DEV Community

Auton AI News
Auton AI News

Posted on Originally published at autonainews.com

EU AI Act’s GPAI Model Evaluation Rules Draw Industry Pushback

Key Takeaways

  • The EU AI Act’s GPAI enforcement phase began August 2, 2026, requiring adversarial testing and incident reporting for models trained above 10^25 FLOPs or with more than 10,000 registered business users.
  • A July 2026 open letter signed by over 30 companies including Nvidia and Microsoft warned that restricting open-weight models would concentrate AI capability in too few hands, exposing the fault line between safety mandates and IP protection.
  • Google DeepMind‘s August 2026 double-blind evaluation pilot, using confidential computing to shield both test prompts and model weights, offers a working template for IP-safe compliance audits under frameworks like the EU AI Act. On August 2, 2026, the EU AI Act’s enforcement clock started on GPAI model rules, putting frontier AI developers on notice that adversarial testing and incident reporting are now legal obligations, not voluntary commitments. The practical question, how regulators inspect a model without seeing its weights, and how developers comply without exposing their IP, has no settled answer, and the race to find one is reshaping how the industry thinks about safety auditing.

Regulators Align on Model Testing

Across three jurisdictions, regulators have converged on mandatory evaluation as the primary tool for governing powerful AI. The EU AI Act sets the most detailed requirements. Providers of GPAI models that exceed 10^25 FLOPs of training compute, or that reach more than 10,000 registered business users, face obligations including model evaluations, documented adversarial testing, and direct incident reporting to the AI Office. The AI Office retains authority to conduct its own evaluations at any point, whether for compliance checks or systemic-risk investigations.

High-risk AI system rules covering areas such as hiring, credit and healthcare are on a separate timeline, phasing in under the AI Omnibus in late 2027 and 2028. That stagger gives deployers some runway, but GPAI providers have no equivalent grace period.

In the United States, the Biden administration’s Executive Order 14110, signed in October 2023, required developers of dual-use foundation models to report training parameters, model weights and red-team results to the federal government. It also directed NIST to develop red-team testing standards. The order’s status became uncertain after the change in administration in January 2025, but NIST’s AI standards work and federally funded safety research have continued, and the EO’s framing still shapes procurement expectations. Federal agencies buying large language models are required, as of March 2026 per OMB M-26-04, to request model cards, evaluation artefacts and acceptable-use policies from vendors.

The UK AI Safety Institute, launched at the Bletchley Park AI Safety Summit in November 2023, takes a pre- and post-deployment approach, using its open-source Inspect framework to assess coding, agentic, reasoning and behavioural capabilities. AISI’s early evaluations found performance in some cyber domains doubling roughly every eight months, though the institute has not published a methodology for that rate that external researchers have independently validated.

Cost and IP: Industry’s Core Objections

A February 2026 survey commissioned by ACT | The App Association estimated that EU and UK tech startups lose an average of €94,000 to €322,000 annually per firm from delayed AI launches attributable to ex-ante regulatory requirements, rising to €160,000 to €453,000 for small firms directly in scope. The figures come from a trade association, so they should be read as industry estimates rather than independent research, but the order of magnitude is consistent with what compliance work at that scale typically costs.

IP exposure is the more structurally difficult objection. Model weights encode proprietary training decisions accumulated over years and billions of dollars of compute. Sharing them with a regulator or auditor creates a surface for theft or reverse-engineering that developers argue no contractual protection fully addresses. A July 2026 open letter, “Open Weights and American AI Leadership,” signed by more than 30 companies including Nvidia, Microsoft and Meta made the case that restricting open-weight models would push AI development toward a small number of closed incumbents. The letter framed openness itself as a safety mechanism, allowing operators to inspect, adapt and audit models rather than relying on developer assurances.

That argument sits in tension with regulators’ view that transparency requires more than published weights, it requires structured evaluation against defined risk criteria, conducted by parties without a commercial stake in the outcome. The EU AI Act’s GPAI enforcement framework assumes that model access for evaluation purposes can be governed by confidentiality protections, but the mechanism for enforcing those protections at the technical level has remained underdeveloped until recently.

Confidential Computing as a Bridge

On August 27, 2026, Google DeepMind launched what it describes as the world’s first double-blind evaluation for frontier AI models, run in partnership with the Singapore AI Safety Institute, OpenMined, MLCommons and AVERI. The pilot used Google Cloud’s Confidential Computing infrastructure to run evaluations inside a secure enclave where neither the evaluator nor the developer could access the other’s data. Test prompts from the evaluating organisation were encrypted before entering the enclave; model weights from Google DeepMind were encrypted on the other side. Neither party saw what the other contributed; only the outputs were released, under terms both parties approved in advance.

The design targets two problems simultaneously. Benchmark contamination, where a developer trains a model against known test sets to inflate scores, is prevented because the developer never sees the prompts. IP leakage is prevented because the evaluator never sees the weights. The February 2026 NIST report on AI evaluation integrity had identified both as live risks in current third-party assessment practice.

The pilot tested Gemini 2.5 Flash-Lite. Whether the approach scales to models with more complex inference pipelines, or to evaluators without access to Google Cloud infrastructure, is a practical question the pilot does not yet answer, but as a proof of concept for IP-safe, saturation-resistant auditing, it directly addresses the objection that compliance and confidentiality are mutually exclusive.

Third-Party Auditing’s Structural Gaps

Independent auditing is widely cited as the accountability layer that self-reporting cannot provide, but its institutional infrastructure is still thin. Organisations including METR (Model Evaluation and Threat Research), Apollo Research, and the UK and US AISIs conduct pre-deployment evaluations under compute-credit arrangements with labs such as OpenAI and Anthropic. A January 2026 arXiv paper on frontier AI auditing found that even the best current assessments lack features standard in more mature regulated industries, including auditor access to non-public operational data and standardised reporting formats.

Deb Raji, a fellow at the Mozilla Foundation and the Algorithmic Justice League, proposed in October 2021 a framework for mandatory third-party algorithmic audits in the US. The proposal called for a national incident-reporting system to prioritise which systems get audited, an independent oversight board to certify auditors and set standards, and regulator-facilitated data access for certified auditors. Raji’s core argument is that internal audits are conducted before deployment, focus on intended users rather than affected communities, and are rarely published, and that companies have sometimes provided misleading information in voluntary assessments.

The concern is not theoretical. External audits have surfaced algorithmic biases that internal teams did not surface or did not disclose, in contexts ranging from facial recognition used in law enforcement to credit-scoring systems. The structural problem is that deep model access, the kind needed to find the most serious failure modes, requires either legal compulsion or a degree of trust between lab and auditor that is difficult to establish without the kind of institutional framework Raji’s proposal envisions. The compliance frameworks now being built under the EU AI Act may eventually create that structure, but the audit profession itself is still being defined.

Compliance in Practice

For providers in scope under the EU AI Act’s GPAI rules, the obligations that took effect on August 2, 2026 are already live. Automatic event logging, technical documentation, adversarial testing records and incident reporting to the AI Office are all current requirements, not upcoming ones. Providers must also share sufficient information with deployers to allow proper use, and deployers bear their own obligations around human oversight and input data quality.

At the state level in the US, Colorado’s algorithmic discrimination requirements under SB 24-205 were set to arrive by June 30, 2026, adding another layer of compliance testing for developers and deployers operating in that market. Overlapping jurisdictional requirements, federal procurement rules, state anti-discrimination mandates, and the EU’s cross-border enforcement reach, mean that for any company with international operations or US federal contracts, compliance is not a single exercise. It is an ongoing process that likely requires both internal evaluation capability and periodic engagement with external auditors.

Google DeepMind’s August 2026 pilot produced one working answer to the IP-versus-transparency dilemma. Whether regulators in Brussels, Washington or London formalise confidential computing as an accepted audit mechanism is the question that will determine how that answer scales.


Originally published at https://autonainews.com/eu-ai-acts-gpai-model-evaluation-rules-draw-industry-pushback/

Top comments (0)