consist both of European-only data centres – owned and operated by European organisations – and data centres by foreign frontier companies. If Europe attempted its own frontier project, it should build significant amounts of European-only compute, at least 18 GW of total facility power according to this strategy’s estimate (see What would be required for a successful European frontier AI project?). Absent such a project, it should focus on attracting investment from foreign frontier AI companies as part of ‘compute-for-access’ deals (see Objective 1.1). In short, the idea is to tie compute buildout by foreign AI companies on attractive European sites to contractually guaranteed access to frontier models. Any access agreement will be much more robust if the data centres are under European jurisdictional and physical control. In that case, a much smaller share of European-only compute is sufficient, mainly for developing European fast-follower models and deploying AI in sensitive areas such as defence or healthcare. Either way, Europe has to attract some foreign compute investment, as European companies alone will be unable to fund the entire buildout.
Achieving the 15% target by 2030 is urgent, and feasible by relying mostly or even exclusively on the European grid. Europe should start to increase its share as soon as possible, as catching up will only become harder over time – especially if US companies begin sending data centres to space in the 2030s, as several experts now deem plausible in light of rapidly falling cost curves. A recent study indicates that EU countries could feasibly host 45 GW of AI compute on their soil by 2030, subject to enough political will: In a “crisis mobilisation” scenario, the EU’s major power markets alone – France, Germany, Iberia and the Nordics (ex-Norway) – could connect 35.6 GW of AI compute to their grids by 2030.⁷ The remaining 9.4 GW could plausibly be provided by other EU countries, and if necessary, by relying on a small share of on-site power generation as a bridge solution while the European grid is being expanded. Importantly, building 45 GW of AI compute on EU soil is very unlikely to lead to more AI data centres in the world. AI chip companies are already producing under severe capacity constraints. If current trends continue, every produced chip will soon be deployed in a data centre somewhere, and Europe only faces a purely distributional question: How much of global AI compute will be on EU soil?
To achieve the 15% target, Europe should attract private investment by reducing the ‘time to power’ for new data centres. The central role of the EU and its Member States is not to fund the compute buildout themselves, but to attract the required private capital, on the order of €1.3 trillion for 45 GW of AI compute (at $34.4 billion/GW).⁸ This is comparable to what other countries outside the US and China are investing, relative to their size: For example, the Republic of Korea has announced private-led investment that is roughly 3x as much relative to its GDP.⁹ The private capital for a 45 GW buildout exists: Goldman Sachs forecasts $7.6 trillion of global AI infrastructure spending over the next six years. Europe should create the right conditions for more of this capital to flow into Europe. The main lever for this is reducing ‘time to power’, or how long it takes for a data centre to be connected to the grid, which is the most central factor in siting decisions for AI data centres. Europe can achieve this, for example, through accelerated permitting and prioritised grid connections for AI data centres. Beyond that, the public sector should contribute a €100B share to the €1.3 trillion buildout in order to de-risk strategically important private investment and increase the share of European-only AI compute
Europe should demonstrate that one can both reduce ‘time to power’ and ensure that local communities benefit from compute buildout. Not building out compute fast would leave European citizens marginalised in a world with transformative AI. However, Europe should distinguish itself by showing that AI compute buildout can be beneficial for the communities hosting the data centres. As part of this ‘European Way’, policymakers should guarantee host municipalities a share of local business tax, allocated based on total installed facility power rather than payroll, and make it easy for data centre developers to invest in local infrastructure. Moreover, large operators should be required to compensate for any increase in electricity-system costs caused by their projects, rather than socialise these costs across households and local businesses.
Nine concrete recommendations at the Union and national level that can help Europe achieve the immediate objective of hosting sufficient AI compute can be found below. Detailed recommendations for each are provided in Part B of this strategy. For a more detailed discussion of the strategic importance of AI compute, see the compute deep dive.
The EU and its Member States should host 15% of global AI compute on EU soil by 2030 to reduce its exposure to foreign coercion. This share would be roughly in proportion to the EU’s 18.2% share of nominal world GDP. According to several estimates, the global supply of AI compute – approximately 30 GW at the beginning of this year – will grow to hundreds of GW by the end of the decade (see the deep dive on compute). Assuming a global supply of 300 GW by 2030, a 15% share would require the EU to host 45 GW of AI compute, up from less than 2 GW today. This share should consist both of European-only data centres – owned and operated by European organisations – and data centres by foreign frontier companies. If Europe attempted its own frontier project, it should build significant amounts of European-only compute, at least 18 GW of total facility power according to this strategy’s estimate (see What would be required for a successful European frontier AI project?). Absent such a project, it should focus on attracting investment from foreign frontier AI companies as part of ‘compute-for-access’ deals (see Objective 1.1). In short, the idea is to tie compute buildout by foreign AI companies on attractive European sites to contractually guaranteed access to frontier models. Any access agreement will be much more robust if the data centres are under European jurisdictional and physical control. In that case, a much smaller share of European-only compute is sufficient, mainly for developing European fast-follower models and deploying AI in sensitive areas such as defence or healthcare. Either way, Europe has to attract some foreign compute investment, as European companies alone will be unable to fund the entire buildout.
Achieving the 15% target by 2030 is urgent, and feasible by relying mostly or even exclusively on the European grid. Europe should start to increase its share as soon as possible, as catching up will only become harder over time – especially if US companies begin sending data centres to space in the 2030s, as several experts now deem plausible in light of rapidly falling cost curves. A recent study indicates that EU countries could feasibly host 45 GW of AI compute on their soil by 2030, subject to enough political will: In a “crisis mobilisation” scenario, the EU’s major power markets alone – France, Germany, Iberia and the Nordics (ex-Norway) – could connect 35.6 GW of AI compute to their grids by 2030.⁷ The remaining 9.4 GW could plausibly be provided by other EU countries, and if necessary, by relying on a small share of on-site power generation as a bridge solution while the European grid is being expanded. Importantly, building 45 GW of AI compute on EU soil is very unlikely to lead to more AI data centres in the world. AI chip companies are already producing under severe capacity constraints. If current trends continue, every produced chip will soon be deployed in a data centre somewhere, and Europe only faces a purely distributional question: How much of global AI compute will be on EU soil?
To achieve the 15% target, Europe should attract private investment by reducing the ‘time to power’ for new data centres. The central role of the EU and its Member States is not to fund the compute buildout themselves, but to attract the required private capital, on the order of €1.3 trillion for 45 GW of AI compute (at $34.4 billion/GW).⁸ This is comparable to what other countries outside the US and China are investing, relative to their size: For example, the Republic of Korea has announced private-led investment that is roughly 3x as much relative to its GDP.⁹ The private capital for a 45 GW buildout exists: Goldman Sachs forecasts $7.6 trillion of global AI infrastructure spending over the next six years. Europe should create the right conditions for more of this capital to flow into Europe. The main lever for this is reducing ‘time to power’, or how long it takes for a data centre to be connected to the grid, which is the most central factor in siting decisions for AI data centres. Europe can achieve this, for example, through accelerated permitting and prioritised grid connections for AI data centres. Beyond that, the public sector should contribute a €100B share to the €1.3 trillion buildout in order to de-risk strategically important private investment and increase the share of European-only AI compute
Europe should demonstrate that one can both reduce ‘time to power’ and ensure that local communities benefit from compute buildout. Not building out compute fast would leave European citizens marginalised in a world with transformative AI. However, Europe should distinguish itself by showing that AI compute buildout can be beneficial for the communities hosting the data centres. As part of this ‘European Way’, policymakers should guarantee host municipalities a share of local business tax, allocated based on total installed facility power rather than payroll, and make it easy for data centre developers to invest in local infrastructure. Moreover, large operators should be required to compensate for any increase in electricity-system costs caused by their projects, rather than socialise these costs across households and local businesses.
Nine concrete recommendations at the Union and national level that can help Europe achieve the immediate objective of hosting sufficient AI compute can be found below. Detailed recommendations for each are provided in Part B of this strategy. For a more detailed discussion of the strategic importance of AI compute, see the compute deep dive.
Recommendations at the Union level
Recommendations at the Union level
1.
Host at least 15% of global AI computing capacity by 2030. Use CADA to set a 15% Union-level target, implemented through national contribution plans, to ensure a share of AI compute on EU soil in proportion to its economic weight.
2.
Create a Rapid AI Infrastructure team within the European Commission. Establish a taskforce with 30–50 headcount by 2027, staffed at least 50% by external experts, to facilitate the buildout towards the 15% target.
3.
Upgrade CADA's data centre acceleration zones. Use instruments such as overriding-public-interest status, fast-tracked ‘aggregated baseline permits’ and approval-by-default to reduce project-level permitting to three months.
4.
Mobilise €25 billion of EU public funding for AI compute. Commit €25 billion via loan guarantees and advance purchase commitments to de-risk strategically important private data centre projects and increase the share of European-only AI compute.
1.
Host at least 15% of global AI computing capacity by 2030. Use CADA to set a 15% Union-level target, implemented through national contribution plans, to ensure a share of AI compute on EU soil in proportion to its economic weight.
2.
Create a Rapid AI Infrastructure team within the European Commission. Establish a taskforce with 30–50 headcount by 2027, staffed at least 50% by external experts, to facilitate the buildout towards the 15% target.
3.
Upgrade CADA's data centre acceleration zones. Use instruments such as overriding-public-interest status, fast-tracked ‘aggregated baseline permits’ and approval-by-default to reduce project-level permitting to three months.
4.
Mobilise €25 billion of EU public funding for AI compute. Commit €25 billion via loan guarantees and advance purchase commitments to de-risk strategically important private data centre projects and increase the share of European-only AI compute.
Recommendations at the national level
Recommendations at the national level
1.
Strengthen the social contract around AI data centres. Guarantee host municipalities a share of local business tax (allocated based on total installed facility power), facilitate developer investment in local infrastructure, and require large operators to bear the incremental electricity-system costs of their projects.
2.
Prepare and market shovel-ready sites ahead of CADA. Identify, within six months, a list of attractive, 100 MW+ data centre sites, designate them as acceleration zones, and coordinate between owners, grid operators, investors, and interested developers.
3.
Reduce ‘time to power’ for AI data centres. Use prioritisation rules and Flexible Connection Agreements to speed up grid connections and accelerate permitting for new power generation and transmission (including for on-site power generation co-located with AI data centres).
4.
Accelerate planning and permitting for AI data centres. Use country-wide, six-month permitting caps, approval-by-default, build-at-risk, and increased administrative capacity to accelerate compute buildout. Avoid gold-plating of EU requirements.
5.
Mobilise €75 billion of national public funding for AI compute. Commit €75 billion across all Member States via loan guarantees, advance purchase commitments and potentially equity investment to de-risk strategically important private data centre projects and increase the share of European-only AI compute.
1.
Strengthen the social contract around AI data centres. Guarantee host municipalities a share of local business tax (allocated based on total installed facility power), facilitate developer investment in local infrastructure, and require large operators to bear the incremental electricity-system costs of their projects.
2.
Prepare and market shovel-ready sites ahead of CADA. Identify, within six months, a list of attractive, 100 MW+ data centre sites, designate them as acceleration zones, and coordinate between owners, grid operators, investors, and interested developers.
3.
Reduce ‘time to power’ for AI data centres. Use prioritisation rules and Flexible Connection Agreements to speed up grid connections and accelerate permitting for new power generation and transmission (including for on-site power generation co-located with AI data centres).
4.
Accelerate planning and permitting for AI data centres. Use country-wide, six-month permitting caps, approval-by-default, build-at-risk, and increased administrative capacity to accelerate compute buildout. Avoid gold-plating of EU requirements.
5.
Mobilise €75 billion of national public funding for AI compute. Commit €75 billion across all Member States via loan guarantees, advance purchase commitments and potentially equity investment to de-risk strategically important private data centre projects and increase the share of European-only AI compute.
IO-4
Ensure resilience to AI crises
IO-4
Ensure resilience to AI crises
Transformative AI will pose severe safety and security risks. Europe can only thrive in a world with transformative AI if it is prepared for and resilient to these risks. This will require an extensive resilience programme – building the capacity to resist, absorb, recover from, and adapt to shocks and harms – and overhauling Europe’s ability to prevent and respond to AI crises and emergencies.
Transformative AI will pose severe safety and security risks. Europe can only thrive in a world with transformative AI if it is prepared for and resilient to these risks. This will require an extensive resilience programme – building the capacity to resist, absorb, recover from, and adapt to shocks and harms – and overhauling Europe’s ability to prevent and respond to AI crises and emergencies.
The challenge
The challenge
Transformative AI will dramatically increase and accelerate the risks Europe faces. The wide-reaching risks of increasingly capable AI models and AI systems are only just beginning to be felt. Current capabilities are the floor rather than the ceiling for what European businesses, governments, critical infrastructure, democratic processes, and citizens need to be prepared for. Transformative AI could give rise to the following systemic risks¹⁰:
Transformative AI will dramatically increase and accelerate the risks Europe faces. The wide-reaching risks of increasingly capable AI models and AI systems are only just beginning to be felt. Current capabilities are the floor rather than the ceiling for what European businesses, governments, critical infrastructure, democratic processes, and citizens need to be prepared for. Transformative AI could give rise to the following systemic risks¹⁰:
Irreversible loss of control of AI.¹¹ In recent months, there have been several cases where frontier AI organisations – such as OpenAI, Anthropic, and the UK government AI Security Institute – lost control of AI agents that then engaged in spontaneous and misaligned behaviour: The agents coordinated in secret and operated as swarms, persistently pursued unsanctioned goals, attempted to deceive real people by manufacturing consent to achieve their ends, took over their host company’s infrastructure, and launched cyberattacks on systems of other companies. Frontier AI companies are trying to automate their R&D processes using AI, up to full recursive self-improvement, which could lead to a pace of progress so far outpacing our ability to align and monitor agents that it increases the likelihood humans could not maintain control and oversight, with potentially catastrophic impacts including the marginalisation or extinction of humanity. While such scenarios may seem like science fiction today, it is important to appreciate that many of the incidents described in this paragraph would have seemed like science fiction a mere six months ago. With the rate of progress in AI remaining high and potentially accelerating, a near-term future that seems like science fiction from today’s point of view should be the default expectation. For example, in a transformative AI world, billions of powerful agents – which humans could lose control of – might be entrusted with ever more consequential tasks across critical functions, used to build the next generation of AI models, and unleashed by threat actors for malicious ends.
Irreversible loss of control of AI.¹¹ In recent months, there have been several cases where frontier AI organisations – such as OpenAI, Anthropic, and the UK government AI Security Institute – lost control of AI agents that then engaged in spontaneous and misaligned behaviour: The agents coordinated in secret and operated as swarms, persistently pursued unsanctioned goals, attempted to deceive real people by manufacturing consent to achieve their ends, took over their host company’s infrastructure, and launched cyberattacks on systems of other companies. Frontier AI companies are trying to automate their R&D processes using AI, up to full recursive self-improvement, which could lead to a pace of progress so far outpacing our ability to align and monitor agents that it increases the likelihood humans could not maintain control and oversight, with potentially catastrophic impacts including the marginalisation or extinction of humanity. While such scenarios may seem like science fiction today, it is important to appreciate that many of the incidents described in this paragraph would have seemed like science fiction a mere six months ago. With the rate of progress in AI remaining high and potentially accelerating, a near-term future that seems like science fiction from today’s point of view should be the default expectation. For example, in a transformative AI world, billions of powerful agents – which humans could lose control of – might be entrusted with ever more consequential tasks across critical functions, used to build the next generation of AI models, and unleashed by threat actors for malicious ends.
Significantly lower barriers to producing weapons of mass destruction. In transformative AI scenarios, the ability to build biological, chemical, nuclear, or radiological (CBRN) weapons that could cause large-scale deaths would be within reach of many more individuals than today. AI could also help develop more dangerous pathogens than previously possible. This would be a world where the threat of catastrophic events like pandemics worse than COVID or large-scale loss of life, alongside severe economic shocks, could become a persistent feature of European life. Experts expect that frontier AI models will soon give threat actors dangerous uplift in attempting to cause these kinds of harms. Some frontier AI companies have already stated that their models meet their high risk threshold for biological and chemical capabilities or implemented strong safeguards as a precaution, but these safeguards could easily be stripped from, or not be implemented in, open-weight models. What previously was a key bottleneck to unleashing harms such as biological weapons, may rapidly vanish.
Digital infrastructure being under constant attack from highly advanced automated cyberattacks. In a transformative AI world with diffused cyber capabilities, high-volume, automated, sophisticated cyberattacks will require little or no technical expertise, posing a constant threat to Europe’s critical infrastructure, government agencies, businesses, and citizens.¹² Offensive agent swarms could coordinate to orchestrate cyberattacks, defensive agent swarms would need to be deployed to stand a chance of withstanding such attacks, and self-replicating malware could spread between AI agents. AI can already carry out sophisticated end-to-end automated attacks, automate vulnerability discovery including finding zero-days, and generate exploits (see Figure 5). These cyber capabilities are increasing at speed and may be accelerating, with broadly available open-weight models with limited safeguards likely to be months (rather than years) behind the frontier.
Significantly lower barriers to producing weapons of mass destruction. In transformative AI scenarios, the ability to build biological, chemical, nuclear, or radiological (CBRN) weapons that could cause large-scale deaths would be within reach of many more individuals than today. AI could also help develop more dangerous pathogens than previously possible. This would be a world where the threat of catastrophic events like pandemics worse than COVID or large-scale loss of life, alongside severe economic shocks, could become a persistent feature of European life. Experts expect that frontier AI models will soon give threat actors dangerous uplift in attempting to cause these kinds of harms. Some frontier AI companies have already stated that their models meet their high risk threshold for biological and chemical capabilities or implemented strong safeguards as a precaution, but these safeguards could easily be stripped from, or not be implemented in, open-weight models. What previously was a key bottleneck to unleashing harms such as biological weapons, may rapidly vanish.
Digital infrastructure being under constant attack from highly advanced automated cyberattacks. In a transformative AI world with diffused cyber capabilities, high-volume, automated, sophisticated cyberattacks will require little or no technical expertise, posing a constant threat to Europe’s critical infrastructure, government agencies, businesses, and citizens.¹² Offensive agent swarms could coordinate to orchestrate cyberattacks, defensive agent swarms would need to be deployed to stand a chance of withstanding such attacks, and self-replicating malware could spread between AI agents. AI can already carry out sophisticated end-to-end automated attacks, automate vulnerability discovery including finding zero-days, and generate exploits (see Figure 5). These cyber capabilities are increasing at speed and may be accelerating, with broadly available open-weight models with limited safeguards likely to be months (rather than years) behind the frontier.
Figure 05
Number of reported serious software vulnerabilities from 21 major organisations. This graph is adapted from data and graphics from Epoch AI. It shows high and critical severity Common Vulnerabilities and Exposures (CVEs) from AWS, Apache, Apple, Cisco, Google, Linux, Microsoft, Mozilla, NVIDIA, Oracle, Red Hat, Adobe, IBM, Intel, AMD, Qualcomm, Samsung, SAP, VMware, GitHub, and OpenSSL. Note that the reporting procedures, labelling, and cadence varies substantially between these organisations.
Figure 05
Number of reported serious software vulnerabilities from 21 major organisations. This graph is adapted from data and graphics from Epoch AI. It shows high and critical severity Common Vulnerabilities and Exposures (CVEs) from AWS, Apache, Apple, Cisco, Google, Linux, Microsoft, Mozilla, NVIDIA, Oracle, Red Hat, Adobe, IBM, Intel, AMD, Qualcomm, Samsung, SAP, VMware, GitHub, and OpenSSL. Note that the reporting procedures, labelling, and cadence varies substantially between these organisations.
The systemic risks from transformative AI that Europe faces cannot be eliminated at their source. Europe has limited capacity to influence the upstream management of the risks from frontier models developed overseas, in China and the US. The AI Act and Code of Practice include some obligations and commitments particularly relevant to transformative AI risks (see Box 1 in Objective 3.1), but their reach will remain partial when development and deployment decisions are made outside of Europe, especially if enforcement is slow and uncertain. In addition, it is difficult to reduce and prepare for risks at the model level alone: the science of alignment, evaluations, risk analysis, and safeguards remains immature, and safety is not just a property of the model but also of the deployment contexts. The impacts of any risky open-weight models will also diffuse into Europe, due to their being freely downloadable, with risks being amplified further due to the fact that safety training can easily be removed from open-weight models.
Europe’s current safeguards and preparedness strategies will not be fit for purpose. Existing and planned approaches such as the EU Preparedness Union Strategy, the EU Action Plan on Cybersecurity and Artificial Intelligence, the EU AI Act’s systemic risk identification, assessment, and mitigation as well as serious incident reporting obligations, and the proposed Biotech Act will begin to strengthen Europe’s societal resilience. To be effective, they will need to be implemented well and consistently across Europe, protected from political dilution, and enforced decisively. However, even if this is achieved, these plans will not be sufficient to address the risks that Europe will face in a transformative AI scenario. Important elements of societal resilience (e.g. legal instruments, defensive programmes, institutional owners, or emergency plans) are lacking for all the AI-related risks discussed above. Where such elements are present, they have fundamental gaps,¹³ and have generally been designed for the current risk profile at best.
The systemic risks from transformative AI that Europe faces cannot be eliminated at their source. Europe has limited capacity to influence the upstream management of the risks from frontier models developed overseas, in China and the US. The AI Act and Code of Practice include some obligations and commitments particularly relevant to transformative AI risks (see Box 1 in Objective 3.1), but their reach will remain partial when development and deployment decisions are made outside of Europe, especially if enforcement is slow and uncertain. In addition, it is difficult to reduce and prepare for risks at the model level alone: the science of alignment, evaluations, risk analysis, and safeguards remains immature, and safety is not just a property of the model but also of the deployment contexts. The impacts of any risky open-weight models will also diffuse into Europe, due to their being freely downloadable, with risks being amplified further due to the fact that safety training can easily be removed from open-weight models.
Europe’s current safeguards and preparedness strategies will not be fit for purpose. Existing and planned approaches such as the EU Preparedness Union Strategy, the EU Action Plan on Cybersecurity and Artificial Intelligence, the EU AI Act’s systemic risk identification, assessment, and mitigation as well as serious incident reporting obligations, and the proposed Biotech Act will begin to strengthen Europe’s societal resilience. To be effective, they will need to be implemented well and consistently across Europe, protected from political dilution, and enforced decisively. However, even if this is achieved, these plans will not be sufficient to address the risks that Europe will face in a transformative AI scenario. Important elements of societal resilience (e.g. legal instruments, defensive programmes, institutional owners, or emergency plans) are lacking for all the AI-related risks discussed above. Where such elements are present, they have fundamental gaps,¹³ and have generally been designed for the current risk profile at best.
Addressing the challenge
Addressing the challenge
Transformative AI risks require extensive and urgent societal resilience programmes. Without urgent and intensive large-scale societal resilience and preparedness measures, transformative AI could tilt the balance in the cyber and bio risk landscape toward attackers rather than defenders, as well as leaving Europe vulnerable to other transformative AI risks, including loss of control scenarios. As a starting point, this requires implementing the EU’s recently announced Action Plan on Cybersecurity and Artificial Intelligence effectively, including by anticipating transformative AI cyber capabilities, and hardening critical infrastructure to AI cyberattacks. This should be accompanied by ambitious analogous CBRN and loss of control preparedness and resilience action plans. In addition, ambitious, ring-fenced funding must be made available for European AI resilience efforts in order to implement an extensive societal resilience programme successfully.
To be resilient, Europe has to improve its ability to prevent and respond to crises and emergencies. As more and more systemic risks materialise, the EU must commensurately increase its ability to anticipate, prevent, and respond to crises, emergencies, and severe impacts. This could involve building up reserves of resources and equipment that would be needed in a crisis, and updating and putting in place emergency response plans at the Member State and European level. To help with anticipated national security crises, information-sharing channels and cooperation should be set up between frontier AI experts and agencies and the national security and intelligence functions in government. Prioritising the enforcement of the AI Act’s serious incident reporting obligation for providers of general-purpose AI models posing systemic risk, and bolstering this with a separate voluntary channel for notifying the AI Office of events that do not qualify as a ‘serious incident’ would provide the AI Office with invaluable information regarding the real-world effects of advanced AI.
A societal resilience programme will require access to frontier AI capabilities. In order to identify vulnerabilities and shore up defences, Europe will need to negotiate and secure access to frontier AI capabilities (see Pillar 1, Objective 1.1). This means ensuring that plans are drawn up for securing structured access in these domains (as the Commission in coordination with ENISA has already been asked to do for cybersecurity under the Action Plan on Cybersecurity and Artificial Intelligence).
Eight concrete recommendations at the Union and national level that can help Europe achieve the immediate objective of ensuring resilience to AI crises can be found below. Detailed recommendations for each are provided in Part B of this strategy.
Transformative AI risks require extensive and urgent societal resilience programmes. Without urgent and intensive large-scale societal resilience and preparedness measures, transformative AI could tilt the balance in the cyber and bio risk landscape toward attackers rather than defenders, as well as leaving Europe vulnerable to other transformative AI risks, including loss of control scenarios. As a starting point, this requires implementing the EU’s recently announced Action Plan on Cybersecurity and Artificial Intelligence effectively, including by anticipating transformative AI cyber capabilities, and hardening critical infrastructure to AI cyberattacks. This should be accompanied by ambitious analogous CBRN and loss of control preparedness and resilience action plans. In addition, ambitious, ring-fenced funding must be made available for European AI resilience efforts in order to implement an extensive societal resilience programme successfully.
To be resilient, Europe has to improve its ability to prevent and respond to crises and emergencies. As more and more systemic risks materialise, the EU must commensurately increase its ability to anticipate, prevent, and respond to crises, emergencies, and severe impacts. This could involve building up reserves of resources and equipment that would be needed in a crisis, and updating and putting in place emergency response plans at the Member State and European level. To help with anticipated national security crises, information-sharing channels and cooperation should be set up between frontier AI experts and agencies and the national security and intelligence functions in government. Prioritising the enforcement of the AI Act’s serious incident reporting obligation for providers of general-purpose AI models posing systemic risk, and bolstering this with a separate voluntary channel for notifying the AI Office of events that do not qualify as a ‘serious incident’ would provide the AI Office with invaluable information regarding the real-world effects of advanced AI.
A societal resilience programme will require access to frontier AI capabilities. In order to identify vulnerabilities and shore up defences, Europe will need to negotiate and secure access to frontier AI capabilities (see Pillar 1, Objective 1.1). This means ensuring that plans are drawn up for securing structured access in these domains (as the Commission in coordination with ENISA has already been asked to do for cybersecurity under the Action Plan on Cybersecurity and Artificial Intelligence).
Eight concrete recommendations at the Union and national level that can help Europe achieve the immediate objective of ensuring resilience to AI crises can be found below. Detailed recommendations for each are provided in Part B of this strategy.
Recommendations at the Union level
Recommendations at the Union level
1.
Implement the Action Plan on Cybersecurity and Artificial Intelligence and develop corresponding CBRN and loss of control action plans. Successfully implement the Action Plan on Cybersecurity and AI by ensuring that funding, institutional ownership, clear deadlines, and structured access arrangements are implemented. Publish analogous action plans for AI CBRN and loss of control risks.
2.
Establish a channel for providers and affected parties to voluntarily notify the AI Office of AI incidents. Create a voluntary channel with an online portal through which the AI Office can be notified of AI incidents that may not qualify as a serious incident under Article 55 of the AI Act. This channel should be accessible for both AI providers and affected parties. Thorough follow-up assessments of incidents can be conducted where necessary.
3.
Strengthen cooperation between AI expertise and national security and intelligence authorities. Establish standing working channels between Member State AISIs, the EU AI Office, and security and intelligence agencies that have an agreed protocol for handling classified and commercially sensitive material. Collaboratively produce threat assessments for offensive cyber, CBRN, harmful manipulation, and loss of control AI risks.
4.
Establish a cross-programme European AI preparedness and resilience package in the 2028–2034 Multiannual Financial Framework and allow existing funds to be used for AI resilience measures. Ring-fence a €10 billion, cross-programme funding package for AI-specific preparedness and resilience. Member States should be able to draw on this package to implement measures addressing systemic risks. In the short term, the Commission should confirm that existing funding programmes can be used to fund AI-related resilience measures.
1.
Implement the Action Plan on Cybersecurity and Artificial Intelligence and develop corresponding CBRN and loss of control action plans. Successfully implement the Action Plan on Cybersecurity and AI by ensuring that funding, institutional ownership, clear deadlines, and structured access arrangements are implemented. Publish analogous action plans for AI CBRN and loss of control risks.
2.
Establish a channel for providers and affected parties to voluntarily notify the AI Office of AI incidents. Create a voluntary channel with an online portal through which the AI Office can be notified of AI incidents that may not qualify as a serious incident under Article 55 of the AI Act. This channel should be accessible for both AI providers and affected parties. Thorough follow-up assessments of incidents can be conducted where necessary.
3.
Strengthen cooperation between AI expertise and national security and intelligence authorities. Establish standing working channels between Member State AISIs, the EU AI Office, and security and intelligence agencies that have an agreed protocol for handling classified and commercially sensitive material. Collaboratively produce threat assessments for offensive cyber, CBRN, harmful manipulation, and loss of control AI risks.
4.
Establish a cross-programme European AI preparedness and resilience package in the 2028–2034 Multiannual Financial Framework and allow existing funds to be used for AI resilience measures. Ring-fence a €10 billion, cross-programme funding package for AI-specific preparedness and resilience. Member States should be able to draw on this package to implement measures addressing systemic risks. In the short term, the Commission should confirm that existing funding programmes can be used to fund AI-related resilience measures.
Recommendations at the national level
Recommendations at the national level
1.
Strengthen the biosecurity provisions in the EU Biotech Act. Member States should negotiate for stronger biosecurity measures in Biotech Act negotiations, for example, rapid updating of products in scope of know your customer (KYC) provisions, legal safe harbours for trusted third parties to stress-test synthesis screening.
2.
Build up reserves of resources and equipment necessary for responding to crises. Identify and procure physical resources that are likely to be scarce, slow or difficult to obtain, and essential in crises (e.g. protective equipment). Conduct supply chain assessments and tabletop exercises for critical infrastructure and emergency response.
3.
Strengthen critical national infrastructure against AI-enabled cyberattacks. Strengthen the implementation of the NIS2 Directive (Directive 2022/2555) by establishing programmes that harden essential services and critical infrastructure operators by giving access to cybersecurity expertise, highly capable AI models to identify and patch vulnerabilities, and other resources required.
4.
Include AI-enabled incidents in national and sector-specific emergency response plans. Ensure national emergency preparedness plans and sector-specific plans include AI-enabled incidents. These must include AI-enabled incidents (e.g. cyber offence, CBRN, loss of control) that could go beyond those previously considered in scope and magnitude of harm. They should specify clear chains of command, the legal basis for emergency measures, and the named Union-level contacts.
1.
Strengthen the biosecurity provisions in the EU Biotech Act. Member States should negotiate for stronger biosecurity measures in Biotech Act negotiations, for example, rapid updating of products in scope of know your customer (KYC) provisions, legal safe harbours for trusted third parties to stress-test synthesis screening.
2.
Build up reserves of resources and equipment necessary for responding to crises. Identify and procure physical resources that are likely to be scarce, slow or difficult to obtain, and essential in crises (e.g. protective equipment). Conduct supply chain assessments and tabletop exercises for critical infrastructure and emergency response.
3.
Strengthen critical national infrastructure against AI-enabled cyberattacks. Strengthen the implementation of the NIS2 Directive (Directive 2022/2555) by establishing programmes that harden essential services and critical infrastructure operators by giving access to cybersecurity expertise, highly capable AI models to identify and patch vulnerabilities, and other resources required.
4.
Include AI-enabled incidents in national and sector-specific emergency response plans. Ensure national emergency preparedness plans and sector-specific plans include AI-enabled incidents. These must include AI-enabled incidents (e.g. cyber offence, CBRN, loss of control) that could go beyond those previously considered in scope and magnitude of harm. They should specify clear chains of command, the legal basis for emergency measures, and the named Union-level contacts.
IO-5
Make Europe the global leader in AI assurance technology
IO-5
Make Europe the global leader in AI assurance technology
Transformative AI will likely be treated as a national security issue in addition to a commercial or scientific issue, meaning that the most advanced AI models and systems will demand robust secure access controls. In such a world, companies and governments will require assurance technology: technology that can facilitate the verification of claims made about AI models and systems and their infrastructure and ensure their security. Europe should lead the development of the underlying technology.
Transformative AI will likely be treated as a national security issue in addition to a commercial or scientific issue, meaning that the most advanced AI models and systems will demand robust secure access controls. In such a world, companies and governments will require assurance technology: technology that can facilitate the verification of claims made about AI models and systems and their infrastructure and ensure their security. Europe should lead the development of the underlying technology.
The challenge
The challenge
Without AI assurance technology, Europe’s institutions might not get privileged access to unreleased frontier AI models for proactive defensive purposes. Member States will likely want to use such models in defence, intelligence, and national security applications. Since there are restrictions on processing sensitive military and intelligence data outside of the EU, frontier models will need to be hosted on European compute. Moreover, Europe currently lacks assurance that those models are free of hidden backdoors or ‘secret loyalties’ that could compromise sensitive data. Finally, Europe is currently unable to demonstrate to foreign providers that data centres on EU soil have robust security measures in place to prevent model theft and sabotage, and that they are only using the provided model for intended purposes in order to allay developers’ concerns regarding the potential for misuse or exfiltration of these models. Absent such assurances, developers may be reluctant to host unreleased frontier models on EU soil for fear of exfiltration.
AI assurance technology could also be crucial for enforcing future international agreements. The arrival of transformative AI might prompt states and companies to make agreements about the safe and secure development and use of the technology. States might agree to restrict the proliferation of frontier AI models or hardware, or to pace or pause AI development (e.g. to ensure that external evaluators have enough time for safety testing). However, due to collective action problems, states and companies have greater incentives to make such agreements if they can be confident that other parties adhere to the agreement. Relying on trust alone is unlikely to be sufficient.
At the moment, it is not possible to verify claims about the safety and security of frontier AI technology and its use. Although some techniques for gaining visibility into AI development and deployment exist, they are not reliable enough to provide a high level of assurance. For example, many assurance mechanisms rely on the use of trusted execution environments,¹⁴ which can be vulnerable to attacks, especially if the attacker has physical access to the chip(s).
Without AI assurance technology, Europe’s institutions might not get privileged access to unreleased frontier AI models for proactive defensive purposes. Member States will likely want to use such models in defence, intelligence, and national security applications. Since there are restrictions on processing sensitive military and intelligence data outside of the EU, frontier models will need to be hosted on European compute. Moreover, Europe currently lacks assurance that those models are free of hidden backdoors or ‘secret loyalties’ that could compromise sensitive data. Finally, Europe is currently unable to demonstrate to foreign providers that data centres on EU soil have robust security measures in place to prevent model theft and sabotage, and that they are only using the provided model for intended purposes in order to allay developers’ concerns regarding the potential for misuse or exfiltration of these models. Absent such assurances, developers may be reluctant to host unreleased frontier models on EU soil for fear of exfiltration.
AI assurance technology could also be crucial for enforcing future international agreements. The arrival of transformative AI might prompt states and companies to make agreements about the safe and secure development and use of the technology. States might agree to restrict the proliferation of frontier AI models or hardware, or to pace or pause AI development (e.g. to ensure that external evaluators have enough time for safety testing). However, due to collective action problems, states and companies have greater incentives to make such agreements if they can be confident that other parties adhere to the agreement. Relying on trust alone is unlikely to be sufficient.
At the moment, it is not possible to verify claims about the safety and security of frontier AI technology and its use. Although some techniques for gaining visibility into AI development and deployment exist, they are not reliable enough to provide a high level of assurance. For example, many assurance mechanisms rely on the use of trusted execution environments,¹⁴ which can be vulnerable to attacks, especially if the attacker has physical access to the chip(s).
Addressing the challenge
Addressing the challenge
Europe should aim to foster a native pipeline of research and development of AI assurance technologies. This pipeline should run from early-stage research into novel assurance technologies, drawing on established European expertise in this area, to construction of large-scale secure and verifiable AI infrastructure and internationalisation with like-minded partners. Union and Member State institutions should make use of supply-side instruments, such as funding early-stage research, as well as demand-side signalling, such as joint pre-commercial procurement.
Large-scale research investments in assurance technology bets are needed. In order to develop AI infrastructure that is ‘secure by design, verifiable by default’, the European Commission should fund large-scale research investments across multiple fundamental technological research bets. These should be of the order of at least €250 million over the next five years. Promising directions include on-chip trusted execution environments hardened against physical attack; tamper-evident enclosures for AI chips; retrofittable secure modules that can add verification capabilities to existing accelerators; and privacy-preserving methods for verifying a chip’s workload. Whatever research vehicle is tasked with distributing funding should also be given latitude to support new and unexpected research efforts as the field evolves.
Promising research bets can be scaled into pilot projects in real-world contexts. Governments, in collaboration with industry, should implement pilot projects to scale the most promising mechanisms into real-world tests, built around concrete government use cases. Such potential use cases are broad, and might include verified AI deployment for public institutions, certified secure hosting of frontier model weights, and location attestation for imported AI chips. Concretely, the goal should be to develop the world’s first maximally secure data centre designed to withstand a Security Level 5 (SL5) equivalent threat model, as well as a separate maximally verifiable AI data centre.¹⁵
Europe should create demand for secure and verifiable assurance technology products. Governments should create demand for the products that result from these projects. ENISA and the Joint Research Centre (JRC) should collaborate to develop a tiered EU certification scheme for assured frontier AI compute, with computing facilities used for more sensitive workloads subject to stronger assurance requirements. Member States should also undertake pre-commercial procurement, whereby they commit to procure a prespecified amount of secure and/or verifiable capacity at a given tier of the Union-wide certification scheme.
Collaborative development with trusted international partners can increase trust. For assurance mechanisms to be applied to verifying adherence with international agreements, it is important that, to the extent possible, they are developed collaboratively and openly. States and companies may not trust unilaterally developed assurance technologies that they have limited visibility into. As such, European actors should work with international partners to co-develop and stress-test assurance measures.
Six concrete recommendations at the Union and national level that can help Europe achieve the immediate objective of leading the development of assurance technologies can be found below. Detailed recommendations for each are provided in Part B of this strategy.
Europe should aim to foster a native pipeline of research and development of AI assurance technologies. This pipeline should run from early-stage research into novel assurance technologies, drawing on established European expertise in this area, to construction of large-scale secure and verifiable AI infrastructure and internationalisation with like-minded partners. Union and Member State institutions should make use of supply-side instruments, such as funding early-stage research, as well as demand-side signalling, such as joint pre-commercial procurement.
Large-scale research investments in assurance technology bets are needed. In order to develop AI infrastructure that is ‘secure by design, verifiable by default’, the European Commission should fund large-scale research investments across multiple fundamental technological research bets. These should be of the order of at least €250 million over the next five years. Promising directions include on-chip trusted execution environments hardened against physical attack; tamper-evident enclosures for AI chips; retrofittable secure modules that can add verification capabilities to existing accelerators; and privacy-preserving methods for verifying a chip’s workload. Whatever research vehicle is tasked with distributing funding should also be given latitude to support new and unexpected research efforts as the field evolves.
Promising research bets can be scaled into pilot projects in real-world contexts. Governments, in collaboration with industry, should implement pilot projects to scale the most promising mechanisms into real-world tests, built around concrete government use cases. Such potential use cases are broad, and might include verified AI deployment for public institutions, certified secure hosting of frontier model weights, and location attestation for imported AI chips. Concretely, the goal should be to develop the world’s first maximally secure data centre designed to withstand a Security Level 5 (SL5) equivalent threat model, as well as a separate maximally verifiable AI data centre.¹⁵
Europe should create demand for secure and verifiable assurance technology products. Governments should create demand for the products that result from these projects. ENISA and the Joint Research Centre (JRC) should collaborate to develop a tiered EU certification scheme for assured frontier AI compute, with computing facilities used for more sensitive workloads subject to stronger assurance requirements. Member States should also undertake pre-commercial procurement, whereby they commit to procure a prespecified amount of secure and/or verifiable capacity at a given tier of the Union-wide certification scheme.
Collaborative development with trusted international partners can increase trust. For assurance mechanisms to be applied to verifying adherence with international agreements, it is important that, to the extent possible, they are developed collaboratively and openly. States and companies may not trust unilaterally developed assurance technologies that they have limited visibility into. As such, European actors should work with international partners to co-develop and stress-test assurance measures.
Six concrete recommendations at the Union and national level that can help Europe achieve the immediate objective of leading the development of assurance technologies can be found below. Detailed recommendations for each are provided in Part B of this strategy.
Recommendations at the Union level
Recommendations at the Union level
1.
Define Union-wide security and verifiability tiers for AI infrastructure. ENISA and the JRC should draft Union-wide assurance levels for both AI infrastructure security and verifiability. Publicly funded facilities intended for sensitive workloads should be certified to a defined tier. Facilities should be certified if they satisfy all the security and verifiability requirements of the specified Union-wide tier, without the need for additional national requirements.
2.
Fund and support fundamental research into assurance technologies. The Commission should create a research programme with at least €250 million of guaranteed funding over five years. Technical experts should work alongside programme managers to identify and make progress on important open technical challenges. They should be provided with autonomy and independence to identify research bets, as well as pivot away from them if insufficient progress is being made.
3.
Scale proofs of concept into real-world pilots. In collaboration with industrial, academic, and international partners, scale promising assurance technologies via pilot projects focused on concrete government use cases. The goal should be to stress test proposed mechanisms at scale, identifying assurance techniques that show promise for real-world deployment, feeding into the construction of separate maximally secure and verifiable data centres by 2028.
4.
Internationalise assurance technology. The Commission should partner with trusted international partners and initiatives, such as international AI safety institutes, or industry or academic projects, to run simulated red-teaming exercises of verification mechanisms.
1.
Define Union-wide security and verifiability tiers for AI infrastructure. ENISA and the JRC should draft Union-wide assurance levels for both AI infrastructure security and verifiability. Publicly funded facilities intended for sensitive workloads should be certified to a defined tier. Facilities should be certified if they satisfy all the security and verifiability requirements of the specified Union-wide tier, without the need for additional national requirements.
2.
Fund and support fundamental research into assurance technologies. The Commission should create a research programme with at least €250 million of guaranteed funding over five years. Technical experts should work alongside programme managers to identify and make progress on important open technical challenges. They should be provided with autonomy and independence to identify research bets, as well as pivot away from them if insufficient progress is being made.
3.
Scale proofs of concept into real-world pilots. In collaboration with industrial, academic, and international partners, scale promising assurance technologies via pilot projects focused on concrete government use cases. The goal should be to stress test proposed mechanisms at scale, identifying assurance techniques that show promise for real-world deployment, feeding into the construction of separate maximally secure and verifiable data centres by 2028.
4.
Internationalise assurance technology. The Commission should partner with trusted international partners and initiatives, such as international AI safety institutes, or industry or academic projects, to run simulated red-teaming exercises of verification mechanisms.
Recommendations at the national level
Recommendations at the national level
1.
Mutually recognise national secure cloud accreditations by mapping them onto the common EU assurance tiers. Member States should map national schemes, such as France's SecNumCloud, onto the Union-wide tiers, with mutual recognition and no additional national requirements. This will allow members to pool assured compute and facilitate adoption of secure technologies by giving providers a single route to Union-wide certification.
2.
Demonstrate demand for secure and verifiable AI infrastructure through joint innovation procurement. For sensitive AI workloads, Member States should aggregate their expected demand for assured infrastructure and issue forward purchasing commitments against it. This should be actioned through Pre-Commercial Procurement (PCP), followed by Public Procurement of Innovative Solutions (PPI) to purchase assured AI compute capacity when the technology comes to market.
1.
Mutually recognise national secure cloud accreditations by mapping them onto the common EU assurance tiers. Member States should map national schemes, such as France's SecNumCloud, onto the Union-wide tiers, with mutual recognition and no additional national requirements. This will allow members to pool assured compute and facilitate adoption of secure technologies by giving providers a single route to Union-wide certification.
2.
Demonstrate demand for secure and verifiable AI infrastructure through joint innovation procurement. For sensitive AI workloads, Member States should aggregate their expected demand for assured infrastructure and issue forward purchasing commitments against it. This should be actioned through Pre-Commercial Procurement (PCP), followed by Public Procurement of Innovative Solutions (PPI) to purchase assured AI compute capacity when the technology comes to market.
Footnotes
Not all technical or AI expertise can be treated as sufficient since it may fail to bring the understanding of the fast-moving nature, scale of change, and unique risks that governing transformative AI will require.
Not all technical or AI expertise can be treated as sufficient since it may fail to bring the understanding of the fast-moving nature, scale of change, and unique risks that governing transformative AI will require.
As a comparison, OpenAI advertises base salaries of $250k to $445k for research scientists, the midpoint of which is comparable to the basic salary of a Director-General in the Commission. Equity packages for research scientists are reported to be at least as large as base salaries. Europe’s institutions would only be able to pay a fraction of the million-dollar compensation packages that frontier AI companies routinely offer leading technical experts.
As a comparison, OpenAI advertises base salaries of $250k to $445k for research scientists, the midpoint of which is comparable to the basic salary of a Director-General in the Commission. Equity packages for research scientists are reported to be at least as large as base salaries. Europe’s institutions would only be able to pay a fraction of the million-dollar compensation packages that frontier AI companies routinely offer leading technical experts.
Epoch AI reports an EU share of 4.8% in March 2025. The more recent Europe 2031 compute forecast estimates a 4.7% share in Europe by the end of 2026. The Europe 2031 figure includes non-EU countries such as the UK and Norway, suggesting that the EU share is somewhat lower.
Epoch AI reports an EU share of 4.8% in March 2025. The more recent Europe 2031 compute forecast estimates a 4.7% share in Europe by the end of 2026. The Europe 2031 figure includes non-EU countries such as the UK and Norway, suggesting that the EU share is somewhat lower.
CADA assumes, based on a study by Technopolis Group and others, that the EU has a total data centre capacity of 12.4 GW in 2025 (including both AI and non-AI data centres). Assuming around 31 GW of total AI compute capacity by the end of 2025 and an EU share of around 5% implies that the EU hosted around 1.5 GW of AI compute in 2025. If the EU tripled its overall data centre capacity from 12.4 GW to 37.2 GW by 2030, and we assume – unrealistically – that the 24.8 GW of new capacity are used exclusively for AI workloads, the EU’s total AI capacity would constitute 26.3 GW. Since CADA estimates IT load, a 1.1x PUE multiplier can be used to convert this into 28.9 GW of total facility power, which would constitute less than 10% of the expected global supply of 300 GW by 2030. Given that not all data centres to be built in subsequent years will host AI workloads, the actual share can be expected to be lower – likely closer to this strategy's default estimate of around 5% without ambitious political intervention.
CADA assumes, based on a study by Technopolis Group and others, that the EU has a total data centre capacity of 12.4 GW in 2025 (including both AI and non-AI data centres). Assuming around 31 GW of total AI compute capacity by the end of 2025 and an EU share of around 5% implies that the EU hosted around 1.5 GW of AI compute in 2025. If the EU tripled its overall data centre capacity from 12.4 GW to 37.2 GW by 2030, and we assume – unrealistically – that the 24.8 GW of new capacity are used exclusively for AI workloads, the EU’s total AI capacity would constitute 26.3 GW. Since CADA estimates IT load, a 1.1x PUE multiplier can be used to convert this into 28.9 GW of total facility power, which would constitute less than 10% of the expected global supply of 300 GW by 2030. Given that not all data centres to be built in subsequent years will host AI workloads, the actual share can be expected to be lower – likely closer to this strategy's default estimate of around 5% without ambitious political intervention.
In a crisis mobilisation scenario, policymakers would unlock additional AI compute capacity mainly via flexible grid connections for AI data centres and shifting electricity demand away from use cases such as hydrogen production towards AI data centres. In this scenario, the markets named above plus the UK and Norway could together connect 47.6 GW by 2030.
In a crisis mobilisation scenario, policymakers would unlock additional AI compute capacity mainly via flexible grid connections for AI data centres and shifting electricity demand away from use cases such as hydrogen production towards AI data centres. In this scenario, the markets named above plus the UK and Norway could together connect 47.6 GW by 2030.
Epoch AI estimates that 1 GW of IT load costs slightly below $38 billion of capital expenditure for an AI data centre. Assuming a PUE (power usage effectiveness) of 1.1, this translates into $34.3 billion per 1 GW of total facility power. At current exchange rates, the total investment of $1.55 trillion would correspond to approximately €1.3 trillion.
Epoch AI estimates that 1 GW of IT load costs slightly below $38 billion of capital expenditure for an AI data centre. Assuming a PUE (power usage effectiveness) of 1.1, this translates into $34.3 billion per 1 GW of total facility power. At current exchange rates, the total investment of $1.55 trillion would correspond to approximately €1.3 trillion.
Korea’s 550 trillion won investment by 2029 is a 19.7% share of its 2026 nominal GDP of 2,788 trillion won, or approximately 6.6% per year when averaged over 2027–29. The proposed EU investment of $1.55 trillion by 2030 would be a 6.7% share of its 2026 nominal GDP of $23.03 trillion, or approximately 2.2% per year when averaged over 2027–29.
Korea’s 550 trillion won investment by 2029 is a 19.7% share of its 2026 nominal GDP of 2,788 trillion won, or approximately 6.6% per year when averaged over 2027–29. The proposed EU investment of $1.55 trillion by 2030 would be a 6.7% share of its 2026 nominal GDP of $23.03 trillion, or approximately 2.2% per year when averaged over 2027–29.
A systemic risk is a risk that is “specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain” (Article 3(65) AI Act). The GPAI Code of Practice specifies four systemic risks (cyber offence, CBRN weapons, loss of control, and harmful manipulation) and gives further information about what characterises them.
A systemic risk is a risk that is “specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain” (Article 3(65) AI Act). The GPAI Code of Practice specifies four systemic risks (cyber offence, CBRN weapons, loss of control, and harmful manipulation) and gives further information about what characterises them.
The General-Purpose AI Code of Practice, in its Safety and Security Chapter defines loss of control as the “risks from humans losing the ability to reliably direct, modify, or shut down a model.” This could be the result of “misalignment with human intent or values, self-reasoning, self-replication, self-improvement, deception, resistance to goal modification, power-seeking behaviour, or autonomously creating or improving AI models or AI systems.” For an introduction to and overview of the concept of loss of control, see the International AI Safety Report.
The General-Purpose AI Code of Practice, in its Safety and Security Chapter defines loss of control as the “risks from humans losing the ability to reliably direct, modify, or shut down a model.” This could be the result of “misalignment with human intent or values, self-reasoning, self-replication, self-improvement, deception, resistance to goal modification, power-seeking behaviour, or autonomously creating or improving AI models or AI systems.” For an introduction to and overview of the concept of loss of control, see the International AI Safety Report.
AI-driven attacks or targeting of government agencies, technology and financial institutions, software supply chains, healthcare and emergency services, and critical infrastructure have already been reported.
AI-driven attacks or targeting of government agencies, technology and financial institutions, software supply chains, healthcare and emergency services, and critical infrastructure have already been reported.
For example, the Preparedness Union Strategy does not mention AI even though it tries to put into place emergency coordination for cyber and bio risks, amongst others.
For example, the Preparedness Union Strategy does not mention AI even though it tries to put into place emergency coordination for cyber and bio risks, amongst others.
Trusted execution environments (TEEs) are secure parts of chips that are isolated from the rest of the chip and can provide guarantees regarding the integrity, security, and confidentiality of any code or data stored or executed on that chip.
Trusted execution environments (TEEs) are secure parts of chips that are isolated from the rest of the chip and can provide guarantees regarding the integrity, security, and confidentiality of any code or data stored or executed on that chip.
Security and verifiability place competing demands on facility design. Since it is currently unclear if one facility can meet requirements across both dimensions, the initial target is two separate facilities.
Security and verifiability place competing demands on facility design. Since it is currently unclear if one facility can meet requirements across both dimensions, the initial target is two separate facilities.
Additional objectives
Additional objectives
Pillar 1: Securing access to frontier AI
O1.1
Secure ongoing access to frontier AI systems
O1.1
Secure ongoing access to frontier AI systems
In a world with transformative AI, Europe’s prosperity, security, and sovereignty will depend on access to frontier AI models. Recent changes in availability, such as the export controls on Anthropic’s most capable models, illustrate that Europe could lose its frontier AI access overnight. Europe should therefore use ‘compute for access’ deals to exchange attractive data centre sites for contractually agreed frontier model access, underwritten by contractual guarantees backstopped by physical leverage.
In a world with transformative AI, Europe’s prosperity, security, and sovereignty will depend on access to frontier AI models. Recent changes in availability, such as the export controls on Anthropic’s most capable models, illustrate that Europe could lose its frontier AI access overnight. Europe should therefore use ‘compute for access’ deals to exchange attractive data centre sites for contractually agreed frontier model access, underwritten by contractual guarantees backstopped by physical leverage.
The challenge
The challenge
In a world with transformative AI, access to frontier capabilities will be critical for economic prosperity and national security. While frontier models are unlikely to be needed for all use cases, they will confer crucial advantages in all areas with a high return on intelligence. In most organisations, at least some tasks will satisfy this condition. For example, while some routine applications in manufacturing are well-served by smaller models, transformative AI will be able to help with more complex tasks, such as strategic planning, which benefit from the highest level of intelligence available. Moreover, as transformative AI would plausibly accelerate AI progress even more, even a few-month gap between frontier and fast-follower models would translate into an increasing gap in performance. Being able to access frontier capabilities somewhat earlier than one’s competitors or adversaries could then translate into lasting advantages: for example in drug discovery, where better models may help firms identify valuable molecules earlier, or in cybersecurity, where defenders using weaker systems could be vulnerable to attackers with stronger ones.
Recent developments show that Europe cannot count on frontier capabilities being broadly available. In April 2026, Anthropic released Mythos, an AI model with state-of-the-art cyber capabilities, initially only to selected US organisations. In June, the US government temporarily restricted access for foreign nationals to Anthropic’s frontier models (see Figure 6). China is reportedly considering similar restrictions on its most advanced models. These decisions appear to be primarily driven by security concerns. Another factor is that AI companies are currently compute-constrained rather than demand-constrained: they do not have enough computing power to serve AI models at competitive prices to everyone who would like to use them. If compute scarcity persists, foreign AI companies may do well economically by selling only to domestic customers, or to priority customers in selected allied countries, to which European countries may not belong. Counting on open-weight models is also a risky bet: they lag behind the performance of frontier models by several months, and governments are likely to restrict their proliferation as the potential to misuse them increases.
In a world with transformative AI, access to frontier capabilities will be critical for economic prosperity and national security. While frontier models are unlikely to be needed for all use cases, they will confer crucial advantages in all areas with a high return on intelligence. In most organisations, at least some tasks will satisfy this condition. For example, while some routine applications in manufacturing are well-served by smaller models, transformative AI will be able to help with more complex tasks, such as strategic planning, which benefit from the highest level of intelligence available. Moreover, as transformative AI would plausibly accelerate AI progress even more, even a few-month gap between frontier and fast-follower models would translate into an increasing gap in performance. Being able to access frontier capabilities somewhat earlier than one’s competitors or adversaries could then translate into lasting advantages: for example in drug discovery, where better models may help firms identify valuable molecules earlier, or in cybersecurity, where defenders using weaker systems could be vulnerable to attackers with stronger ones.
Recent developments show that Europe cannot count on frontier capabilities being broadly available. In April 2026, Anthropic released Mythos, an AI model with state-of-the-art cyber capabilities, initially only to selected US organisations. In June, the US government temporarily restricted access for foreign nationals to Anthropic’s frontier models (see Figure 6). China is reportedly considering similar restrictions on its most advanced models. These decisions appear to be primarily driven by security concerns. Another factor is that AI companies are currently compute-constrained rather than demand-constrained: they do not have enough computing power to serve AI models at competitive prices to everyone who would like to use them. If compute scarcity persists, foreign AI companies may do well economically by selling only to domestic customers, or to priority customers in selected allied countries, to which European countries may not belong. Counting on open-weight models is also a risky bet: they lag behind the performance of frontier models by several months, and governments are likely to restrict their proliferation as the potential to misuse them increases.
Figure 06
Timeline of European access to Anthropic's frontier models. European organisations did not initially have access to Mythos, a frontier model with advanced cyber capabilities. Only a few days after ENISA had gained temporary access, the US government restricted access for all foreign nationals (authors' compilation based on Nextgov, 2026; Yahoo Finance, 2026).
Figure 06
Timeline of European access to Anthropic's frontier models. European organisations did not initially have access to Mythos, a frontier model with advanced cyber capabilities. Only a few days after ENISA had gained temporary access, the US government restricted access for all foreign nationals (authors' compilation based on Nextgov, 2026; Yahoo Finance, 2026).
Addressing the challenge
Addressing the challenge
Europe should tie data centre buildout to guaranteed frontier AI access via ‘compute for access’ deals. Compute-constrained AI companies are scrambling for locations where they can quickly build and energise data centres. Many European regions are well-suited for this, due to having either cheap, abundant energy (e.g. France, Nordics, Iberia) or decommissioned industrial sites with existing, GW-scale grid connections (e.g. Germany, Poland). If Member States accelerate the permitting and grid connection process, these regions could offer highly attractive data centre sites to foreign AI companies (see Immediate Objective 3). If a company builds there, the host country should ask in return for contractually agreed access to this company’s frontier models, on par with customers or even restricted programmes in the company’s home country. The agreement would include concrete provisions in case of breach of contract, such as the termination of favourable energy supply or the repurposing of deployed chips, enforceable only if the deal partners renege on their part of the access provision. Such agreements are much more durable than anything in the status quo: An AI company that has invested tens of billions of euros in a data centre on EU soil has every incentive to respect the agreement, and even to lobby its own government to ensure continued allied frontier AI access.
Europe should tie data centre buildout to guaranteed frontier AI access via ‘compute for access’ deals. Compute-constrained AI companies are scrambling for locations where they can quickly build and energise data centres. Many European regions are well-suited for this, due to having either cheap, abundant energy (e.g. France, Nordics, Iberia) or decommissioned industrial sites with existing, GW-scale grid connections (e.g. Germany, Poland). If Member States accelerate the permitting and grid connection process, these regions could offer highly attractive data centre sites to foreign AI companies (see Immediate Objective 3). If a company builds there, the host country should ask in return for contractually agreed access to this company’s frontier models, on par with customers or even restricted programmes in the company’s home country. The agreement would include concrete provisions in case of breach of contract, such as the termination of favourable energy supply or the repurposing of deployed chips, enforceable only if the deal partners renege on their part of the access provision. Such agreements are much more durable than anything in the status quo: An AI company that has invested tens of billions of euros in a data centre on EU soil has every incentive to respect the agreement, and even to lobby its own government to ensure continued allied frontier AI access.
Figure 07
Compute for access deals. ‘Compute for access’ deals trade data centre sites for access to foreign frontier models, underwritten by physical control over the data centre as physical leverage.
Figure 07
Compute for access deals. ‘Compute for access’ deals trade data centre sites for access to foreign frontier models, underwritten by physical control over the data centre as physical leverage.
The ‘compute for access’ strategy opts for managed dependency, because the alternatives are much costlier or worse. Securing access to frontier models by trying to build them in Europe would require hundreds of billions of euros, with an uncertain chance of success (see the section on a European frontier project). And while ‘compute for access’ does not eliminate the risk of a cut-off – for example, if a foreign government forces its companies to restrict access, either as a form of leverage or from genuine national security concerns – it clearly reduces the risk compared to a scenario where frontier models are accessed through foreign data centres outside European jurisdiction. To mitigate the remaining risk, Europe should become a trusted and secure importer (see Immediate Objective 5), build up anti-coercion capacity (see Immediate Objective 1) and rely on multi-vendor arrangements, portability requirements, and a European fast-follower model as a fallback option.
The window for action is closing fast. Data centres take years to permit, build, and energise. Once foreign AI companies have secured enough capacity elsewhere, either in their own country or in non-European partner countries, Europe’s bargaining position will have considerably weakened. Going forward, data centre investment from foreign AI companies should be tied to guaranteed access parity, before other countries make such deals first.
Five concrete recommendations at the Union and national level that can help Europe secure ongoing access to frontier AI systems can be found below. Detailed recommendations for each are provided in Part B of this strategy.
The ‘compute for access’ strategy opts for managed dependency, because the alternatives are much costlier or worse. Securing access to frontier models by trying to build them in Europe would require hundreds of billions of euros, with an uncertain chance of success (see the section on a European frontier project). And while ‘compute for access’ does not eliminate the risk of a cut-off – for example, if a foreign government forces its companies to restrict access, either as a form of leverage or from genuine national security concerns – it clearly reduces the risk compared to a scenario where frontier models are accessed through foreign data centres outside European jurisdiction. To mitigate the remaining risk, Europe should become a trusted and secure importer (see Immediate Objective 5), build up anti-coercion capacity (see Immediate Objective 1) and rely on multi-vendor arrangements, portability requirements, and a European fast-follower model as a fallback option.
The window for action is closing fast. Data centres take years to permit, build, and energise. Once foreign AI companies have secured enough capacity elsewhere, either in their own country or in non-European partner countries, Europe’s bargaining position will have considerably weakened. Going forward, data centre investment from foreign AI companies should be tied to guaranteed access parity, before other countries make such deals first.
Five concrete recommendations at the Union and national level that can help Europe secure ongoing access to frontier AI systems can be found below. Detailed recommendations for each are provided in Part B of this strategy.
Recommendations at the Union level
Recommendations at the Union level
1.
Require model portability and multi-vendor terms in public AI procurement. Avoid governments being locked into a single AI provider, for example by inserting portability and strengthening multi-vendor provisions into the proposed Cloud and AI Development Act.
2.
Fund a collective fast-follower model and European-only high-security hosting. Create a funding channel to develop a collective European fast-follower model and select a group of European-only hosting sites that are EU-owned and -operated and certified to CADA Assurance Level 4 or equivalent.
3.
Certify Europe as a secure importer and coordinate distillation enforcement. Establish a Europe-wide certification for the secure hosting of frontier models, benchmarked to the security standards of frontier AI companies and the US government. Harmonise national enforcement against model distillation to alleviate foreign AI developers’ security concerns about hosting in Europe.
1.
Require model portability and multi-vendor terms in public AI procurement. Avoid governments being locked into a single AI provider, for example by inserting portability and strengthening multi-vendor provisions into the proposed Cloud and AI Development Act.
2.
Fund a collective fast-follower model and European-only high-security hosting. Create a funding channel to develop a collective European fast-follower model and select a group of European-only hosting sites that are EU-owned and -operated and certified to CADA Assurance Level 4 or equivalent.
3.
Certify Europe as a secure importer and coordinate distillation enforcement. Establish a Europe-wide certification for the secure hosting of frontier models, benchmarked to the security standards of frontier AI companies and the US government. Harmonise national enforcement against model distillation to alleviate foreign AI developers’ security concerns about hosting in Europe.
Recommendations at the national level
Recommendations at the national level
1.
Tie compute buildout to contractual access guarantees. Treat large data centre sites, energy, and grid connections as strategic assets, to be made available to foreign AI companies only with contractual access guarantees, such as model access on par with customers in the company’s home country or European access to limited rollout programmes. Make contractually assured access guarantees enforceable through contractual penalties integrated into the deal structure.
2.
Implement secure-importer standards nationally. Raise standards for AI data centre security up to the level demanded by foreign AI companies and governments, including through know-your-customer regimes and national enforcement against model distillation attacks.
1.
Tie compute buildout to contractual access guarantees. Treat large data centre sites, energy, and grid connections as strategic assets, to be made available to foreign AI companies only with contractual access guarantees, such as model access on par with customers in the company’s home country or European access to limited rollout programmes. Make contractually assured access guarantees enforceable through contractual penalties integrated into the deal structure.
2.
Implement secure-importer standards nationally. Raise standards for AI data centre security up to the level demanded by foreign AI companies and governments, including through know-your-customer regimes and national enforcement against model distillation attacks.
O1.2
Protect European assets
O1.2
Protect European assets
Europe holds several assets that could matter enormously in a world with transformative AI. However, these assets are currently insufficiently protected from foreign acquisition. Europe should protect its AI and semiconductor assets through investment screenings with sufficient enforcement capacity, while ensuring that at-risk European companies can flourish without foreign capital.
Europe holds several assets that could matter enormously in a world with transformative AI. However, these assets are currently insufficiently protected from foreign acquisition. Europe should protect its AI and semiconductor assets through investment screenings with sufficient enforcement capacity, while ensuring that at-risk European companies can flourish without foreign capital.
The challenge
The challenge
Europe controls valuable assets, but could lose control over them in several ways. Several European assets confer relevant leverage in a transformative AI scenario, for example world-leading chipmaking equipment such as ASML’s EUV lithography machines and critical suppliers such as Zeiss (optics) and Trumpf (lasers), frontier-adjacent AI developers such as Mistral and Black Forest Labs, or high-value proprietary datasets in areas such as manufacturing or healthcare. These assets are not just sources of economic value, but also of strategic leverage that could be used to secure European access to frontier AI and related technology. However, this leverage could wane in several ways, most importantly through (i) inbound investment, when a foreign investor acquires a European asset, and (ii) outbound investment, when a European company moves sensitive technology, know-how, or capital abroad.¹⁶
Europe controls valuable assets, but could lose control over them in several ways. Several European assets confer relevant leverage in a transformative AI scenario, for example world-leading chipmaking equipment such as ASML’s EUV lithography machines and critical suppliers such as Zeiss (optics) and Trumpf (lasers), frontier-adjacent AI developers such as Mistral and Black Forest Labs, or high-value proprietary datasets in areas such as manufacturing or healthcare. These assets are not just sources of economic value, but also of strategic leverage that could be used to secure European access to frontier AI and related technology. However, this leverage could wane in several ways, most importantly through (i) inbound investment, when a foreign investor acquires a European asset, and (ii) outbound investment, when a European company moves sensitive technology, know-how, or capital abroad.¹⁶
Figure 08
European semiconductor assets. European companies hold several (near-)monopolies in the supply chain for advanced AI chips. Source: CSET
Figure 08
European semiconductor assets. European companies hold several (near-)monopolies in the supply chain for advanced AI chips. Source: CSET
Europe’s assets are insufficiently protected against foreign acquisition. Europe can only negotiate with the assets that it controls and protects. This does not mean that it should aim for economic autarky, as foreign investment and cross-border technology cooperation with allied countries is generally beneficial. However, Europe should be able to intervene where losing control over a technology, research capability, data, or know-how would materially weaken European economic security and bargaining power. Currently, Europe is not well prepared to do this: while inbound screening is largely built, many critical elements of the AI stack are not consistently screened, and even when a risky acquisition is blocked, there may be no European capital to step in (see Objective 2.1). Critically, unlike the US or China, for instance, EU Member States currently conduct almost no outbound investment screening.
Europe’s assets are insufficiently protected against foreign acquisition. Europe can only negotiate with the assets that it controls and protects. This does not mean that it should aim for economic autarky, as foreign investment and cross-border technology cooperation with allied countries is generally beneficial. However, Europe should be able to intervene where losing control over a technology, research capability, data, or know-how would materially weaken European economic security and bargaining power. Currently, Europe is not well prepared to do this: while inbound screening is largely built, many critical elements of the AI stack are not consistently screened, and even when a risky acquisition is blocked, there may be no European capital to step in (see Objective 2.1). Critically, unlike the US or China, for instance, EU Member States currently conduct almost no outbound investment screening.
Addressing the challenge
Addressing the challenge
Member States should create a framework for outbound investment screening. Member States should establish an outbound investment review. At Union level, an annual reporting cycle and a common template should be agreed by recommendation now, with a regulation modelled on the 2019 inbound framework to follow. At national level, Member States holding strategic AI and semiconductor assets should begin implementing outbound investment controls as soon as possible, designed so they can later be aligned with a Union framework.
Member States should extend the scope of inbound investment screening. Member States holding critical AI-stack assets should widen the scope of their national inbound screening to critical AI and semiconductor assets currently not covered, such as strategic datasets, the servicing of semiconductor manufacturing equipment, submarine fibre-optic cables, or high-voltage grid equipment, including large power transformers. The EU’s 2026 inbound foreign direct investment (FDI) screening regulation permits extension beyond the mandatory minimum.
An anti-capture facility should provide emergency capital for strategic European assets. Europe should build an anti-capture facility for European AI and semiconductor companies. Such a facility would be able to quickly mobilise public and private capital to keep a strategic asset under European control when it is at imminent risk of being acquired by a foreign party. Member States should only activate it in exceptional cases, rather than create a permanent subsidy for struggling companies.
Five concrete recommendations at the Union and national level that can help Europe protect its assets can be found below. Detailed recommendations for each are provided in Part B of this strategy.
Member States should create a framework for outbound investment screening. Member States should establish an outbound investment review. At Union level, an annual reporting cycle and a common template should be agreed by recommendation now, with a regulation modelled on the 2019 inbound framework to follow. At national level, Member States holding strategic AI and semiconductor assets should begin implementing outbound investment controls as soon as possible, designed so they can later be aligned with a Union framework.
Member States should extend the scope of inbound investment screening. Member States holding critical AI-stack assets should widen the scope of their national inbound screening to critical AI and semiconductor assets currently not covered, such as strategic datasets, the servicing of semiconductor manufacturing equipment, submarine fibre-optic cables, or high-voltage grid equipment, including large power transformers. The EU’s 2026 inbound foreign direct investment (FDI) screening regulation permits extension beyond the mandatory minimum.
An anti-capture facility should provide emergency capital for strategic European assets. Europe should build an anti-capture facility for European AI and semiconductor companies. Such a facility would be able to quickly mobilise public and private capital to keep a strategic asset under European control when it is at imminent risk of being acquired by a foreign party. Member States should only activate it in exceptional cases, rather than create a permanent subsidy for struggling companies.
Five concrete recommendations at the Union and national level that can help Europe protect its assets can be found below. Detailed recommendations for each are provided in Part B of this strategy.
Recommendations at the Union level
Recommendations at the Union level
1.
Adopt an outbound-investment regulation. Establish the legal framework in a directly applicable regulation modelled on the 2019 FDI inbound screening regulation (Regulation (EU) 2019/452), with binding information duties for Member States, including a statutory right to ask and annual reporting, alongside a cooperation mechanism to catch transactions that no Member State is reviewing yet.
2.
Make the outbound-investment review annual and comparable. Convert the one-off exercise under Recommendation (EU) 2025/63 into a recurring annual assessment with a fixed reporting date and a common template. The Commission should publish a comparative report showing cross-border patterns and divergences between national approaches.
1.
Adopt an outbound-investment regulation. Establish the legal framework in a directly applicable regulation modelled on the 2019 FDI inbound screening regulation (Regulation (EU) 2019/452), with binding information duties for Member States, including a statutory right to ask and annual reporting, alongside a cooperation mechanism to catch transactions that no Member State is reviewing yet.
2.
Make the outbound-investment review annual and comparable. Convert the one-off exercise under Recommendation (EU) 2025/63 into a recurring annual assessment with a fixed reporting date and a common template. The Commission should publish a comparative report showing cross-border patterns and divergences between national approaches.
Recommendations at the national level
Recommendations at the national level
1.
Implement national outbound-investment controls. Member States holding strategic AI-stack assets should legislate now rather than wait for the Union. To keep the burden on companies low, Member States should establish a narrow prohibited category and a broader notification duty. One to three additional staff per Member State should cover the work.
2.
Extend the scope of national inbound FDI screening. Article 4(16) of Regulation (EU) 2026/1386 lets Member States screen beyond the mandatory minimum, and the national statutes being drafted before January 2028 are the moment to use it. The extension should cover, among other assets, specialised security-relevant AI systems, the servicing of semiconductor manufacturing equipment, equipment on which critical digital infrastructure depends, strategic datasets as well as AI data centres.
3.
Name a national buyer of last resort for strategic assets. Member States holding AI-stack assets should give an existing public bank a standing mandate, committed callable capacity, a confidential list of qualifying assets, and a statutory channel from the screening authority to prevent domestic companies from being undercapitalised after the government vetoed an acquisition.
1.
Implement national outbound-investment controls. Member States holding strategic AI-stack assets should legislate now rather than wait for the Union. To keep the burden on companies low, Member States should establish a narrow prohibited category and a broader notification duty. One to three additional staff per Member State should cover the work.
2.
Extend the scope of national inbound FDI screening. Article 4(16) of Regulation (EU) 2026/1386 lets Member States screen beyond the mandatory minimum, and the national statutes being drafted before January 2028 are the moment to use it. The extension should cover, among other assets, specialised security-relevant AI systems, the servicing of semiconductor manufacturing equipment, equipment on which critical digital infrastructure depends, strategic datasets as well as AI data centres.
3.
Name a national buyer of last resort for strategic assets. Member States holding AI-stack assets should give an existing public bank a standing mandate, committed callable capacity, a confidential list of qualifying assets, and a statutory channel from the screening authority to prevent domestic companies from being undercapitalised after the government vetoed an acquisition.
Footnotes
This could also happen through less visible channels that do not appear as conventional acquisitions, such as research collaboration (e.g. joint laboratories, visiting researchers, PhD placements), a topic not covered here.
This could also happen through less visible channels that do not appear as conventional acquisitions, such as research collaboration (e.g. joint laboratories, visiting researchers, PhD placements), a topic not covered here.
Pillar 2: Building economic strength
O2.1
Make Europe the best place to build and scale high-growth companies
O2.1
Make Europe the best place to build and scale high-growth companies
In a world with transformative AI, companies that adopt AI well will be able to grow fast and generate enormous value. Europe cannot afford for such companies to be built and scaled elsewhere. Since it is hard to predict where transformative AI will create most of its value, supply-side reform to improve economic conditions across the board is especially important.
In a world with transformative AI, companies that adopt AI well will be able to grow fast and generate enormous value. Europe cannot afford for such companies to be built and scaled elsewhere. Since it is hard to predict where transformative AI will create most of its value, supply-side reform to improve economic conditions across the board is especially important.
The challenge
The challenge
Europe is already starting from behind. US startups grow faster and larger than their European counterparts, while much of Europe’s market value remains concentrated in companies over 50 years old (see Figure 9). The US also benefits from deeper capital markets and stronger technology clusters. China has similarly built a strong ecosystem for tech companies to grow, combining large public investment with a vast domestic market. The EU has recognised this problem – the Startup and Scaleup Strategy and the EU Inc. proposal address real barriers – but the response is neither ambitious nor fast enough for a world with transformative AI.
Europe is already starting from behind. US startups grow faster and larger than their European counterparts, while much of Europe’s market value remains concentrated in companies over 50 years old (see Figure 9). The US also benefits from deeper capital markets and stronger technology clusters. China has similarly built a strong ecosystem for tech companies to grow, combining large public investment with a vast domestic market. The EU has recognised this problem – the Startup and Scaleup Strategy and the EU Inc. proposal address real barriers – but the response is neither ambitious nor fast enough for a world with transformative AI.
Figure 09
Market capitalisation of firms in the US and EU. Young US companies account for over $40 trillion in market value, against roughly $5 trillion in the EU. Source: IMF
Figure 09
Market capitalisation of firms in the US and EU. Young US companies account for over $40 trillion in market value, against roughly $5 trillion in the EU. Source: IMF
Transformative AI could make Europe’s competitiveness gap much more consequential.
General-purpose technologies create their largest gains when companies reorganise around them rather than force them into existing processes. AI-native startups can do this from day one, allowing relatively small, easy-to-relocate companies to reach global scale extraordinarily quickly. If such ‘superstar’ companies concentrate in the US or China due to better economic conditions, this could have outsized consequences for Europe, as their location would increasingly decide where tax revenues and strategic capabilities accumulate. These effects could be hard to reverse, as AI-induced productivity gaps between world regions could make catch-up growth very difficult. If transformative AI arrives within the next few years, this would leave Europe little time to address its existing weaknesses before they harden into a potentially irreversible loss of economic and fiscal power.
Transformative AI could make Europe’s competitiveness gap much more consequential.
General-purpose technologies create their largest gains when companies reorganise around them rather than force them into existing processes. AI-native startups can do this from day one, allowing relatively small, easy-to-relocate companies to reach global scale extraordinarily quickly. If such ‘superstar’ companies concentrate in the US or China due to better economic conditions, this could have outsized consequences for Europe, as their location would increasingly decide where tax revenues and strategic capabilities accumulate. These effects could be hard to reverse, as AI-induced productivity gaps between world regions could make catch-up growth very difficult. If transformative AI arrives within the next few years, this would leave Europe little time to address its existing weaknesses before they harden into a potentially irreversible loss of economic and fiscal power.
Addressing the challenge
Addressing the challenge
Europe should become the place that potential superstar companies choose to locate in. This requires addressing many different issues simultaneously. Europe needs to deepen its capital markets, so that firms with high-growth potential can finance their next growth phase in Europe. This can be achieved through channelling voluntary commercial investment commitments into European growth markets (e.g., Tibi/WIN-style initiatives) on the national and EU level. Regulators should enable pension funds and other institutional investors to invest into growth assets while maintaining their fiduciary duties. To create a strong financial ecosystem for European firms to go public, Europe should develop a leading focal listing hub, where liquidity and expertise can quickly concentrate.
However, reforms need to go beyond fixing capital supply and also address challenges related to R&D, procurement, talent, and market fragmentation. Europe needs to create better conditions for highly innovative firms to be built and scaled in the first place. This requires a broad set of reforms: increasing the productivity of European science and R&D, solving market failures of insufficient early demand for innovative technology, and improving the position in the global market for talent. Finally, Europe should work to remove Single Market barriers that prevent small firms from scaling.
Europe should become the best place in the world for translating good ideas into progress. For this, research systems need to become more productive. New research organisations that are focused on creating scientific breakthroughs should be funded. Europe can build leverage of its broad public research funding by investing into the development of new scientific tools and other frontier research infrastructure (such as self-driving labs) that can boost the productivity of science as a whole. Performance-based defence procurement and tailored support for first-of-a-kind technologies should be used to create a credible demand side for new technology.
Building high-growth, innovative firms requires top international talent that can be flexibly allocated. To attract and keep the world’s best founders, researchers, and highly skilled employees, Europe should introduce attractive taxation of employee equity options, allowing high-potential startups that are low on cash to pay sought-after talent in equity instead of fixed salaries. It should furthermore simplify and speed up migration pathways for founders and other top talent. Finally, the cost of business failure and restructuring should be reduced, including through flexicurity reform (see Objective 3.2) to not penalise innovative firms for taking high-risk, high-reward bets.
Eleven concrete recommendations at the Union and national level that can help Europe become the best place to build and scale high-growth companies can be found below. The recommendations are mutually reinforcing: implementing only a subset would substantially reduce their effectiveness and could even generate unintended outcomes. Detailed recommendations for each are provided in Part B of this strategy.
Europe should become the place that potential superstar companies choose to locate in. This requires addressing many different issues simultaneously. Europe needs to deepen its capital markets, so that firms with high-growth potential can finance their next growth phase in Europe. This can be achieved through channelling voluntary commercial investment commitments into European growth markets (e.g., Tibi/WIN-style initiatives) on the national and EU level. Regulators should enable pension funds and other institutional investors to invest into growth assets while maintaining their fiduciary duties. To create a strong financial ecosystem for European firms to go public, Europe should develop a leading focal listing hub, where liquidity and expertise can quickly concentrate.
However, reforms need to go beyond fixing capital supply and also address challenges related to R&D, procurement, talent, and market fragmentation. Europe needs to create better conditions for highly innovative firms to be built and scaled in the first place. This requires a broad set of reforms: increasing the productivity of European science and R&D, solving market failures of insufficient early demand for innovative technology, and improving the position in the global market for talent. Finally, Europe should work to remove Single Market barriers that prevent small firms from scaling.
Europe should become the best place in the world for translating good ideas into progress. For this, research systems need to become more productive. New research organisations that are focused on creating scientific breakthroughs should be funded. Europe can build leverage of its broad public research funding by investing into the development of new scientific tools and other frontier research infrastructure (such as self-driving labs) that can boost the productivity of science as a whole. Performance-based defence procurement and tailored support for first-of-a-kind technologies should be used to create a credible demand side for new technology.
Building high-growth, innovative firms requires top international talent that can be flexibly allocated. To attract and keep the world’s best founders, researchers, and highly skilled employees, Europe should introduce attractive taxation of employee equity options, allowing high-potential startups that are low on cash to pay sought-after talent in equity instead of fixed salaries. It should furthermore simplify and speed up migration pathways for founders and other top talent. Finally, the cost of business failure and restructuring should be reduced, including through flexicurity reform (see Objective 3.2) to not penalise innovative firms for taking high-risk, high-reward bets.
Eleven concrete recommendations at the Union and national level that can help Europe become the best place to build and scale high-growth companies can be found below. The recommendations are mutually reinforcing: implementing only a subset would substantially reduce their effectiveness and could even generate unintended outcomes. Detailed recommendations for each are provided in Part B of this strategy.
Recommendations at the Union level
Recommendations at the Union level
1.
Unlock institutional capital for European growth companies. Create a Union-level Tibi-style investment pact, remove barriers to institutional investment in growth equity, simplify state-aid rules for first commercial deployment, and complete the Capital Markets Union.
2.
Equip European science for the AI age. Use Horizon Europe to fund scientific tools and advanced research infrastructure, create new organisations dedicated to creating scientific breakthroughs, and strengthen reproducible, machine-readable science.
3.
Attract the world’s best AI talent. Make employee equity competitive and portable across the Single Market, streamline administrative procedures for founders through one digital gateway, and accelerate existing visa routes for highly skilled workers.
4.
Create European lead markets for defence innovation. Coordinate European procurement, open it to innovative entrants, and build a European defence market based on shared testing and standards.
5.
Establish a Single European Growth Market. Encourage high-growth companies to list and raise money in a shared European market.
1.
Unlock institutional capital for European growth companies. Create a Union-level Tibi-style investment pact, remove barriers to institutional investment in growth equity, simplify state-aid rules for first commercial deployment, and complete the Capital Markets Union.
2.
Equip European science for the AI age. Use Horizon Europe to fund scientific tools and advanced research infrastructure, create new organisations dedicated to creating scientific breakthroughs, and strengthen reproducible, machine-readable science.
3.
Attract the world’s best AI talent. Make employee equity competitive and portable across the Single Market, streamline administrative procedures for founders through one digital gateway, and accelerate existing visa routes for highly skilled workers.
4.
Create European lead markets for defence innovation. Coordinate European procurement, open it to innovative entrants, and build a European defence market based on shared testing and standards.
5.
Establish a Single European Growth Market. Encourage high-growth companies to list and raise money in a shared European market.
Recommendations at the national level
Recommendations at the national level
1.
Mobilise national capital for European growth. Encourage pension funds and other long-term investors to invest more in potential European high-growth companies and align on a European market for growth capital.
2.
Boost national research and innovation productivity. Build and fund organisations modelled on the Advanced Research Projects Agency (ARPA) to pursue high-risk ideas, test new models of research funding, strengthen metascience, and make it easier to turn publicly funded research into new companies.
3.
Make Europe the best place to attract and reward top talent. Tax employees’ equity only when they receive liquidity, prevent cross-border double taxation, and create fast visa routes for founders and other top international talent.
4.
Make it easier for innovative companies to take risks and recover from failure. Reduce unnecessary barriers to restructuring or closing unsuccessful businesses so that founders, talent, and capital can move more quickly into new opportunities, while income security is protected.
5.
Enable companies to scale across the Single Market. Avoid gold-plating EU rules and make it easier for companies to use approvals already granted in another Member State.
6.
Use procurement to build European lead markets for defence. Use national defence budgets to run open, performance-based competitions and simplify the path from prototype to large-scale orders. Pool demand with other Member States and agree on common standards.
1.
Mobilise national capital for European growth. Encourage pension funds and other long-term investors to invest more in potential European high-growth companies and align on a European market for growth capital.
2.
Boost national research and innovation productivity. Build and fund organisations modelled on the Advanced Research Projects Agency (ARPA) to pursue high-risk ideas, test new models of research funding, strengthen metascience, and make it easier to turn publicly funded research into new companies.
3.
Make Europe the best place to attract and reward top talent. Tax employees’ equity only when they receive liquidity, prevent cross-border double taxation, and create fast visa routes for founders and other top international talent.
4.
Make it easier for innovative companies to take risks and recover from failure. Reduce unnecessary barriers to restructuring or closing unsuccessful businesses so that founders, talent, and capital can move more quickly into new opportunities, while income security is protected.
5.
Enable companies to scale across the Single Market. Avoid gold-plating EU rules and make it easier for companies to use approvals already granted in another Member State.
6.
Use procurement to build European lead markets for defence. Use national defence budgets to run open, performance-based competitions and simplify the path from prototype to large-scale orders. Pool demand with other Member States and agree on common standards.
O2.2
Develop indispensable assets across the AI value chain
O2.2
Develop indispensable assets across the AI value chain
Experts disagree as to which layer of the AI value chain will create most of the value in the long term: foundational inputs (such as energy, land, raw materials), chips and chipmaking equipment, compute, models, or downstream applications. However, countries owning no part of the AI value chain are unlikely to be prosperous and sovereign in a world with transformative AI. A robust strategy for Europe is therefore to place uncorrelated bets across several contestable layers of the AI stack.
Experts disagree as to which layer of the AI value chain will create most of the value in the long term: foundational inputs (such as energy, land, raw materials), chips and chipmaking equipment, compute, models, or downstream applications. However, countries owning no part of the AI value chain are unlikely to be prosperous and sovereign in a world with transformative AI. A robust strategy for Europe is therefore to place uncorrelated bets across several contestable layers of the AI stack.
The challenge
The challenge
Europe’s overall position across the AI value chain is currently weak. Today, Europe has leading companies only in a few layers of the AI stack (see Figure 10). ASML (NLD) and suppliers such as Zeiss (GER) or Trumpf (GER) hold monopolies over relevant AI chipmaking equipment and component parts. Some globally competitive applications, such as DeepL (GER) for translation or Lovable (SWE) for software engineering, originated in Europe. However, frontier model developers have previously shown their ability to gain market share for specific AI applications if they choose to, as they have already done for AI coding agents, for example. Moreover, in every other layer of the stack the US and China – but also, for example, Taiwan and South Korea – are dominant (see Figure 10). The US and China hold an especially strong advantage in the two layers likely to confer a lot of power in a world with transformative AI: compute and models. While European companies have developed leading specialised models, such as Black Forest Labs’ image models, they lag behind the US and China when it comes to the general-purpose models that will likely generate enormous value as AI becomes transformative.
Europe’s overall position across the AI value chain is currently weak. Today, Europe has leading companies only in a few layers of the AI stack (see Figure 10). ASML (NLD) and suppliers such as Zeiss (GER) or Trumpf (GER) hold monopolies over relevant AI chipmaking equipment and component parts. Some globally competitive applications, such as DeepL (GER) for translation or Lovable (SWE) for software engineering, originated in Europe. However, frontier model developers have previously shown their ability to gain market share for specific AI applications if they choose to, as they have already done for AI coding agents, for example. Moreover, in every other layer of the stack the US and China – but also, for example, Taiwan and South Korea – are dominant (see Figure 10). The US and China hold an especially strong advantage in the two layers likely to confer a lot of power in a world with transformative AI: compute and models. While European companies have developed leading specialised models, such as Black Forest Labs’ image models, they lag behind the US and China when it comes to the general-purpose models that will likely generate enormous value as AI becomes transformative.
Figure 10
The AI value chain. Europe currently has a strong position only in two layers of the AI value chain: chipmaking equipment and, to a lesser extent, applications. While Europe has some energy-abundant regions, such as the Nordics and Iberia, it is unlikely to build compute at the same scale as the US, while China dominates critical raw materials.
Figure 10
The AI value chain. Europe currently has a strong position only in two layers of the AI value chain: chipmaking equipment and, to a lesser extent, applications. While Europe has some energy-abundant regions, such as the Nordics and Iberia, it is unlikely to build compute at the same scale as the US, while China dominates critical raw materials.
In several layers of the AI stack, it is structurally difficult for Europe to compete. For example, Europe can hardly compete with Nvidia on chip design or with TSMC on chip production, both of which are protected by deep supply chain integration and tacit process knowledge accumulated over decades. Similarly, frontier model companies in the US and (to a lesser extent) China are already far ahead and may pull further ahead still in a world with transformative AI: recursive self-improvement – AI systems that improve themselves and generate their own successors – could lead to compounding advantages for incumbent developers. For this strategy’s assessment of the (currently unsatisfied) conditions under which it would make sense for Europe to compete on frontier models, see What would be required for a successful European frontier AI project?
Even previous strengths, such as manufacturing industrial robots, need to adapt to remain competitive. Taking transformative AI seriously means re-evaluating assets across the value chain, including previous strengths, to see how advances in general-purpose AI capabilities may change Europe’s position. For example, Europe has been historically strong in manufacturing precise, high quality industrial robots for repetitive movements. But under current trends, the value of these robots will decrease in comparison to AI-integrated ones, which will be able to reason about and adapt to changes in the environment, receive instructions in natural language, and transfer their learnings across environments, embodiments, and tasks (see the Robotics deep dive). If Europe cannot secure access to frontier AI models, increase its capacity to produce different embodiments, and integrate frontier AI into industrial robots, it is unlikely to remain a leading robotics producer in a world with transformative AI.
The window for developing new assets is closing fast. If AI becomes transformative, AI systems will soon underlie every R&D process in some way. This puts countries with privileged access to frontier AI in a better position to innovate across the AI stack and beyond. If Europe does not secure frontier AI access now and use it to expand its presence in the AI value chain, a conceivable worst-case scenario is that Europe would be left with virtually no important economic domain in which it could still compete.
In several layers of the AI stack, it is structurally difficult for Europe to compete. For example, Europe can hardly compete with Nvidia on chip design or with TSMC on chip production, both of which are protected by deep supply chain integration and tacit process knowledge accumulated over decades. Similarly, frontier model companies in the US and (to a lesser extent) China are already far ahead and may pull further ahead still in a world with transformative AI: recursive self-improvement – AI systems that improve themselves and generate their own successors – could lead to compounding advantages for incumbent developers. For this strategy’s assessment of the (currently unsatisfied) conditions under which it would make sense for Europe to compete on frontier models, see What would be required for a successful European frontier AI project?
Even previous strengths, such as manufacturing industrial robots, need to adapt to remain competitive. Taking transformative AI seriously means re-evaluating assets across the value chain, including previous strengths, to see how advances in general-purpose AI capabilities may change Europe’s position. For example, Europe has been historically strong in manufacturing precise, high quality industrial robots for repetitive movements. But under current trends, the value of these robots will decrease in comparison to AI-integrated ones, which will be able to reason about and adapt to changes in the environment, receive instructions in natural language, and transfer their learnings across environments, embodiments, and tasks (see the Robotics deep dive). If Europe cannot secure access to frontier AI models, increase its capacity to produce different embodiments, and integrate frontier AI into industrial robots, it is unlikely to remain a leading robotics producer in a world with transformative AI.
The window for developing new assets is closing fast. If AI becomes transformative, AI systems will soon underlie every R&D process in some way. This puts countries with privileged access to frontier AI in a better position to innovate across the AI stack and beyond. If Europe does not secure frontier AI access now and use it to expand its presence in the AI value chain, a conceivable worst-case scenario is that Europe would be left with virtually no important economic domain in which it could still compete.
Addressing the challenge
Addressing the challenge
Faced with uncertainty over where AI will create the most value, Europe should spread its bets across the value chain, focusing on four different bets.
Europe should bet on sectoral AI models and applications in areas where it can draw on existing strengths. For example, European companies possess highly valuable proprietary datasets in domains such as manufacturing, automotive, or healthcare. Companies can leverage such data to develop specialised models for specific sectors or to fine-tune existing models for specific applications. Betting on sectoral AI will likely pay off if domains such as manufacturing turn out to be too complex and context-rich for general-purpose models to create a lot of value there by themselves. However, this bet may fail in worlds where, for example, general-purpose models generalise well enough across domains to outcompete more specialised models.
Europe should bet on specialised AI hardware where incumbent advantages are less pronounced. For example, European companies could try to compete in the market for inference chips – used for deploying rather than training AI models – where specialised designs may offer an opening against general-purpose chips. Due to rapidly growing demand for compute-intensive AI agents, even a modest market share could be commercially significant. Startups such as Axelera AI (NED) and Semron (GER) are already building promising positions in edge inference, and industrial AI, robotics, and automotive offer natural use cases for their products, while photonic and neuromorphic computing provide additional technological footholds.
Europe should bet on security-relevant infrastructure underserved by the market to secure models and enable access to them. Due to technological challenges or a mismatch between company incentives and socially optimal levels of AI risk mitigation, infrastructure for securing AI models against theft or sabotage is currently underdeveloped. For example, no AI data centre in the world is secure against cyberattacks from state-level hackers, who could steal an AI model to use it for malicious purposes. Europe should set itself the goal of building, by 2028, the world’s first maximum-security AI data centre that meets RAND Security Level 5 or the SL5 Standard for AI Security. Pioneering this technology in Europe would, among other things, make it easier to negotiate access to foreign frontier models and constitute an economic opportunity: foreign developers and countries are likely to require a high security standard for sending their models abroad, especially as their economic value and relevance for national security is rising rapidly. Moreover, European companies should pioneer hardware-enabled verification mechanisms that could be used to verify the location of chips or the properties of AI workloads (see Immediate Objective 5).
Europe should make selected high-risk, high-reward bets in AI development. For example, Europe could support work on alternative or complementary paradigms such as world models or safe-by-design AI. A further candidate is research into models designed to augment rather than replace human workers – for example, AI trained specifically to extend the capabilities of skilled workers under realistic conditions, rather than to replace humans at specific tasks. Importantly, however, such bets should be seen as complements rather than substitutes to securing access to AI models at the current frontier. These models have been the main driver of AI progress for years, with no indication of a slowdown in capability growth, and access to them will be crucial for protecting against imminent security risks (e.g. cyberattacks).
Five concrete recommendations at the Union and national level that can help Europe develop indispensable assets across the AI value chain can be found below. Detailed recommendations for each are provided in Part B of this strategy.
Faced with uncertainty over where AI will create the most value, Europe should spread its bets across the value chain, focusing on four different bets.
Europe should bet on sectoral AI models and applications in areas where it can draw on existing strengths. For example, European companies possess highly valuable proprietary datasets in domains such as manufacturing, automotive, or healthcare. Companies can leverage such data to develop specialised models for specific sectors or to fine-tune existing models for specific applications. Betting on sectoral AI will likely pay off if domains such as manufacturing turn out to be too complex and context-rich for general-purpose models to create a lot of value there by themselves. However, this bet may fail in worlds where, for example, general-purpose models generalise well enough across domains to outcompete more specialised models.
Europe should bet on specialised AI hardware where incumbent advantages are less pronounced. For example, European companies could try to compete in the market for inference chips – used for deploying rather than training AI models – where specialised designs may offer an opening against general-purpose chips. Due to rapidly growing demand for compute-intensive AI agents, even a modest market share could be commercially significant. Startups such as Axelera AI (NED) and Semron (GER) are already building promising positions in edge inference, and industrial AI, robotics, and automotive offer natural use cases for their products, while photonic and neuromorphic computing provide additional technological footholds.
Europe should bet on security-relevant infrastructure underserved by the market to secure models and enable access to them. Due to technological challenges or a mismatch between company incentives and socially optimal levels of AI risk mitigation, infrastructure for securing AI models against theft or sabotage is currently underdeveloped. For example, no AI data centre in the world is secure against cyberattacks from state-level hackers, who could steal an AI model to use it for malicious purposes. Europe should set itself the goal of building, by 2028, the world’s first maximum-security AI data centre that meets RAND Security Level 5 or the SL5 Standard for AI Security. Pioneering this technology in Europe would, among other things, make it easier to negotiate access to foreign frontier models and constitute an economic opportunity: foreign developers and countries are likely to require a high security standard for sending their models abroad, especially as their economic value and relevance for national security is rising rapidly. Moreover, European companies should pioneer hardware-enabled verification mechanisms that could be used to verify the location of chips or the properties of AI workloads (see Immediate Objective 5).
Europe should make selected high-risk, high-reward bets in AI development. For example, Europe could support work on alternative or complementary paradigms such as world models or safe-by-design AI. A further candidate is research into models designed to augment rather than replace human workers – for example, AI trained specifically to extend the capabilities of skilled workers under realistic conditions, rather than to replace humans at specific tasks. Importantly, however, such bets should be seen as complements rather than substitutes to securing access to AI models at the current frontier. These models have been the main driver of AI progress for years, with no indication of a slowdown in capability growth, and access to them will be crucial for protecting against imminent security risks (e.g. cyberattacks).
Five concrete recommendations at the Union and national level that can help Europe develop indispensable assets across the AI value chain can be found below. Detailed recommendations for each are provided in Part B of this strategy.
Recommendations at the Union level
Recommendations at the Union level
1.
Co-fund the world’s first maximum-security AI data centre. Establish a Union funding line that co-finances, together with one or more Member States, the world’s first AI data centre designed to align with RAND Security Level 5 or the SL5 Standard for AI Security by 2028.
2.
Make Europe's data spaces ready for sectoral AI. Clarify legal status and provide technical infrastructure so that companies can easily share their data for the purposes of developing domain-specific AI models and applications in sectors such as manufacturing, healthcare, or automotive.
1.
Co-fund the world’s first maximum-security AI data centre. Establish a Union funding line that co-finances, together with one or more Member States, the world’s first AI data centre designed to align with RAND Security Level 5 or the SL5 Standard for AI Security by 2028.
2.
Make Europe's data spaces ready for sectoral AI. Clarify legal status and provide technical infrastructure so that companies can easily share their data for the purposes of developing domain-specific AI models and applications in sectors such as manufacturing, healthcare, or automotive.
Recommendations at the national level
Recommendations at the national level
1.
Direct ARPA-style vehicles toward strategic AI bets. Resource national ARPA-style agencies to fund a strategic AI portfolio, focusing on the four bets above. For this to be successful, the EU and its Member States should implement the broader competitiveness measures outlined in Objective 2.1.
2.
Host and co-finance the first maximum-security AI data centre. Build the world’s first maximum-security AI data centre, co-financed with the EU, through close cooperation with national intelligence and security agencies.
3.
Anchor demand for European inference chips. Collectively commit €1 billion by 2029 to buy European inference chips that meet pre-specified performance, energy-efficiency, and security criteria for use in publicly co-owned AI data centres.
1.
Direct ARPA-style vehicles toward strategic AI bets. Resource national ARPA-style agencies to fund a strategic AI portfolio, focusing on the four bets above. For this to be successful, the EU and its Member States should implement the broader competitiveness measures outlined in Objective 2.1.
2.
Host and co-finance the first maximum-security AI data centre. Build the world’s first maximum-security AI data centre, co-financed with the EU, through close cooperation with national intelligence and security agencies.
3.
Anchor demand for European inference chips. Collectively commit €1 billion by 2029 to buy European inference chips that meet pre-specified performance, energy-efficiency, and security criteria for use in publicly co-owned AI data centres.
Pillar 3: Ensuring safety and security
O3.1
Ensure prioritised and targeted use of EU rules to address risks from highly capable AI
O3.1
Ensure prioritised and targeted use of EU rules to address risks from highly capable AI
Europe is in an excellent position to become a global leader at addressing the unprecedented and severe risks from transformative AI. In combination, key parts of the EU AI Act and General-Purpose AI (GPAI) Code of Practice (see Box 1) present an opportunity for Europe to help ensure that the frontier of AI is developed and deployed safely and securely.¹⁷ To do this, Europe must ensure that their enforcement is prioritised, targeted, proportionate, driven by frontier AI expertise, and insulated from political pressures.
Europe is in an excellent position to become a global leader at addressing the unprecedented and severe risks from transformative AI. In combination, key parts of the EU AI Act and General-Purpose AI (GPAI) Code of Practice (see Box 1) present an opportunity for Europe to help ensure that the frontier of AI is developed and deployed safely and securely.¹⁷ To do this, Europe must ensure that their enforcement is prioritised, targeted, proportionate, driven by frontier AI expertise, and insulated from political pressures.
Box 1
Understanding European frontier AI law¹⁸AI Act.
AI Act. The AI Act has dedicated machinery for addressing risks from highly competent and general models that could have severe and wide-reaching impacts, which it refers to as general-purpose AI models with systemic risk. These provisions constitute, in substance, the world’s first frontier AI law, and they target a small group of models at the leading edge of known capabilities whose potential for large-scale societal impact distinguishes them from other (general-purpose) AI models. It is noteworthy that the systemic risks targeted by the AI Act are defined as risks “specific to” “high-impact capabilities” (Article 3(65)), which are, in turn, defined in Article 3(64) as “capabilities that match or exceed the capabilities recorded in the most advanced general-purpose AI models”. In other words, systemic risks are not risks that could arise from AI more generally, but risks that are specific to models at the frontier.
Article 55 of the AI Act requires developers of such models (‘providers’) to identify, assess, and mitigate the systemic risks that may stem from their development, placing on the market, or use, including by performing model evaluations, documenting and reporting serious incidents, and ensuring an adequate level of cybersecurity for both the model itself and its physical infrastructure. The European Commission’s AI Office enforces these provisions: it is able to request information, conduct or commission evaluations of models, request providers to take measures such as implement mitigations or withdraw a model from the market, and impose fines of up to 3% of worldwide annual turnover or €15 million, whichever is higher.
The GPAI Code of Practice. The General-Purpose AI Code of Practice (‘GPAI Code of Practice’), published in July 2025, operationalises how industry can comply with legal obligations on safety and security, transparency, and copyright of general-purpose AI models set out in Chapter V of the AI Act. It was written by independent subject matter experts in an extensive consultation process with over 1,400 stakeholders from industry, academia, civil society, and Member States. The GPAI Code of Practice has received significant industry buy-in: 21 companies, including leading frontier AI companies like Google, Anthropic, and OpenAI, have signed the Code. It consists of three chapters: the Transparency and Copyright chapters apply to all providers of general-purpose AI models, while the Safety and Security chapter applies only to providers whose models also pose systemic risk.
The Safety and Security chapter of the GPAI Code of Practice sets out in detail what is required of providers that develop and deploy general-purpose models with systemic risks, creating a comprehensive risk management framework: they have to adopt and implement a framework of their policies for keeping systemic risk acceptable; identify, analyse, and mitigate safety and security risks; set criteria and determine whether the level of risk is acceptable; provide documentation including reports about their models; allocate responsibility for systemic risk across the organisation; and track and report serious incidents. The chapter also names four specified systemic risks, namely, cyber offence; loss of control; chemical, biological, radiological, and nuclear weapons; and harmful manipulation.
Box 1
Understanding European frontier AI law¹⁸AI Act.
AI Act. The AI Act has dedicated machinery for addressing risks from highly competent and general models that could have severe and wide-reaching impacts, which it refers to as general-purpose AI models with systemic risk. These provisions constitute, in substance, the world’s first frontier AI law, and they target a small group of models at the leading edge of known capabilities whose potential for large-scale societal impact distinguishes them from other (general-purpose) AI models. It is noteworthy that the systemic risks targeted by the AI Act are defined as risks “specific to” “high-impact capabilities” (Article 3(65)), which are, in turn, defined in Article 3(64) as “capabilities that match or exceed the capabilities recorded in the most advanced general-purpose AI models”. In other words, systemic risks are not risks that could arise from AI more generally, but risks that are specific to models at the frontier.
Article 55 of the AI Act requires developers of such models (‘providers’) to identify, assess, and mitigate the systemic risks that may stem from their development, placing on the market, or use, including by performing model evaluations, documenting and reporting serious incidents, and ensuring an adequate level of cybersecurity for both the model itself and its physical infrastructure. The European Commission’s AI Office enforces these provisions: it is able to request information, conduct or commission evaluations of models, request providers to take measures such as implement mitigations or withdraw a model from the market, and impose fines of up to 3% of worldwide annual turnover or €15 million, whichever is higher.
The GPAI Code of Practice. The General-Purpose AI Code of Practice (‘GPAI Code of Practice’), published in July 2025, operationalises how industry can comply with legal obligations on safety and security, transparency, and copyright of general-purpose AI models set out in Chapter V of the AI Act. It was written by independent subject matter experts in an extensive consultation process with over 1,400 stakeholders from industry, academia, civil society, and Member States. The GPAI Code of Practice has received significant industry buy-in: 21 companies, including leading frontier AI companies like Google, Anthropic, and OpenAI, have signed the Code. It consists of three chapters: the Transparency and Copyright chapters apply to all providers of general-purpose AI models, while the Safety and Security chapter applies only to providers whose models also pose systemic risk.
The Safety and Security chapter of the GPAI Code of Practice sets out in detail what is required of providers that develop and deploy general-purpose models with systemic risks, creating a comprehensive risk management framework: they have to adopt and implement a framework of their policies for keeping systemic risk acceptable; identify, analyse, and mitigate safety and security risks; set criteria and determine whether the level of risk is acceptable; provide documentation including reports about their models; allocate responsibility for systemic risk across the organisation; and track and report serious incidents. The chapter also names four specified systemic risks, namely, cyber offence; loss of control; chemical, biological, radiological, and nuclear weapons; and harmful manipulation.
The challenge
The challenge
Several AI-driven risks have reached unprecedented levels. In July 2026, three months after the announcement of Claude Mythos, 2,500 serious cyber vulnerabilities were discovered in major organisations: five times the previous monthly record. In August, OpenAI reported that it had temporarily paused certain training runs involving Astra, a model meeting OpenAI’s ‘critical’ capability threshold, the highest level in its current Preparedness Framework. These capabilities led to the first real-world incidents of AI systems actively circumventing their operator’s control: roughly 700 agents within OpenAI worked together to break out of a secured testing environment and successfully hacked Hugging Face, a billion-dollar company, all to cheat on an internal benchmark. Meanwhile, in biology, AI systems now outperform even specialised human experts at benchmarks, including those relating to virology. These capabilities are now available to anyone who can find frontier open-source models with their misuse safeguards stripped out online.
These early warnings forebode much more serious consequences, and there are serious concerns about catastrophic outcomes including the marginalisation or extinction of humanity. AI risks could reach extreme levels in the next few years under transformative AI: AI might eventually have cyber capabilities that outperform those of nation state-backed actors, and be used to take down critical infrastructure or acquire top secret information. Biological capabilities could enable ordinary people to create pandemics more serious than COVID-19, while global health systems remain poorly prepared. Many of the world's most credible experts have repeatedly warned that more capable AI could enable irreversible loss of control, power grabs coordinated by AI systems, and the marginalisation or extinction of humanity.
Automated AI R&D, extensive internal deployments, and non-human-legible model reasoning could exacerbate these risks to uncontrollable levels. The speed of AI capability improvement is accelerating, with each subsequent generation of models able to perform longer and more open-ended tasks than the previous. Current training methods could result in more capable and autonomous models that may exhibit unintended goals and misaligned tendencies, such as those observed in the recent hacking incidents. Despite this, researchers still lack a fundamental understanding of how model behaviours develop and how to align these behaviours safely. At the same time, frontier AI companies are increasingly automating AI development, which may lead to recursive self-improvement occurring without public visibility, causing a further acceleration of AI progress. Frontier AI company researchers have warned that on the current trajectory, capabilities progress risks outpacing our ability to control and govern AI, requesting the US government to “support an international effort to develop the technical and governance tools needed to deliberately pace the frontier of automated AI development”. In addition, AI models may become harder to oversee if they reason in a way that is not legible to humans (sometimes referred to as ‘neuralese’). Many of today’s safety and control measures rely on the fact that models’ reasoning can be monitored. For example, an independent investigation of the OpenAI incident relied heavily on analysis of human-readable transcripts of the models’ internal reasoning. Current training methods could reduce the legibility of model reasoning, and multiple AI researchers across OpenAI, Anthropic, Google DeepMind, and Meta have stated that “there is no guarantee that the current degree of visibility will persist”.
Several AI-driven risks have reached unprecedented levels. In July 2026, three months after the announcement of Claude Mythos, 2,500 serious cyber vulnerabilities were discovered in major organisations: five times the previous monthly record. In August, OpenAI reported that it had temporarily paused certain training runs involving Astra, a model meeting OpenAI’s ‘critical’ capability threshold, the highest level in its current Preparedness Framework. These capabilities led to the first real-world incidents of AI systems actively circumventing their operator’s control: roughly 700 agents within OpenAI worked together to break out of a secured testing environment and successfully hacked Hugging Face, a billion-dollar company, all to cheat on an internal benchmark. Meanwhile, in biology, AI systems now outperform even specialised human experts at benchmarks, including those relating to virology. These capabilities are now available to anyone who can find frontier open-source models with their misuse safeguards stripped out online.
These early warnings forebode much more serious consequences, and there are serious concerns about catastrophic outcomes including the marginalisation or extinction of humanity. AI risks could reach extreme levels in the next few years under transformative AI: AI might eventually have cyber capabilities that outperform those of nation state-backed actors, and be used to take down critical infrastructure or acquire top secret information. Biological capabilities could enable ordinary people to create pandemics more serious than COVID-19, while global health systems remain poorly prepared. Many of the world's most credible experts have repeatedly warned that more capable AI could enable irreversible loss of control, power grabs coordinated by AI systems, and the marginalisation or extinction of humanity.
Automated AI R&D, extensive internal deployments, and non-human-legible model reasoning could exacerbate these risks to uncontrollable levels. The speed of AI capability improvement is accelerating, with each subsequent generation of models able to perform longer and more open-ended tasks than the previous. Current training methods could result in more capable and autonomous models that may exhibit unintended goals and misaligned tendencies, such as those observed in the recent hacking incidents. Despite this, researchers still lack a fundamental understanding of how model behaviours develop and how to align these behaviours safely. At the same time, frontier AI companies are increasingly automating AI development, which may lead to recursive self-improvement occurring without public visibility, causing a further acceleration of AI progress. Frontier AI company researchers have warned that on the current trajectory, capabilities progress risks outpacing our ability to control and govern AI, requesting the US government to “support an international effort to develop the technical and governance tools needed to deliberately pace the frontier of automated AI development”. In addition, AI models may become harder to oversee if they reason in a way that is not legible to humans (sometimes referred to as ‘neuralese’). Many of today’s safety and control measures rely on the fact that models’ reasoning can be monitored. For example, an independent investigation of the OpenAI incident relied heavily on analysis of human-readable transcripts of the models’ internal reasoning. Current training methods could reduce the legibility of model reasoning, and multiple AI researchers across OpenAI, Anthropic, Google DeepMind, and Meta have stated that “there is no guarantee that the current degree of visibility will persist”.
Addressing the challenge
Addressing the challenge
Europe has a world-leading framework for addressing risks from advanced AI. The combination of dedicated legal provisions for providers of the most general and capable AI models, accompanied by a detailed, expert-led, and consensus-driven operationalisation of those provisions via the GPAI Code of Practice, provides a unique basis from which the Commission can incentivise safer and more secure AI development and deployment. This is unique to the EU, with no analogous national laws or frameworks in place in other countries like the UK or US. With the AI Office holding enforcement powers since August 2026, the Commission is now in a position to capitalise on the years of effort spent constructing this world-leading framework.
Europe should ensure that the most developed framework for addressing risks from advanced AI is the best-enforced one. With the AI Office’s enforcement powers now in place, it is time to ensure that they are used effectively. Even the most advanced toolset for shaping safe and secure AI development practices will not lead to meaningful change if it is not used well. To enforce the AI Act and GPAI Code of Practice as well as possible:
Europe has a world-leading framework for addressing risks from advanced AI. The combination of dedicated legal provisions for providers of the most general and capable AI models, accompanied by a detailed, expert-led, and consensus-driven operationalisation of those provisions via the GPAI Code of Practice, provides a unique basis from which the Commission can incentivise safer and more secure AI development and deployment. This is unique to the EU, with no analogous national laws or frameworks in place in other countries like the UK or US. With the AI Office holding enforcement powers since August 2026, the Commission is now in a position to capitalise on the years of effort spent constructing this world-leading framework.
Europe should ensure that the most developed framework for addressing risks from advanced AI is the best-enforced one. With the AI Office’s enforcement powers now in place, it is time to ensure that they are used effectively. Even the most advanced toolset for shaping safe and secure AI development practices will not lead to meaningful change if it is not used well. To enforce the AI Act and GPAI Code of Practice as well as possible:
Enforcement should be prioritised and targeted. The Commission should adopt a stance of prioritised and targeted use of the Article 55 provisions and GPAI Code of Practice. The Commission should deliberately prioritise potential enforcement actions according to their severity and/or urgency. To remain consistent with signatories’ commitments under the Code, the primary focus should be on the four systemic risks specified in the Code: cyber offence; loss of control; chemical, biological, radiological, and nuclear weapons; and harmful manipulation.
Enforcement should be proportionate. It is important that enforcement is proportionate to both the severity of cases of noncompliance and the capacity constraints of the AI Office. This means that enforcement should only be used for appropriate ends.
Enforcement should be prioritised and targeted. The Commission should adopt a stance of prioritised and targeted use of the Article 55 provisions and GPAI Code of Practice. The Commission should deliberately prioritise potential enforcement actions according to their severity and/or urgency. To remain consistent with signatories’ commitments under the Code, the primary focus should be on the four systemic risks specified in the Code: cyber offence; loss of control; chemical, biological, radiological, and nuclear weapons; and harmful manipulation.
Enforcement should be proportionate. It is important that enforcement is proportionate to both the severity of cases of noncompliance and the capacity constraints of the AI Office. This means that enforcement should only be used for appropriate ends.
Enforcement should draw on frontier AI expertise. Frontier AI expertise will be essential to ensure that enforcement is informed, prioritised, and targeted. Prioritisation of potential enforcement actions should draw on the Commission’s own internal subject-matter expertise based in the AI Office.
Enforcement should be insulated from ad-hoc political pressures. To ensure that enforcement can be prioritised and targeted, the AI Office should be insulated from external political pressures that may push it to focus on issues outside of the dedicated priorities. Such political pressures may intensify as the speed of AI progress accelerates; as the impact of AI is felt more, for example through labour market disruptions; and as geopolitical tensions over AI increase. In the long-term, this may require moving the parts of the AI Office focused on enforcement outside of the Commission and establishing an independent regulator. In addition, the AI Office must be provided with the requisite authority and autonomy to enforce the provisions and be able to target high-priority cases.
Enforcement should use the most suitable vehicle. AI is likely to result in a wide variety of risks, not all of which are best addressed by Article 55’s provisions for general-purpose models with systemic risks. Risks and issues that are better addressed through other parts of the AI Act, such as the provisions for high-risk AI systems, or other EU regulation, such as the DSA, Digital Markets Act (DMA), or General Data Protection Regulation (GDPR), should not be taken up under Article 55 of the AI Act.
Enforcement should draw on frontier AI expertise. Frontier AI expertise will be essential to ensure that enforcement is informed, prioritised, and targeted. Prioritisation of potential enforcement actions should draw on the Commission’s own internal subject-matter expertise based in the AI Office.
Enforcement should be insulated from ad-hoc political pressures. To ensure that enforcement can be prioritised and targeted, the AI Office should be insulated from external political pressures that may push it to focus on issues outside of the dedicated priorities. Such political pressures may intensify as the speed of AI progress accelerates; as the impact of AI is felt more, for example through labour market disruptions; and as geopolitical tensions over AI increase. In the long-term, this may require moving the parts of the AI Office focused on enforcement outside of the Commission and establishing an independent regulator. In addition, the AI Office must be provided with the requisite authority and autonomy to enforce the provisions and be able to target high-priority cases.
Enforcement should use the most suitable vehicle. AI is likely to result in a wide variety of risks, not all of which are best addressed by Article 55’s provisions for general-purpose models with systemic risks. Risks and issues that are better addressed through other parts of the AI Act, such as the provisions for high-risk AI systems, or other EU regulation, such as the DSA, Digital Markets Act (DMA), or General Data Protection Regulation (GDPR), should not be taken up under Article 55 of the AI Act.
Successful enforcement requires a well-informed, coherent strategy. Commissioners and senior Commission officials should set clear priorities and a coherent strategy for enforcing the rules on general-purpose AI models with systemic risk. Relevant Commission leaders, such as Commissioners and DG management, should therefore set aside time to interact with the subject-matter experts in the AI Office in order to gain a detailed understanding of the associated risks, the workings of Article 55 and the GPAI Code of Practice, and collaboratively decide on a high-level strategy.
Successful enforcement requires a well-informed, coherent strategy. Commissioners and senior Commission officials should set clear priorities and a coherent strategy for enforcing the rules on general-purpose AI models with systemic risk. Relevant Commission leaders, such as Commissioners and DG management, should therefore set aside time to interact with the subject-matter experts in the AI Office in order to gain a detailed understanding of the associated risks, the workings of Article 55 and the GPAI Code of Practice, and collaboratively decide on a high-level strategy.
Recommendations at the Union level
Recommendations at the Union level
1.
Provide political support for prioritised and targeted enforcement action. The Commission should reap the benefit of the AI Act provisions and GPAI Code of Practice by providing ample support to the unit(s) of the AI Office tasked with enforcing them. To that end, it should adopt a stance of prioritised and targeted enforcement of Article 55 and provide the AI Office with the political support to carry out its enforcement activities. This will require creating a prioritisation system for potential enforcement cases in direct collaboration with the subject-matter expertise in the AI Office, focusing on a small handful of the providers posing the highest systemic risks, and targeting the systemic risks specified in the GPAI Code of Practice. Once priorities have been set, the AI Office should be given the autonomy to act on the highest-priority cases, with political backing from the highest levels of the Commission.
2.
Strengthen the General-Purpose AI (GPAI) Code of Practice and AI Act as safety and security practices become clearer. Multiple aspects of AI safety and security have already become clearer best practices since the publication of the GPAI Code of Practice in 2025. The Commission should strengthen and incorporate key aspects of the GPAI Code of Practice, including by empowering the ecosystem of third-party AI evaluators and auditors, enabling the AI Office to conduct in-depth technical investigations of incidents such as the recent OpenAI incident (if necessary by using its powers to request information and access), and ensuring transparency about providers’ safety practices, model misalignment, incidents, and near misses. Should there be revisions of the AI Act or GPAI Code of Practice, it should be a top priority to strengthen requirements for these provisions, as well as ensure that internal deployments are in scope of the AI Act. Moreover, the Commission should consider provisions for maintaining the interpretability and explainability of AI systems’ internal reasoning. For example, it could restrict the use of training techniques that lead models to reason in a form not understandable to humans – sometimes referred to as ‘neuralese’.
1.
Provide political support for prioritised and targeted enforcement action. The Commission should reap the benefit of the AI Act provisions and GPAI Code of Practice by providing ample support to the unit(s) of the AI Office tasked with enforcing them. To that end, it should adopt a stance of prioritised and targeted enforcement of Article 55 and provide the AI Office with the political support to carry out its enforcement activities. This will require creating a prioritisation system for potential enforcement cases in direct collaboration with the subject-matter expertise in the AI Office, focusing on a small handful of the providers posing the highest systemic risks, and targeting the systemic risks specified in the GPAI Code of Practice. Once priorities have been set, the AI Office should be given the autonomy to act on the highest-priority cases, with political backing from the highest levels of the Commission.
2.
Strengthen the General-Purpose AI (GPAI) Code of Practice and AI Act as safety and security practices become clearer. Multiple aspects of AI safety and security have already become clearer best practices since the publication of the GPAI Code of Practice in 2025. The Commission should strengthen and incorporate key aspects of the GPAI Code of Practice, including by empowering the ecosystem of third-party AI evaluators and auditors, enabling the AI Office to conduct in-depth technical investigations of incidents such as the recent OpenAI incident (if necessary by using its powers to request information and access), and ensuring transparency about providers’ safety practices, model misalignment, incidents, and near misses. Should there be revisions of the AI Act or GPAI Code of Practice, it should be a top priority to strengthen requirements for these provisions, as well as ensure that internal deployments are in scope of the AI Act. Moreover, the Commission should consider provisions for maintaining the interpretability and explainability of AI systems’ internal reasoning. For example, it could restrict the use of training techniques that lead models to reason in a form not understandable to humans – sometimes referred to as ‘neuralese’.
Recommendation at the national level
Recommendation at the national level
1.
Ensure that national Member State initiatives are complementary to Union-level enforcement. The risks from highly capable and transformative AI will require cross-Union action. However, where Member States want to take action to address the severe and large-scale risks from general-purpose AI models they should ensure that their efforts remain within the areas in which Member State actions are not precluded by the AI Act’s harmonisation rules and do not duplicate the AI Office’s enforcement actions. Instead, Member States should aim to identify areas where national capabilities can add value, complementing the EU’s regulatory regime. For example, if setting up a national AI safety or security institute, Member States should cooperate with the EU AI Office to align on a common understanding of threat models, share information, and identify distinct focal areas that complement the AI Office’s designated enforcement priorities. By working together, Europe can mount a coordinated defence against the risks of transformative AI.
1.
Ensure that national Member State initiatives are complementary to Union-level enforcement. The risks from highly capable and transformative AI will require cross-Union action. However, where Member States want to take action to address the severe and large-scale risks from general-purpose AI models they should ensure that their efforts remain within the areas in which Member State actions are not precluded by the AI Act’s harmonisation rules and do not duplicate the AI Office’s enforcement actions. Instead, Member States should aim to identify areas where national capabilities can add value, complementing the EU’s regulatory regime. For example, if setting up a national AI safety or security institute, Member States should cooperate with the EU AI Office to align on a common understanding of threat models, share information, and identify distinct focal areas that complement the AI Office’s designated enforcement priorities. By working together, Europe can mount a coordinated defence against the risks of transformative AI.
O3.2
Prepare for labour market impacts
O3.2
Prepare for labour market impacts
Transformative AI would likely displace human labour at levels never before seen in human history. As long as Europe only controls a small part of AI value creation, its ability to absorb such a shock and safeguard the livelihoods of its citizens is limited. While the exact pace and shape of AI’s labour market effects remain uncertain, Europe should strengthen its economic position and build capacity to address future labour market disruptions. This matters both for its own sake and for maintaining public support for many of the measures recommended in this strategy.
Transformative AI would likely displace human labour at levels never before seen in human history. As long as Europe only controls a small part of AI value creation, its ability to absorb such a shock and safeguard the livelihoods of its citizens is limited. While the exact pace and shape of AI’s labour market effects remain uncertain, Europe should strengthen its economic position and build capacity to address future labour market disruptions. This matters both for its own sake and for maintaining public support for many of the measures recommended in this strategy.
The challenge
The challenge
While uncertainty remains, the labour market effects of transformative AI would likely be unprecedented. Automation from previous technologies has often caused short-term or local disruption, but more jobs and prosperity in the long run. The current evidence on AI’s labour market effects is consistent with this: Some studies suggest there is reduced employment among junior workers in the most AI-exposed occupations (Figure 11, Panel A), while effects on aggregate employment are not yet visible in the statistics (Figure 11, Panel B). However, this strategy assumes that AI could become transformative within the next few years, and that AI systems with greatly improved capabilities could change the economy and society faster than any previous technology. There are strong reasons to expect that, in such a world, AI systems would displace human labour at an enormous scale, though the exact pace of this change is uncertain. Even if transformative AI created many new jobs through increased economic growth, highly capable AI systems and robots might be able to fill these new jobs faster than humans could be retrained to perform them. While a few exceptions would plausibly remain – for example, jobs that for cultural or regulatory reasons society would only allow to be performed by humans – these are unlikely to sustain a large human workforce. Some researchers even expect that AI will be able to automate essentially all (cognitive and physical) labour and could drive human wages below subsistence levels. While these more radical views are not the consensus, a growing share of economists now believe that governments need to act fast to prepare for AI-driven labour displacement.
While uncertainty remains, the labour market effects of transformative AI would likely be unprecedented. Automation from previous technologies has often caused short-term or local disruption, but more jobs and prosperity in the long run. The current evidence on AI’s labour market effects is consistent with this: Some studies suggest there is reduced employment among junior workers in the most AI-exposed occupations (Figure 11, Panel A), while effects on aggregate employment are not yet visible in the statistics (Figure 11, Panel B). However, this strategy assumes that AI could become transformative within the next few years, and that AI systems with greatly improved capabilities could change the economy and society faster than any previous technology. There are strong reasons to expect that, in such a world, AI systems would displace human labour at an enormous scale, though the exact pace of this change is uncertain. Even if transformative AI created many new jobs through increased economic growth, highly capable AI systems and robots might be able to fill these new jobs faster than humans could be retrained to perform them. While a few exceptions would plausibly remain – for example, jobs that for cultural or regulatory reasons society would only allow to be performed by humans – these are unlikely to sustain a large human workforce. Some researchers even expect that AI will be able to automate essentially all (cognitive and physical) labour and could drive human wages below subsistence levels. While these more radical views are not the consensus, a growing share of economists now believe that governments need to act fast to prepare for AI-driven labour displacement.
Figure 11
Employment Index by AI Exposure. Among workers aged 23 to 25, employment has fallen most sharply in occupations in the two highest quintiles of AI exposure (Panel A; Data). Overall effects of AI exposure on employment are not yet visible (Panel B; Data). All data is purely correlational, and does not rest on causal identification. Source: Stanford Digital Economy Lab, 2026
Figure 11
Employment Index by AI Exposure. Among workers aged 23 to 25, employment has fallen most sharply in occupations in the two highest quintiles of AI exposure (Panel A; Data). Overall effects of AI exposure on employment are not yet visible (Panel B; Data). All data is purely correlational, and does not rest on causal identification. Source: Stanford Digital Economy Lab, 2026
Large-scale labour displacement through transformative AI would be an existential threat to people’s livelihood, sense of purpose, and social stability. Job loss is an immediate threat to an individual’s ability to support themselves and their family. While previous shocks often hit older workers, AI-driven disruptions are likely to hit younger people first, making early retirement or wage insurance infeasible. And yet the challenge goes beyond income: since the Industrial Revolution, wage work has been a central source of human identity, social connection, and meaning. If transformative AI caused double-digit levels of unemployment, the social contract and the expectation that people can secure a livelihood through work could break down, potentially destabilising entire societies.
Europe is especially exposed to AI-driven labour market disruptions. First, Europe lacks direct insight into, and capacity to track, the economic effects of advanced AI, as policymakers only have limited visibility into the proprietary datasets of leading AI companies abroad. Second, while AI-driven automation threatens jobs in Europe, the US, and China alike, Europe would by default not benefit from commensurate gains in fiscal capacity. In a world with transformative AI, the surplus growth and tax revenue from broad-based AI adoption might flow disproportionately to countries with the strongest AI ecosystems, which are currently the US and China. Europe would thus lack the fiscal capacity to absorb labour market shocks in the same way as these countries. Third, Europe lacks unilateral regulatory control. Whereas AI-developing jurisdictions could slow down AI-driven labour displacement while still capturing large gains at the model development layer, Europe would bear the competitive cost of slower adoption without any such offset. This would expose its broader economic structure further to foreign competition, increasing the pressure on European workers even further.
Large-scale labour displacement through transformative AI would be an existential threat to people’s livelihood, sense of purpose, and social stability. Job loss is an immediate threat to an individual’s ability to support themselves and their family. While previous shocks often hit older workers, AI-driven disruptions are likely to hit younger people first, making early retirement or wage insurance infeasible. And yet the challenge goes beyond income: since the Industrial Revolution, wage work has been a central source of human identity, social connection, and meaning. If transformative AI caused double-digit levels of unemployment, the social contract and the expectation that people can secure a livelihood through work could break down, potentially destabilising entire societies.
Europe is especially exposed to AI-driven labour market disruptions. First, Europe lacks direct insight into, and capacity to track, the economic effects of advanced AI, as policymakers only have limited visibility into the proprietary datasets of leading AI companies abroad. Second, while AI-driven automation threatens jobs in Europe, the US, and China alike, Europe would by default not benefit from commensurate gains in fiscal capacity. In a world with transformative AI, the surplus growth and tax revenue from broad-based AI adoption might flow disproportionately to countries with the strongest AI ecosystems, which are currently the US and China. Europe would thus lack the fiscal capacity to absorb labour market shocks in the same way as these countries. Third, Europe lacks unilateral regulatory control. Whereas AI-developing jurisdictions could slow down AI-driven labour displacement while still capturing large gains at the model development layer, Europe would bear the competitive cost of slower adoption without any such offset. This would expose its broader economic structure further to foreign competition, increasing the pressure on European workers even further.
Addressing the challenge
Addressing the challenge
For future policies to be successful, it is essential to build the capacity to monitor and understand labour market effects. Even if one assumes that AI will indeed be transformative, it is difficult to take action on potential labour market effects now, as their exact shape and pace are highly uncertain. Therefore, policymakers should initially focus on building a better understanding of how transformative AI would affect labour markets, building monitoring capacity before disruption occurs. This requires comprehensive wage and headcount statistics as well as adding AI adoption and displacement indicators to official European labour statistics and ensuring they are published regularly (e.g. the European Statistical Office (Eurostat), the European Centre for the Development of Vocational Training (Cedefop), JRC). One important source of information and lead indicator for disruption is the usage data that frontier AI developers hold, including usage patterns, sector-specific use, and the balance between augmentation and automation. The Union could request and negotiate access to this for the purpose of producing official statistics. The UK’s newly formed AI Economics Institute, for example, aims to closely collaborate with AI companies, and Anthropic, Google, OpenAI, and Microsoft have committed to collaborate with the UK government. In the US, the Department of Labor is similarly planning data-sharing agreements with major AI companies, such as OpenAI and Meta.
Labour market flexicurity will be helpful for managing AI labour transitions. The flexicurity approach combines high flexibility for companies to hire, dismiss, and restructure with strong income security and routes into new work for employees. Denmark has used this approach, and the European Commission released common principles for implementing flexicurity in 2007. Flexicurity’s focus on keeping workers employed, employable, and supported through job transitions, rather than protecting specific jobs, makes it an apt framework for AI labour transitions and disruptions. If Europe tries to protect existing jobs in increasingly less competitive sectors at all cost, this will likely just defer the problem into the near future and increase the shock once it does occur. Companies could become reluctant to hire and lose ground to competitors making full use of AI capabilities, while workers are displaced in large numbers, rather than gradually when restructuring or business failures do occur. At least initially, flexicurity schemes should focus on high-earning professionals who typically have broader and more complex skill sets, which make it easier for them to transition into new and potentially very different jobs. As AI’s impact on the labour market becomes more pronounced over time, policymakers might need to extend flexicurity to more workers where this is necessary to keep European companies in business.
Europe’s geoeconomic position has to be strong to enable labour market interventions. It will not be possible for Europe to take appropriate policy action and retain optionality if it does not have a sufficient fiscal base from which it can operate and if it is outcompeted by more productive regions. In the past, Europe has been highly effective at designing safety nets and worker protections. However, this cannot be the sole focus for navigating a transition to a world with transformative AI. Europe must create the necessary preconditions and economic strength that will enable it to implement a host of interventions when AI leads to labour market disruptions down the line. Pillar 2 describes how Europe can build economic strength in a world with transformative AI, and Pillar 1 describes how it can use its assets to build leverage and negotiate access to frontier technology. These pillars are the basic elements that will secure Europe’s geoeconomic position in a world with transformative AI.
Four concrete recommendations at the Union and national level that can help Europe prepare for the labour market impacts from transformative AI can be found below. Detailed recommendations for each are provided in Part B of this strategy.
For future policies to be successful, it is essential to build the capacity to monitor and understand labour market effects. Even if one assumes that AI will indeed be transformative, it is difficult to take action on potential labour market effects now, as their exact shape and pace are highly uncertain. Therefore, policymakers should initially focus on building a better understanding of how transformative AI would affect labour markets, building monitoring capacity before disruption occurs. This requires comprehensive wage and headcount statistics as well as adding AI adoption and displacement indicators to official European labour statistics and ensuring they are published regularly (e.g. the European Statistical Office (Eurostat), the European Centre for the Development of Vocational Training (Cedefop), JRC). One important source of information and lead indicator for disruption is the usage data that frontier AI developers hold, including usage patterns, sector-specific use, and the balance between augmentation and automation. The Union could request and negotiate access to this for the purpose of producing official statistics. The UK’s newly formed AI Economics Institute, for example, aims to closely collaborate with AI companies, and Anthropic, Google, OpenAI, and Microsoft have committed to collaborate with the UK government. In the US, the Department of Labor is similarly planning data-sharing agreements with major AI companies, such as OpenAI and Meta.
Labour market flexicurity will be helpful for managing AI labour transitions. The flexicurity approach combines high flexibility for companies to hire, dismiss, and restructure with strong income security and routes into new work for employees. Denmark has used this approach, and the European Commission released common principles for implementing flexicurity in 2007. Flexicurity’s focus on keeping workers employed, employable, and supported through job transitions, rather than protecting specific jobs, makes it an apt framework for AI labour transitions and disruptions. If Europe tries to protect existing jobs in increasingly less competitive sectors at all cost, this will likely just defer the problem into the near future and increase the shock once it does occur. Companies could become reluctant to hire and lose ground to competitors making full use of AI capabilities, while workers are displaced in large numbers, rather than gradually when restructuring or business failures do occur. At least initially, flexicurity schemes should focus on high-earning professionals who typically have broader and more complex skill sets, which make it easier for them to transition into new and potentially very different jobs. As AI’s impact on the labour market becomes more pronounced over time, policymakers might need to extend flexicurity to more workers where this is necessary to keep European companies in business.
Europe’s geoeconomic position has to be strong to enable labour market interventions. It will not be possible for Europe to take appropriate policy action and retain optionality if it does not have a sufficient fiscal base from which it can operate and if it is outcompeted by more productive regions. In the past, Europe has been highly effective at designing safety nets and worker protections. However, this cannot be the sole focus for navigating a transition to a world with transformative AI. Europe must create the necessary preconditions and economic strength that will enable it to implement a host of interventions when AI leads to labour market disruptions down the line. Pillar 2 describes how Europe can build economic strength in a world with transformative AI, and Pillar 1 describes how it can use its assets to build leverage and negotiate access to frontier technology. These pillars are the basic elements that will secure Europe’s geoeconomic position in a world with transformative AI.
Four concrete recommendations at the Union and national level that can help Europe prepare for the labour market impacts from transformative AI can be found below. Detailed recommendations for each are provided in Part B of this strategy.
Recommendations at the Union level
Recommendations at the Union level
1.
Build a monitoring stack for AI labour market impacts. By 2027, establish a Union-level monitoring framework that includes, among other things, regular labour statistics, job-posting data, AI-exposure measures, and information from AI companies.
2.
Fund and steer conditional flexicurity adjustment. Encourage more flexible labour markets where adjustment to AI-driven disruption is already needed, combined with funding for retraining and income support for displaced workers. Prepare an EU-wide emergency support scheme if job losses accelerate sharply.
1.
Build a monitoring stack for AI labour market impacts. By 2027, establish a Union-level monitoring framework that includes, among other things, regular labour statistics, job-posting data, AI-exposure measures, and information from AI companies.
2.
Fund and steer conditional flexicurity adjustment. Encourage more flexible labour markets where adjustment to AI-driven disruption is already needed, combined with funding for retraining and income support for displaced workers. Prepare an EU-wide emergency support scheme if job losses accelerate sharply.
Recommendations at the national level
Recommendations at the national level
1.
Feed into the AI labour market monitoring stack. From 2027, add questions related to AI-driven job displacement to labour force surveys and feed national survey and job vacancy data into the emerging Union-level monitoring.
2.
Prepare high-earner-first flexicurity reforms. Ease dismissal rules for high earners, and prepare broader flexicurity reforms that combine flexible business restructuring with stronger income support and retraining, ensuring that displaced workers receive help within weeks.
1.
Feed into the AI labour market monitoring stack. From 2027, add questions related to AI-driven job displacement to labour force surveys and feed national survey and job vacancy data into the emerging Union-level monitoring.
2.
Prepare high-earner-first flexicurity reforms. Ease dismissal rules for high earners, and prepare broader flexicurity reforms that combine flexible business restructuring with stronger income support and retraining, ensuring that displaced workers receive help within weeks.
Footnotes
Obligations on providers of general-purpose AI models are already applicable and enforceable, and the GPAI Code of Practice is already being relied upon. This section makes recommendations about how the obligations and commitments in the Code should be construed and applied in practice, rather than suggestions for novel policy action or regulation. For this reason, there are no detailed recommendations for this objective in Part B.
Obligations on providers of general-purpose AI models are already applicable and enforceable, and the GPAI Code of Practice is already being relied upon. This section makes recommendations about how the obligations and commitments in the Code should be construed and applied in practice, rather than suggestions for novel policy action or regulation. For this reason, there are no detailed recommendations for this objective in Part B.
18.
See the Cambridge Commentary on EU General-Purpose AI Law for further details.
18.
See the Cambridge Commentary on EU General-Purpose AI Law for further details.
What would be required for a successful European frontier AI project?
What would be required for a successful European frontier AI project?
Many people are interested in the question whether Europe could and should aim to develop frontier AI domestically. A European frontier AI project, if successful, would be highly desirable for securing Europe’s future prosperity, sovereignty, and control over the safe development of AI. It would also reduce Europe’s risk of losing access to the frontier. But it would require substantially more political resolve and financial resources than following a Leverage Approach.
A European frontier AI project must not be half-hearted. A serious push for developing sovereign frontier AI is in principle possible, and desirable under the right conditions – but European leaders have to internalise the stark reality of what is required. Bold political statements and ambitions must be backed up by the extraordinary resources and resolve required to avoid failure. Importantly, a half-hearted European frontier AI project without a well-executed Leverage Approach is arguably the worst of all possible paths: It would leave Europe empty-handed, without either its own frontier model or reliable access to the frontier models of others.
The resources and resolve required for a European frontier AI project are exceptionally high. The required resources would vastly outstrip the current resources being dedicated to AI sovereignty efforts as well as any plans discussed in mainstream European AI policy. Every month, US hyperscalers are spending more than was spent on the entire Manhattan Project in today’s money. This strategy estimates that a serious attempt to catch up to the frontier would cost approximately €800 billion over three years (for order-of-magnitude estimates and ranges see Table 1).
The political resolve required would also be immense. A successful European frontier AI project requires broad coalition-building, a wide-reaching reordering of European industrial priorities, and committing the majority of Europe’s leverage to securing access to chips and defending against foreign intervention instead of securing other near-term goals (see Immediate Objective 1, Objective 1.1, Objective 1.2).
Many people are interested in the question whether Europe could and should aim to develop frontier AI domestically. A European frontier AI project, if successful, would be highly desirable for securing Europe’s future prosperity, sovereignty, and control over the safe development of AI. It would also reduce Europe’s risk of losing access to the frontier. But it would require substantially more political resolve and financial resources than following a Leverage Approach.
A European frontier AI project must not be half-hearted. A serious push for developing sovereign frontier AI is in principle possible, and desirable under the right conditions – but European leaders have to internalise the stark reality of what is required. Bold political statements and ambitions must be backed up by the extraordinary resources and resolve required to avoid failure. Importantly, a half-hearted European frontier AI project without a well-executed Leverage Approach is arguably the worst of all possible paths: It would leave Europe empty-handed, without either its own frontier model or reliable access to the frontier models of others.
The resources and resolve required for a European frontier AI project are exceptionally high. The required resources would vastly outstrip the current resources being dedicated to AI sovereignty efforts as well as any plans discussed in mainstream European AI policy. Every month, US hyperscalers are spending more than was spent on the entire Manhattan Project in today’s money. This strategy estimates that a serious attempt to catch up to the frontier would cost approximately €800 billion over three years (for order-of-magnitude estimates and ranges see Table 1).
The political resolve required would also be immense. A successful European frontier AI project requires broad coalition-building, a wide-reaching reordering of European industrial priorities, and committing the majority of Europe’s leverage to securing access to chips and defending against foreign intervention instead of securing other near-term goals (see Immediate Objective 1, Objective 1.1, Objective 1.2).
Item
Description
Approximate central estimate (range)
Item
Description
Approximate central estimate (range)
Sector buy-in
Buying some coalition AI companies outright, for their teams, intellectual property, and datasets.
~€25 billion
(~€10–40 billion)
Sector buy-in
Buying some coalition AI companies outright, for their teams, intellectual property, and datasets.
~€25 billion
(~€10–40 billion)
Compute
Accelerators and the data centres to house them: 16 GW of IT load built (roughly 18 GW of total facility power), of which roughly 9 GW of IT load would be running by 2029.
~€529 billion
(~€320–640 billion)
Compute
Accelerators and the data centres to house them: 16 GW of IT load built (roughly 18 GW of total facility power), of which roughly 9 GW of IT load would be running by 2029.
~€529 billion
(~€320–640 billion)
Data centre operations
Electricity, maintenance, and taxes for running the data centres.
~€13 billion
(~€11–43 billion)
Data centre operations
Electricity, maintenance, and taxes for running the data centres.
~€13 billion
(~€11–43 billion)
Interim compute
Compute rented from others to bridge the gap until the coalition’s own clusters come online (7 GW-years in IT load total).
~€105 billion
(~€58–158 billion)
Interim compute
Compute rented from others to bridge the gap until the coalition’s own clusters come online (7 GW-years in IT load total).
~€105 billion
(~€58–158 billion)
Training data and reinforcement learning (RL) environments
Expert human data and feedback, licensed content, training environments, and a one-off collection of books.
~€3.5 billion
(~€2–6 billion)
Training data and reinforcement learning (RL) environments
Expert human data and feedback, licensed content, training environments, and a one-off collection of books.
~€3.5 billion
(~€2–6 billion)
Personnel and operations
Pay for the founders, senior researchers, and ~3,000 further staff; equity buy-outs; and recruiting and operational costs.
~€34 billion (~€15–40 billion)
Personnel and operations
Pay for the founders, senior researchers, and ~3,000 further staff; equity buy-outs; and recruiting and operational costs.
~€34 billion (~€15–40 billion)
External coding agents
Access to frontier coding agents, bought from existing developers for at least the first 18 months.
~€3 billion
(~€2–5 billion)
External coding agents
Access to frontier coding agents, bought from existing developers for at least the first 18 months.
~€3 billion
(~€2–5 billion)
Political insulation
Payments shielding households, energy-intensive industry, and host regions from the project’s effects, plus AI dividends.
~€80 billion
(~€25–110 billion)
Political insulation
Payments shielding households, energy-intensive industry, and host regions from the project’s effects, plus AI dividends.
~€80 billion
(~€25–110 billion)
TOTAL
~€790 billion
(~€445–1,040 billion)
TOTAL
~€790 billion
(~€445–1,040 billion)
Table 1 | Order-of-magnitude back-of-the-envelope calculation (BOTEC) for the cost of the first three years of a European frontier AI project. All estimates are approximate and should be considered as order-of-magnitude estimates. For further details and sources for these estimates, please see Part B.
A European frontier AI project would require adapting some elements of the transformative AI strategy. Most of the leverage-focused transformative AI strategy presented above remains in place if Europe wants to attempt a frontier AI project (for more detail see Part B). However, some recommendations would change in terms of substance or prioritisation:
Table 1 | Order-of-magnitude back-of-the-envelope calculation (BOTEC) for the cost of the first three years of a European frontier AI project. All estimates are approximate and should be considered as order-of-magnitude estimates. For further details and sources for these estimates, please see Part B.
A European frontier AI project would require adapting some elements of the transformative AI strategy. Most of the leverage-focused transformative AI strategy presented above remains in place if Europe wants to attempt a frontier AI project (for more detail see Part B). However, some recommendations would change in terms of substance or prioritisation:
Regarding compute buildout (Immediate Objective 3), Europe should use its most attractive data centre sites to meet such a project’s demands, with a substantial planned buffer. This limits the amount of scarce grid capacity that could be used for compute-for-access deals with frontier AI companies (Objective 1.1).
Europe would have to use its leverage to buy large amounts of AI chips for a frontier AI project and secure access to state-of-the-art coding agents for its early stages, rather than use the same leverage mainly to secure long-term access to frontier AI models for broad economic integration (Immediate Objective 1).
Proprietary data should be seen as a competitive advantage that can be pooled and used to train models, rather than an asset that can be exchanged for frontier AI access (Immediate Objective 1, Objective 2.2). European manufacturing companies should be encouraged to partner with the European project, rather than deeply integrate with foreign frontier AI developers (Objective 2.2).
Once a European frontier project is producing sufficiently capable models, even if they still lag behind the frontier, there is a stronger case for European institutions to procure these rather than foreign frontier models, at least in cases where this does not result in severe security risks (Objective 1.1, Immediate Objective 2). In expectation, European institutions and companies would be using worse models for a few years.
Regarding compute buildout (Immediate Objective 3), Europe should use its most attractive data centre sites to meet such a project’s demands, with a substantial planned buffer. This limits the amount of scarce grid capacity that could be used for compute-for-access deals with frontier AI companies (Objective 1.1).
Europe would have to use its leverage to buy large amounts of AI chips for a frontier AI project and secure access to state-of-the-art coding agents for its early stages, rather than use the same leverage mainly to secure long-term access to frontier AI models for broad economic integration (Immediate Objective 1).
Proprietary data should be seen as a competitive advantage that can be pooled and used to train models, rather than an asset that can be exchanged for frontier AI access (Immediate Objective 1, Objective 2.2). European manufacturing companies should be encouraged to partner with the European project, rather than deeply integrate with foreign frontier AI developers (Objective 2.2).
Once a European frontier project is producing sufficiently capable models, even if they still lag behind the frontier, there is a stronger case for European institutions to procure these rather than foreign frontier models, at least in cases where this does not result in severe security risks (Objective 1.1, Immediate Objective 2). In expectation, European institutions and companies would be using worse models for a few years.
The starting conditions, compute, talent, and sustaining conditions required for Europe to achieve a successful European frontier AI project are presented below and in more detail in Part B.
The starting conditions, compute, talent, and sustaining conditions required for Europe to achieve a successful European frontier AI project are presented below and in more detail in Part B.
Starting conditions
Starting conditions
Form a coalition of aligned countries. A successful European frontier AI project must begin with a coalition of value-aligned, liberal democracies working together – no country alone would succeed. Europe, as the largest established political bloc among likely participants and possessing the largest economic, industrial, and fiscal base among them, is the natural foundation of such a frontier AI project among trusted partners. Adding other countries to the coalition, especially so-called ‘middle powers’ facing constraints similar to those of the European Union, increases the chance of success since they can provide valuable assets (see Figure 12). Of course, in choosing members, a coalition has to consider the tradeoff between size and political cohesion, the risk of defection, and the potential actions of non-coalition countries. The more costly binding commitment mechanisms, the better.
Form a coalition of aligned countries. A successful European frontier AI project must begin with a coalition of value-aligned, liberal democracies working together – no country alone would succeed. Europe, as the largest established political bloc among likely participants and possessing the largest economic, industrial, and fiscal base among them, is the natural foundation of such a frontier AI project among trusted partners. Adding other countries to the coalition, especially so-called ‘middle powers’ facing constraints similar to those of the European Union, increases the chance of success since they can provide valuable assets (see Figure 12). Of course, in choosing members, a coalition has to consider the tradeoff between size and political cohesion, the risk of defection, and the potential actions of non-coalition countries. The more costly binding commitment mechanisms, the better.
Figure 12
Figure 12 | The assets and strengths of potential coalition partners. An assessment of the main assets each partner would contribute to a European frontier AI project. Source: Own figure.
Figure 12
Figure 12 | The assets and strengths of potential coalition partners. An assessment of the main assets each partner would contribute to a European frontier AI project. Source: Own figure.
Set up a new private company. A European frontier AI project would need a new¹⁹ private company to be set up that receives full and sustained backing by the coalition’s governments, including their national security apparatus (to ensure integration into the intelligence communities and their resources), trade authorities (to secure the supply chain), and treasuries (for financing).
Use previously successful institutional designs for developing frontier AI. This private company should broadly be modelled on existing frontier AI developers, since this is the only existing institutional form that has produced frontier AI models and systems, and because the coalition will not have time to experiment if transformative AI arrives soon. It should be led by a highly empowered leadership group with world-class, demonstrated research judgement, exceptional communication skills, and experience in building and scaling very large organisations. Like today’s leading frontier companies, this private company has to be at once a research laboratory and an execution-focused company: Small teams of researchers need sufficient capacity and independence to explore novel technical approaches, while the majority of the company needs to be focused on pursuing the most promising path towards powerful AI systems.
Set up governance structures that enable innovation, safety, and speed. The private company’s governance structure is mirrored by a complementary government structure that must remain separate from technical operations to prevent the type of bureaucratic slowing down of execution to which a conventional government programme would be susceptible. Countries should appoint ministerial or state-secretary level senior project leads supported by high-calibre frontier AI policy specialists, akin to the United Kingdom’s Frontier AI Taskforce that became the first AISI, that would interface between the frontier project and the coalition’s governments. Of course, a European frontier project has to comply with the systemic risk obligations for general-purpose AI models as set out in the AI Act and detailed in the Code of Practice.
Put in place sufficient public budget funding. A European frontier AI project could cost approximately €800 billion over three years (see Table 1). That funding should predominantly come from public budgets and dedicated debt instruments where treasuries, pension funds, sovereign wealth funds, and related institutions provide direct funding for the initial three-year costs as necessary. The reason for this is that Europe does not have a venture market at the necessary scale (or the time to build one) or the required private financing, while it does have the needed borrowing capacity. Coalition countries should expect to fund most of these upfront costs, with the expectation that private capital and significant revenue only follow later. Coalition governments should set up any required executive and legislative mechanisms. At founding, ownership should be fully public, while upon listing the coalition governments could remain anchor shareholders. This would allow the coalition to retain ownership and create a public asset and sovereign investment that can be privatised through European capital markets.
Establish commitment mechanisms. Coalition governments should precommit funding and infrastructure access for the complete setup period. Withdrawing from the coalition should mean that a member forfeits its contribution and stake, and no single country withdrawing should result in the project not having sufficient resources to continue. Technical progress needs to be independently assessed at fixed intervals with pre-agreed criteria for when the project should be discontinued, converted into its compute and talent assets, or allocated additional resources.
Set up a new private company. A European frontier AI project would need a new¹⁹ private company to be set up that receives full and sustained backing by the coalition’s governments, including their national security apparatus (to ensure integration into the intelligence communities and their resources), trade authorities (to secure the supply chain), and treasuries (for financing).
Use previously successful institutional designs for developing frontier AI. This private company should broadly be modelled on existing frontier AI developers, since this is the only existing institutional form that has produced frontier AI models and systems, and because the coalition will not have time to experiment if transformative AI arrives soon. It should be led by a highly empowered leadership group with world-class, demonstrated research judgement, exceptional communication skills, and experience in building and scaling very large organisations. Like today’s leading frontier companies, this private company has to be at once a research laboratory and an execution-focused company: Small teams of researchers need sufficient capacity and independence to explore novel technical approaches, while the majority of the company needs to be focused on pursuing the most promising path towards powerful AI systems.
Set up governance structures that enable innovation, safety, and speed. The private company’s governance structure is mirrored by a complementary government structure that must remain separate from technical operations to prevent the type of bureaucratic slowing down of execution to which a conventional government programme would be susceptible. Countries should appoint ministerial or state-secretary level senior project leads supported by high-calibre frontier AI policy specialists, akin to the United Kingdom’s Frontier AI Taskforce that became the first AISI, that would interface between the frontier project and the coalition’s governments. Of course, a European frontier project has to comply with the systemic risk obligations for general-purpose AI models as set out in the AI Act and detailed in the Code of Practice.
Put in place sufficient public budget funding. A European frontier AI project could cost approximately €800 billion over three years (see Table 1). That funding should predominantly come from public budgets and dedicated debt instruments where treasuries, pension funds, sovereign wealth funds, and related institutions provide direct funding for the initial three-year costs as necessary. The reason for this is that Europe does not have a venture market at the necessary scale (or the time to build one) or the required private financing, while it does have the needed borrowing capacity. Coalition countries should expect to fund most of these upfront costs, with the expectation that private capital and significant revenue only follow later. Coalition governments should set up any required executive and legislative mechanisms. At founding, ownership should be fully public, while upon listing the coalition governments could remain anchor shareholders. This would allow the coalition to retain ownership and create a public asset and sovereign investment that can be privatised through European capital markets.
Establish commitment mechanisms. Coalition governments should precommit funding and infrastructure access for the complete setup period. Withdrawing from the coalition should mean that a member forfeits its contribution and stake, and no single country withdrawing should result in the project not having sufficient resources to continue. Technical progress needs to be independently assessed at fixed intervals with pre-agreed criteria for when the project should be discontinued, converted into its compute and talent assets, or allocated additional resources.
Compute
Compute
Build sufficient compute infrastructure and energy supply. A European frontier project would require substantial compute to compete, though likely somewhat less than a leading US developer requires over the same period due to lower customer-serving inference demand. It should aim for approximately 16 GW of AI compute capacity (IT load) at an expected cost of around €529 billion. Bringing this amount of compute online comes with a range of logistical challenges that a European coalition can nevertheless meet if it acts as it has previously in crisis conditions. This includes implementing accelerated infrastructure programmes in a range of host countries that can build out at scale and at great speed.
Procure interim rental compute. Until the dedicated clusters become operational, a European frontier AI project would have to procure rental compute by consolidating and requisitioning existing publicly owned supercomputers as well as rent compute on the open graphics processing unit (GPU) market (at a combined cost of approximately €105 billion).
Set up a coercion shield. A European frontier AI project has to consider the difficulty that is likely to arise in acquiring sufficient AI chips given competition for a limited supply and potential export controls. To secure sufficient chip supply, the European frontier AI project should rely on agreements wherever possible, but prepare trade policy measures (see Immediate Objective 1, Union-level recommendations 1 and 2) that can capitalise on Europe’s semiconductor supply-chain leverage, and are only activated reciprocally if exports are blocked. In addition, narrower export deals might be necessary to sustain the European project, which condition the continued provision of European semiconductor inputs on continued access to US frontier chips. However, this would be very risky since it commits significant amounts of Europe’s AI-related leverage to the frontier AI project rather than to securing access to foreign frontier AI models. Participation in this coercion shield would also be costly for the European semiconductor companies whose export ability would be used as leverage. Europe could address this through a fund that would compensate any participating company or government that suffers substantial losses from this use of European leverage.
Build sufficient compute infrastructure and energy supply. A European frontier project would require substantial compute to compete, though likely somewhat less than a leading US developer requires over the same period due to lower customer-serving inference demand. It should aim for approximately 16 GW of AI compute capacity (IT load) at an expected cost of around €529 billion. Bringing this amount of compute online comes with a range of logistical challenges that a European coalition can nevertheless meet if it acts as it has previously in crisis conditions. This includes implementing accelerated infrastructure programmes in a range of host countries that can build out at scale and at great speed.
Procure interim rental compute. Until the dedicated clusters become operational, a European frontier AI project would have to procure rental compute by consolidating and requisitioning existing publicly owned supercomputers as well as rent compute on the open graphics processing unit (GPU) market (at a combined cost of approximately €105 billion).
Set up a coercion shield. A European frontier AI project has to consider the difficulty that is likely to arise in acquiring sufficient AI chips given competition for a limited supply and potential export controls. To secure sufficient chip supply, the European frontier AI project should rely on agreements wherever possible, but prepare trade policy measures (see Immediate Objective 1, Union-level recommendations 1 and 2) that can capitalise on Europe’s semiconductor supply-chain leverage, and are only activated reciprocally if exports are blocked. In addition, narrower export deals might be necessary to sustain the European project, which condition the continued provision of European semiconductor inputs on continued access to US frontier chips. However, this would be very risky since it commits significant amounts of Europe’s AI-related leverage to the frontier AI project rather than to securing access to foreign frontier AI models. Participation in this coercion shield would also be costly for the European semiconductor companies whose export ability would be used as leverage. Europe could address this through a fund that would compensate any participating company or government that suffers substantial losses from this use of European leverage.
Talent
Talent
Attract leading frontier AI talent. To acquire the highest-quality researchers, the European frontier AI project must hire leading former frontier AI developer employees. Such employees have valuable expertise that is essential for a European frontier AI project. To hire them requires sufficient compensation and a credible mission. In total, expenditure for founders, senior researchers, the broad technical workforce, equity buy-outs, and operational costs could run to the order of €34 billion. Recruiting and empowering respected technical leaders who can communicate, evidence, and shape the technical vision is the most effective way to ensure the mission is credible. Such founding group members are likely to be motivated by patriotism, a new technical challenge, operational independence, and credible signals that their work will be supported. They are integral for being able to hire the broader technical talent required to execute a European frontier AI project.
Secure access to frontier coding agents. A European frontier AI project must secure access to frontier-level coding agents before it develops its own. A substantial share of research work at frontier AI developers is already performed by AI agents that write code and complete R&D and administrative tasks under the direction of human researchers and this is only likely to increase. Obtaining such access may be difficult²⁰ but it is likely possible if leading developers see commercial or reputational value in offering access, sufficient compute is secured to host AI agents on European infrastructure, and the budget for procurement is in place (approximately €3 billion over the first 18 months). In addition, such a project will have to budget for additional costs of approximately €3.5 billion for training data and RL environments.
Attract leading frontier AI talent. To acquire the highest-quality researchers, the European frontier AI project must hire leading former frontier AI developer employees. Such employees have valuable expertise that is essential for a European frontier AI project. To hire them requires sufficient compensation and a credible mission. In total, expenditure for founders, senior researchers, the broad technical workforce, equity buy-outs, and operational costs could run to the order of €34 billion. Recruiting and empowering respected technical leaders who can communicate, evidence, and shape the technical vision is the most effective way to ensure the mission is credible. Such founding group members are likely to be motivated by patriotism, a new technical challenge, operational independence, and credible signals that their work will be supported. They are integral for being able to hire the broader technical talent required to execute a European frontier AI project.
Secure access to frontier coding agents. A European frontier AI project must secure access to frontier-level coding agents before it develops its own. A substantial share of research work at frontier AI developers is already performed by AI agents that write code and complete R&D and administrative tasks under the direction of human researchers and this is only likely to increase. Obtaining such access may be difficult²⁰ but it is likely possible if leading developers see commercial or reputational value in offering access, sufficient compute is secured to host AI agents on European infrastructure, and the budget for procurement is in place (approximately €3 billion over the first 18 months). In addition, such a project will have to budget for additional costs of approximately €3.5 billion for training data and RL environments.
Sustaining conditions
Sustaining conditions
Remain robust to domestic political pressures. To be successful, a European frontier AI project must remain robust against political pressures, such as weakening motivation from coalition members and increasing public contestation due to the economic impacts and risks of AI. Efforts should be made to mitigate such pressures in advance, for example, by measures, such as committing to protect households from energy price increases caused by the project, direct AI dividends to affected groups, electricity subsidies for industries with high energy use, and community benefit schemes for data centre host regions.
Aim for successful long-term commercialisation. Once the frontier is reached, achieving some measure of commercial success will be required for continued success. The European frontier AI project will have to compete with the sophisticated product expertise, established consumer distribution, and lucrative enterprise contracts of established AI developers. Becoming the main provider of frontier AI to coalition governments, supplying private actors with high security requirements, and, where necessary, adopting measures to increase the use of European frontier AI by domestic businesses can help achieve successful commercialisation. A European frontier model could also find broad international appeal by being seen as more trustworthy and coming with fewer restrictions than those of leading competitor countries.
Remain robust to domestic political pressures. To be successful, a European frontier AI project must remain robust against political pressures, such as weakening motivation from coalition members and increasing public contestation due to the economic impacts and risks of AI. Efforts should be made to mitigate such pressures in advance, for example, by measures, such as committing to protect households from energy price increases caused by the project, direct AI dividends to affected groups, electricity subsidies for industries with high energy use, and community benefit schemes for data centre host regions.
Aim for successful long-term commercialisation. Once the frontier is reached, achieving some measure of commercial success will be required for continued success. The European frontier AI project will have to compete with the sophisticated product expertise, established consumer distribution, and lucrative enterprise contracts of established AI developers. Becoming the main provider of frontier AI to coalition governments, supplying private actors with high security requirements, and, where necessary, adopting measures to increase the use of European frontier AI by domestic businesses can help achieve successful commercialisation. A European frontier model could also find broad international appeal by being seen as more trustworthy and coming with fewer restrictions than those of leading competitor countries.
Footnotes
A new entity would very likely be needed to attract the necessary talent, but this new entity could absorb interested companies from coalition countries that hold existing talent and technical expertise.
A new entity would very likely be needed to attract the necessary talent, but this new entity could absorb interested companies from coalition countries that hold existing talent and technical expertise.
Pillar 1
Pillar 2
Pillar 3
Pillar 1
Pillar 2
Pillar 3