Rules Without Models: Why Europe Must Build the AI It Regulates
1 Introduction: A European Decade of Rules Without Models
The European Union (EU) has spent a decade building a digital constitution. The General Data Protection Regulation (GDPR), the Digital Services Act, the Digital Markets Act, the Data Governance Act, the Data Act, the AI Act, and the proposed Cloud and AI Development Act (CADA) of June 2026 together sketch a polity’s stance on the digital.Footnote 1 Seen alone, each is a piece of regulation. Seen together, they are the draft of a legal architecture for a technology whose design and supply Europe does not control. A decade of rule-making has produced a Europe that others are legally obliged to consider yet can ignore technologically. The evidence accumulated for years and, by mid-2026, was overwhelming.
In March 2023, the Italian Garante for the Protection of Personal Data ordered an urgent limitation on OpenAI’s processing of Italian users’ personal data on GDPR grounds. OpenAI withdrew ChatGPT from Italian users, reinstated it a month later after implementing the measures the Garante required, and was fined.Footnote 2 The Garante’s action was widely read as a demonstration of European regulatory power. In fact, it showed the limits of exercising regulatory power over a foreign product. Compliance was obtained; availability was not, because no order can require a foreign provider to serve a market it is willing to leave. The fine was annulled by the Court of Rome on 18 March, 2026 on jurisdictional grounds, leaving the substantive GDPR questions unresolved, and the model itself remained American throughout.
In April 2025, Meta released Llama 4 under a licence withholding from individuals domiciled in the EU and companies with a principal place of business in the Union the rights to the multimodal model materials, a clause first imposed on the Llama 3.2 multimodal models in September 2024 and carried forward in identical wording.Footnote 3 The Open Source Initiative was categorical: this is not open source, and EU-domiciled developers are excluded from the rights in what is marketed as the American open-source alternative.Footnote 4 The exclusion was chosen rather than imposed: no Union rule required it, and the multimodal materials were withheld from EU-domiciled developers rather than released on the Union’s regulatory terms. In this case, regulation without infrastructure was insufficient even to keep the alternative available.
In June 2026, the United States Department of Commerce ordered Anthropic to restrict access to Claude Fable 5 and Claude Mythos 5 for foreign nationals, wherever located, including the firm’s own non-US staff. Anthropic could not verify nationality request by request, so it disabled both models worldwide on 12 June 2026.Footnote 5 Access was restored piecemeal after two weeks of negotiations between the company and the administration: following approval on 26 June, Mythos 5 was restored to more than one hundred US companies and institutions, and the export controls on both models were lifted on 30 June, with global access to Fable 5 restored the following day. Austria formally wrote to Executive Vice-President Henna Virkkunen on 27 June, before the controls were lifted, asking the Commission to host Anthropic within the Union.Footnote 6 What matters here is not the final resolution but the vulnerability revealed by the episode: a single directive from a foreign government took frontier models off the European table overnight, and the restoration was secured only through Anthropic’s negotiations with its own government rather than through any European lever. The models used by Europeans are subject to foreign discretion, and Mythos 5 remained restricted to a small group of vetted partners, with wider release stated as a goal rather than a date.
On 7 July 2026, Reuters reported that Chinese authorities, including commerce ministry officials, had held meetings with Alibaba, ByteDance, and Z.ai to discuss restricting foreign access to their most capable AI models, closed- and open-weight alike, with the Qwen, Doubao, and GLM families named as those affected.Footnote 7 At the beginning of August 2026, nothing had been decided, but the direction was clear. European developers who had relied on Chinese open-weight models as a cheaper alternative to expensive American systems found themselves dependent on a supply subject to a foreign ministry’s discretion and moving towards closure. Open weights, it turned out, were a variable, not a constant, of the European digital future.
Beneath all of this, the CLOUD Act, adopted by the United States in 2018, gives United States authorities a lawful procedure to compel the disclosure of data within the possession, custody, or control of providers subject to United States jurisdiction, wherever the servers sit, potentially placing the provider in conflict with the European law that governs where the data may be processed.Footnote 8 The question is not where the data sit, but which sovereign has legal standing to compel disclosure through its own courts. Where the provider falls within that jurisdiction, the United States is one such sovereign, regardless of where the servers are located.
These are three decided episodes, one reported deliberation, and one standing condition of the same problem. In every case, Europe retained nominal access to the technology but lost effective control over the terms. The episodes themselves are not in dispute; what this article argues is that the right name for the condition is demotion, and that the remedy follows from the name. The Union has built a coherent legal framework for AI. It has not yet built the institutional framework that the legal one presupposes. The standard European reply to complaints about regulatory density – that compliance costs are worth their price – concedes too much. That reply has an institutional face in the Commission’s stated preference (see § 6) for networking and strengthening what exists rather than building: regulate and coordinate, rather than provide. Anu Bradford has argued that European regulation may itself become a source of commercial advantage where consumers prefer applications that adhere to high regulatory standards. Both the thesis and its extension into AI have been contested.Footnote 9 However, in regulated public-procurement markets, a European public capability compliant with the GDPR and the AI Act, by construction, carries a real advantage in cost, friction, and regulatory risk, even if not an exclusive one, since foreign providers can comply too. What converts advantage into a gate is CADA’s Union assurance levels, the graduated procurement requirements (see § 5), which attach to the services through which models are delivered and whose strictest tier turns on ownership, control, and jurisdiction. Admittedly, the scope is limited: GDPR compliance did not displace Google or Meta in consumer network markets, where compliance is a floor, not a differentiator. But procurement is where the sovereign uses of AI concentrate, and where the conversion bites.
In the rest of this article, I shall argue that the correction is not more regulation. It is a European public institution for the models themselves, developed as genuinely open source and certified by design in compliance with European law, where ‘certified’ means demonstrable compliance, not a formal conformity assessment. Three complementary pathways lead to that institution: an industrial consortium that triggers the process, a Member-State-led vehicle that opens national defence and industrial resources, and a European Joint Undertaking that gives multi-decade institutional stability. The technical route that makes all three realistic in the near term is distillation from models genuinely compliant with the Open Source AI Definition (OSAID). I shall call the institution European Open Source AI, EOSAI for short. The call for a European public digital capability is not mine alone, and § 6 places this proposal among its neighbours; the article adds the three pathways, sequenced by their legal natures, and a technical route that makes them buildable now. A final clarification: EOSAI names neither a single legal entity nor a family of models, but a federated public capability, of which the three vehicles of §§ 4–6 are the organs, each with its own legal form, resource base, and lifespan.
2 Two-tier Sovereignty and the CLOUD Act as Permanent Backdrop
Sovereignty over AI has at least two layers. The model layer concerns whose weights, training data, governance, intellectual property, and technical decisions are in question. The deployment layer concerns where the model runs, under whose jurisdiction, with whose data residency, on what terms of service, and with what recourse in the event of a dispute. The distinction matters because a provider can deliver on one layer while failing on the other, and the two failures compound: a European commercial firm that trains its own model on foreign cloud infrastructure delivers model-layer sovereignty and forfeits deployment-layer sovereignty in the same breath.
The vocabulary needs to be defended before it carries any more weight. I have argued elsewhere that digital sovereignty is best understood as a form of control: the ability to determine what happens to data, software, standards, and services, and by whom (Floridi, 2020). The fight over it is about who holds that ability, not over territory. Extending sovereignty to the digital is contested. In particular, Mueller (2020) has argued that the extension is a mistake: the infrastructure is transnational, its governance is distributed across firms, protocols, and standards bodies, and projecting a territorial concept onto it produces confusion in theory and nationalism in practice. However, the objection concerns sovereignty as territorial control, so it is as dated as its target. For it does not concern sovereignty as legal standing, which is the juridical face of control: the question of which authority can lawfully compel, restrict, or withdraw is posed, and answered, at every layer of the stack, and the episodes discussed in § 1 are so many answers. For instance, the Garante showed European standing over conduct, while standing over model supply, withdrawal, and extraterritorial access remained non-European. The annulment cuts a further way: it turned on which European authority held competence, so the standing Europe has is itself distributed in ways that dilute it. The record’s force lies in capability, not frequency: it shows who holds the standing to close access, not how often access closes. Standing, so understood, has three faces: jurisdiction, the power to compel through one’s own courts; infrastructural capability, the power to operate without another’s permission; and non-domination, freedom from another’s discretionary power. They are discussed in § 7. Here, it is important to anticipate that the three are linked but separate, since each can fail alone: jurisdiction without capability binds only what remains on the market; capability without jurisdiction is what the CLOUD Act reaches; and both together still leave a polity exposed wherever control over what it depends on answers to someone else. Infrastructure is where the three converge, because there the first two are the means and the third is the condition they exist to secure; that convergence, not an equivalence, is what sovereignty refers to in this article. What Mueller’s objection still captures is the risk that a sovereignty vocabulary slides into territorial autarky and fragmentation (Edler et al., 2023); but the solution lies in the design, because openness and federation, discussed in §§ 3–6, are anti-autarkic commitments. Frischmann’s (2012) older lesson about infrastructure bears here: rules presuppose infrastructural conditions for their exercise, and a polity that regulates what it does not provide discovers that its rules operate on conditions set by another sovereign. The two already-distinguished layers specify where this happens for AI and explain the episodes described in § 1, which vary in both mechanism and actor. What the Garante affair adds is that regulation can move conduct but cannot keep a capability available. The Llama exclusion and Beijing’s deliberations are anchored at the model layer, where the licence and the ministry reside, though the Llama exclusion reaches through to deployment as well; both concern flow rather than stock: weights already downloaded remain on European disks, while the improvements, support, and successors are what a licence or a ministry withholds. The export directive on Fable 5 closed a hosted service overnight: a deployment-layer fact. The CLOUD Act reaches the data a deployment holds, placing it at the same layer rather than beside it: layers sort loci of control, and data are controlled where the service that processes it is provided. I shall argue that EOSAI answers both points: authorship of the weights secures the model layer’s flow, because a public family is improved under public control, secured by the ownership and asset-lock provisions of § 6, and provision under Union jurisdiction secures the deployment layer that regulation alone cannot.
The same mapping sorts providers by type. The American proprietary providers compromise both layers by design, and those who release weights as ‘open’ go further, since for EU-domiciled developers the licence removes the model layer outright, and with it the deployment sovereignty that self-hosting would supply; access survives only indirectly, through products and services built elsewhere that incorporate the models. Chinese open-weight providers compromise the model layer’s future flow, weights already released remaining self-hostable under Union jurisdiction. Some European commercial providers compromise the deployment layer for many enterprise customers, because scale for many of them requires American cloud infrastructure or American capital (Microsoft, 2024; TechCrunch, 2026). The first brings direct exposure to United States legal process, the second influence and the prospect of future control rather than jurisdiction, and each qualifies deployment-layer sovereignty in its own way.
The CLOUD Act, as § 1 described it, sits under all of this as a permanent structural fact, and European law does not cease to apply to the processing it reaches. Thus, a European hospital that keeps its patient data in a Frankfurt data centre operated by an American cloud provider has not achieved data sovereignty by choosing Frankfurt: it has achieved geographical presence within a jurisdictional exposure that follows the provider, not the data. CADA, proposed on 3 June 2026 by the Commission, recognises this in its Union assurance levels: at Level 4, the strictest tier, a provider must not be controlled from a third country and must retain effective control over all software components.Footnote 10 CADA works on both sides of the market: its assurance levels shape demand through public procurement, and its Cloud and AI Leadership Initiatives set supply-side operational objectives that reach frontier AI itself. What the Act does not do is constitute the producing institution. That is the task EOSAI addresses.
The point holds even against the sympathetic reading. Someone may object that European commercial firms such as Mistral, Aleph Alpha, and AMD-owned Silo AI (AMD, 2024) provide precisely the model-layer sovereignty the argument calls for. The reply is that a commercial firm, however European in origin (and even assuming it remains European), optimises for the constraints of private capital. Foreign investment, foreign cloud, closed weights for frontier models with open weights reserved for legacy variants, and outright foreign acquisition – as in the April 2026 announcement that Canada’s Cohere would acquire Aleph Alpha (CNBC, 2026) – are all rational business responses to competitive pressure. None of them is wrong, yet none of them meets the requirements of a public capability. Sovereignty at both layers, sustained across the decades that infrastructure requires, needs a public-mission vehicle. It is not a substitute for commercial provision but a complement without which commercial provision does not add up to sovereignty.
3 Distillation as the Technical Route
A common objection to any European foundation-model proposal is the frontier-scale argument: European budgets cannot match the billions poured into frontier training runs by American and Chinese providers, and any European effort will therefore be downstream of foreign frontiers no matter how well it is organised. The objection is reasonable but ultimately unconvincing because it assumes that a European public model must be trained from scratch, which is false. The alternative is knowledge distillation, understood here in its broad and current sense: training a target model (student) on what one or more models (teachers) produce, whether by matching their output distributions directly or by learning from corpora the teachers generate. The narrow textbook sense matters less than the legal one: on either method, the student is trained on the teacher’s outputs, which is why the licensing of those outputs is the first legal layer governing what may lawfully be distilled. Distillation is not new. It has become a standard technique behind many efficient production models, and the gap between a well-distilled student and its teacher has narrowed to the point where, for many deployment purposes, the student is preferable to the teacher on grounds of cost, latency, and controllability.Footnote 11 What distillation offers to a European public institution is a route from the existing ecosystem of open European foundation models to a certified, sovereign, continuously maintained family of derived models, at a small fraction of the compute frontier training from scratch requires, since the student is trained on generated corpora rather than on the teacher’s original data at the teacher’s original scale.
The teacher pool exists. EuroLLM-22B was released in December 2025 and described by its developers as the best fully open European-made large language model at the time, trained on four trillion tokens across thirty-five languages including the twenty-four official languages of the Union.Footnote 12 The OpenEuroLLM consortium, led by Charles University in Prague and AMD Silo AI in Finland among twenty European partners in total, was scheduled to release its first family of open foundation models by 31 December 2026, though Jan Hajič, the project coordinator, publicly acknowledged that securing sufficient compute for the final training runs remained a serious constraint.Footnote 13 The German SOOFI consortium, funded by the German Federal Ministry for Economic Affairs and Energy, published its first model, Soofi S, on 13 July 2026 as a gated preview under a licence still being finalised, with a 100-billion-parameter successor planned.Footnote 14 Apertus in Switzerland, Amália in Portugal, ALIA in Spain, and the model programmes of the Italian FAIR Foundation (Future Artificial Intelligence Research) add to the pool. Mistral Large 3, released in December 2025 at 675 billion parameters under Apache 2.0, is the largest European open-weight model and sits outside this pool for the reason the gate exists: a permissive licence on the weights is not the data information OSAID requires (Mistral, 2025). Compute limits constrain their ambition, documented for OpenEuroLLM and evident across the pool, but taken together and distilled through a single institutional process the pool could support a certified European family without the frontier training run. What matters is the institution that combines them, not any member of the pool.
The default method is corpus distillation: the teachers generate training data, and the student is trained on the corpus, which is how teachers of different architectures, tokenisers, and safety tunings combine without parameter-level entanglement. What combination buys is not a higher capability ceiling but coverage across languages and domains, together with the economies of a single evaluation and certification pipeline. Combination also has a legal price, because multi-teacher distillation requires the teachers’ licences to be pairwise compatible. OSAID fixes what counts as a genuinely open teacher, not what makes two teachers’ licences compatible: compatibility is a separate test, passed or failed term by term. Licences, moreover, are only the first legal layer: the lawfulness of the student’s corpus also turns on third-party rights in what the teachers generate, on personal data that generation can carry, and on the provenance of prompts and examples, obligations that the AI Act’s compliance policy and training-content summary make unavoidable even for open-source providers, that the GDPR imposes in parallel, and that copyright imposes at one remove: whether outputs generated by a teacher carry rights derived from that teacher’s own training corpus is unsettled in Union law, and a public capability cannot assume the permissive answer. Provenance runs upstream as well as downstream: a teacher whose own corpus carried the outputs of a foreign frontier model would make the public family a second-order derivative of the systems whose discretion it exists to escape, and authorship of the weights would be formal rather than substantive. That is a further reason for setting the eligibility gate at OSAID rather than at open weights alone, since the data information required by the definition is what allows a candidate teacher’s own inputs to be examined at all.Footnote 15
Two points about distillation need clarifying. First, the source model’s licence must permit the training of derivative models on terms compatible with an open release. This is not a legal nicety. Llama 2 prohibited the use of Llama outputs to improve any other large language model, Llama 2 and its derivatives aside; the later licences replaced the prohibition with a conditional permission, whose naming, display, and notice obligations are set out in the note, and Llama 4 withholds the Sect. 1(a) rights in the multimodal materials from individuals domiciled in the EU and from companies whose principal place of business is there.Footnote 16 Distillation from Llama is therefore unavailable to a European institution that intends to release an independent, genuinely open model: not because outputs may never be used, but because the conditions of use are incompatible with the institution and the release.
Nor is the pattern confined to the American licences. Kimi K3, whose weights were published on 27 July 2026, was released under a bespoke licence: MIT-style permissions over software that it defines to include the weights, plus two conditions beyond the notice requirement that an MIT licence would carry. Where the licensee or an affiliate operates a model-as-a-service business and their aggregate revenue exceeds 20 million US dollars over any twelve consecutive months, a separate agreement with Moonshot must be concluded before the software or any derivative work is used for any commercial purpose at all, and not merely for the service that triggers the condition. Model-as-a-service is itself defined narrowly, as giving a third party access to the model for inference or fine-tuning, with meaningful control over the inputs, parameters, or training data, and expressly excludes ‘end-user products with model capabilities solely embedded within specific features or harnesses’ and the ‘mere relaying of requests to models hosted by others’, so that the condition aims at competing inference businesses rather than at those who build on the model. Where the software or a derivative work is used in a commercial product or service with more than 100 million monthly active users or more than 20 million US dollars in monthly revenue, ‘Kimi K3’ must be displayed prominently on the user interface of that product or service (Moonshot 2026b). Neither condition reaches purely internal use, or access through Moonshot’s own products and certified inference partners. The thresholds are not commensurable: Meta’s is a snapshot at 700 million monthly active users in the month before release, and no right may be exercised until Meta grants a licence at its discretion; Moonshot’s is a rolling twelve-month revenue condition whose consequence is a duty to contract. Only Meta’s excludes a class of licensees by domicile or principal place of business. What they share is the mechanism, and thresholds of that kind are what separate an open-weight release from an open-source one on the OSAID test, wherever the licensor sits.
The models eligible for a European public model family under EOSAI’s own commitment are those released under terms that meet OSAID v1.0, published by the Open Source Initiative on 28 October 2024, under which a system is open source only if its terms secure the freedoms to use, study, modify, and share it for any purpose, including the training of derivative models: the definition sets the conditions; the licences grant the permissions.Footnote 17 EuroLLM and Apertus have released open models under permissive licences (EuroLLM Consortium, 2025; Swiss AI Initiative, 2025), and Apertus has published its data artefacts; OpenEuroLLM is designed to do the same, and OSAID compliance was stated as the target for SOOFI. The same commitment governs the distillation route I support in this article. Soofi S shows that distance in practice: its pretraining report classifies the planned release as satisfying OSAID v1.0, while conceding that under the stricter proposed European definitions, which would require every training token to be redistributable, it falls short in one documented component, a commercially licensed newspaper corpus amounting to 1.3% of the first-phase effective tokens, which leaves roughly 99% of the mixture independently reconstructible; the checkpoint available at the time of writing was a gated preview, so the classification describes the intended release rather than an accomplished one. Release practice is a gradient (Solaiman, 2023), as the gated preview and the threshold licence both show; eligibility is a threshold, and a model joins the family when it crosses it, not before.
Second, distillation is not the whole strategy but the near-term route to the medium-term. A student cannot rise far above what its teachers and its training data contain, and no European teacher is at the frontier. What distillation delivers in eighteen to thirty months is therefore not a competitor to GPT-class or Claude-class systems at frontier reasoning, but a certified, sovereign, deployable family calibrated to the workloads where sovereignty pays: regulated procurement, sensitive public-sector deployment, and the sub-frontier scale at which much European operational demand actually sits, including that of European small and medium-sized enterprises. It also provides a safety net should access to other models be blocked. That calibration answers the objection rather than conceding it. What the episodes of § 1 threaten is not Europe’s position on a capability ranking but the supply on which its public services, its healthcare, its justice system, and its defence depend, and those are the uses at which distillation arrives; standing, in the sense of § 2, is a property of that supply. Where a use genuinely requires frontier capability, the remaining dependence persists until the later programme rather than defeating the earlier one. Furthermore, it seeds the training corpus, the evaluation infrastructure, and the certification pipeline that a later frontier programme will need, on the AI Factories and the planned AI Gigafactories, for which the Commission has committed up to €10 billion in public support to unlock at least €20 billion in private investment.Footnote 18 The combination is what makes the argument realistic: distillation from OSAID-compliant sources now, frontier-scale training on sovereign compute later, with the pathways below carrying both.
4 Three Complementary Pathways
The institutional vehicle for EOSAI can be assembled in three ways, and the mistake to avoid at the outset is to treat them as alternatives. Each pathway forfeits a resource the other two carry: the industrial consortium cannot itself commit defence appropriations, which are a Member-State competence, though it may receive defence grants and contracts; the Member-State-led vehicle cannot reach continental scale alone; the Union Joint Undertaking cannot move at private-law speed, and has no claim on national defence appropriations without a separate Member-State decision. The three together cover the space that none of them alone can, and they operate on different timescales set by their institutional natures. The industrial consortium is the fastest to establish, because private law imposes fewer procedural constraints than public law. The Member-State-led pathway is the second fastest, because a single Member State can decide through its own constitutional and budgetary processes what twenty-seven Member States can decide only through the Council. The Union-led pathway is the slowest, because the Joint Undertaking form under Article 187 of the Treaty on the Functioning of the European Union (TFEU) requires a Council regulation on a Commission proposal, the assembly of participating members, and coordination with the existing EuroHPC and AI Office structures.Footnote 19
The three timescales are not a ranking of merit. They are properties of the instruments, and the sequence exploits them: the consortium starts first because it can, the Member-State-led pathway develops in parallel since national resources need not await consortium establishment, and the Union-led pathway matures later on its own schedule. What matters is that the three do not compete for a single mandate. They occupy complementary institutional niches with different resource envelopes and different long-term functions. The consortium is not a bridge that is demolished when the Joint Undertaking arrives. It is the industrial partner of the eventual continental system, remaining part of that system when the Joint Undertaking is established rather than a stage the system has outgrown.
One further advantage follows from the sequence. If the industrial consortium is established first and demonstrates credibility by delivering a certified derivative model within eighteen months, both the Member-State and the Union pathways will have a working institution to build on. Political capital that would otherwise be spent designing an institution from a blank slate can be redirected to negotiating a Joint Undertaking that federates something already in place. This is the strategic difference between top-down design and bottom-up ratification, and the European institutional record suggests that the latter is the more durable path. Schengen, an intergovernmental agreement of 1985 incorporated into the Treaties fourteen years later, is the canonical case, and the interval is part of the lesson: bottom-up ratification buys durability at the price of time.
Two precedents must be addressed, lest they become objections. Gaia-X, announced in 2019 as the Franco-German route to European cloud sovereignty, produced working groups, labels, and a federation framework, but failed to deliver a service that a customer could buy instead of a hyperscaler contract. Quaero, the Franco-German search-engine programme announced in 2005, fragmented a generation earlier when the Franco-German partnership split, before any procurable service existed: Germany withdrew at the turn of 2006–07 and built Theseus, while the French programme continued alone (The Register, 2007). The lesson is not that European technological initiatives fail: Airbus, Galileo, and EuroHPC succeeded. Instead, it is a lesson in design. The initiatives that succeeded were organised around a product with a customer, a schedule, and a procurement stream; those that failed were organised around a framework whose adoption was voluntary. EOSAI is designed on the former model. Its deliverable is a certified family of models, not a label; its demand is public procurement under CADA, not goodwill; and its first vehicle is a consortium whose members are the product’s launch customers. Only execution can show whether all this is sufficient. But it is at least on the correct side of the distinction on which the two failures sit.
5 The Industrial-led Pathway
A pan-European industrial consortium under private law, constituted as a European Economic Interest Grouping or as a consortium company under the law of a hosting Member State, is the fastest route into being. It requires no Council decision, no unanimity, and no coordination of twenty-seven fiscal authorities. What it does need is State aid compliance, which is a design constraint on how compute and capital are supplied rather than a bar to the vehicle.Footnote 20 It requires founding members who share a strategic reading of the European AI position and who are willing to commit capital and infrastructure against that reading.
The natural axis of such a consortium is a strategic partnership between a pan-European industrial anchor and a European reference computing centre. One credible pairing is Fastweb+Vodafone as industrial lead of the wider consortium and CINECA as computing partner. Others would serve, since any Member State hosting a EuroHPC site with a telecommunications or cloud anchor beside it could supply one; this pairing is taken as the example because its compute record is documented rather than projected. Fastweb+Vodafone brings national telecommunications scale that matters at Union level, following the legal merger of 1 January 2026 (Swisscom, 2026), owned infrastructure that reduces reliance on hyperscalers, and the network and data-centre assets that AI deployment at scale requires. CINECA brings Leonardo, one of the world’s leading pre-exascale supercomputers, a EuroHPC hosting site with the compute and the operational expertise for both distillation and continued pretraining, and the scientific credibility that any serious European public model programme needs. That description is recent and documented: Leonardo’s LISA partition, inaugurated in June 2026, is the first EuroHPC computing partition designed from the ground up for AI workloads (EuroHPC Joint Undertaking, 2026c), and Italian open-weight models have already been trained on Leonardo in collaboration with CINECA (Floridi & Lovecchio 2026).Footnote 21 The pairing is concrete, although one jurisdictional complication is that Fastweb+Vodafone sits within the Swisscom group, which is controlled from Switzerland, a third country under the proposed CADA text. On the proposed text, that control is disqualifying for the audited provider itself; no reading of the criteria avoids it. The consequence, however, is a design constraint for the consortium, not a disqualification. The entity that faces the strictest assurance tier must be established in the Union and controlled in the operative sense: voting rights, board appointments, and veto powers held by the European members, anchored by CINECA’s public membership and mission, with no control right in Fastweb+Vodafone capable of defeating the test. The industrial member’s network and data-centre assets then serve the consortium outside the audited service: not controlling the provider, not within its subcontracting or operational-support chain, and with the commercial and financial links that the proposal’s control inquiry also reaches held below controlling influence, financing capped and contracts at arm’s length. The division is the consortium’s design: the industrial member’s scale carries the wider consortium and its lower-assurance services, while the Level 4 line runs on infrastructure controlled by the audited entity itself, anchored by CINECA. The corporate detail is the argument of § 2 conducted by other means: standing is secured in articles of association or not at all.
The consortium is naturally expanded outwards from that axis. Illustrative candidates for founding membership, chosen to show the shape of the coalition rather than to prejudge it, and named here without any approach having been made, would include a second national telecommunications or cloud infrastructure partner such as Deutsche Telekom, on whose Industrial AI Cloud the German SOOFI model was trained; a large industrial deployer such as Airbus, which combines pan-European corporate identity with dual-use capability; a semiconductor partner such as STMicroelectronics; and one or two regulated deployer partners from banking or insurance whose scale would anchor the compliance-services revenue stream. Seven to ten founding members distributed across Member States is a planning assumption rather than a threshold: large enough that no single national interest owns the consortium, small enough that decisions do not require the coordination the Union pathway exists to supply. What the membership buys is the three currencies the pathway spends: compute, dual-use legitimacy, and regulated demand.
The CADA framework of June 2026, once adopted and applicable, gives the consortium commercial traction. The Union assurance levels for cloud computing services, tied to public procurement, create a demand-side instrument that advantages providers who can meet the strictest sovereignty requirements: not controlled from a third country, effective control over the software components, and cybersecurity certification at ‘high’ assurance level.Footnote 22 A consortium constituted on these lines can be designed from the outset to meet the proposed Level 4 requirements, and the addressable market for public-sector cloud and AI services in the Union is, I assume, large enough to sustain the pathway, though nothing here measures it: § 7 states the adoption failure that would refute the assumption. CADA does not create the consortium but the market segment served by the consortium. This is where the burden-to-advantage conversion becomes concrete. For an American hyperscaler subject to the CLOUD Act, Level 4, where the assurance framework requires it, is a gate that no amount of European data-centre real estate can close. For a European public consortium designed against Level 4 requirements by default, the same gate is a qualification. The criteria reach commercial and financial links and effective control over the software supply chain, so a subsidiary that merely licenses its stack from a third-country parent does not pass. Nor does building the stack in the Union cure the defect: the criteria are cumulative, and a subsidiary controlled from a third country fails on control, however its software is made. Only relocating the capability itself satisfies the test, which is the framework working rather than a loophole in it. The Level 4 lever stands on a proposal that was still before the legislator in August 2026, whereas the weaker advantage, compliance by design with the GDPR and the AI Act in regulated sectors, stands on law already in force. And the lever’s lawful perimeter is itself contested: whether a Level 4-style exclusion of third-country providers is compatible with the Union’s commitments under the World Trade Organization’s Government Procurement Agreement is a live question in trade law, which concerns the lever’s reach rather than being a resolved premise.
What the consortium does concretely in its first eighteen months is straightforward. It establishes the legal entity and its governance. It signs a memorandum of understanding with the OpenEuroLLM and EuroLLM consortia for research collaboration and with the AI Office for early engagement on general-purpose AI model compliance. It uses CINECA’s Leonardo capacity (whose allocation at the necessary scale is assumed here rather than measured), supplemented by AI Factory access where sectoral fine-tuning is needed, to distil a first family of European models from OSAID-compliant sources, compliant by design with the AI Act’s general-purpose AI model provisions, with published data information under the OSAID standard. ‘Certified’, in the sense clarified in § 1, names that compliance status made demonstrable through documented discharge of the obligations, adherence to the Act’s code of practice, conformity with harmonised standards as they are cited, and an audit by an accredited third party rather than by the consortium or its members; it is not the formal conformity assessment that the Act reserves for high-risk systems. The legal objects should be kept as distinct as the layers of § 2. The family is the consortium’s defining output, and for it the consortium is a model provider under those provisions. What CADA’s assurance levels recognise is a different object: the cloud service through which models are delivered, the model as such falling outside the levels. The consortium therefore carries two roles by design: model provider for what it releases and Level 4 service provider for the audited deployment line that hosts the family for public-sector customers; the gate attaches to the second, and what makes the gated service worth procuring is the first. It begins to build the compliance-as-a-service and enterprise support offerings that give its economics a private-revenue spine. It does all of this while remaining institutionally compatible with the two slower pathways: the consortium is designed to become a founding industrial partner of any Joint Undertaking later established, without either dissolving into that Joint Undertaking or being displaced by it.
The economics deserve a paragraph of their own, because a capability funded wholly by appropriations is hostage to budget cycles, and the pathways of §§ 4–6 are meant to last decades. Open source has a settled answer: what is sold is not the artefact but the assurance around it. Red Hat built a subscription business on software anyone could download, with revenue of 3.4 billion US dollars in its 2019 financial year, and IBM paid approximately 34 billion US dollars for the company in July of that year (IBM and Red Hat, 2019). Red Hat monetised a commons it had not created alone, whereas EOSAI must fund the artefact and then give it away. What transfers is the revenue mechanism, not the cost structure, which is why partial rather than full self-financing is the claim. The equivalent services for a public model family are identifiable: hosted inference and fine-tuning inside the audited Level 4 line; evaluation, documentation, and audit support for customers discharging their own AI Act duties; maintenance contracts covering retraining, security patching, and long-term version support; sectoral adaptation for health, justice, and defence; and the certification of integrators. CADA’s procurement gate supplies access to the buyers. Two conditions keep this compatible with the mission: openness is not for sale, so what is charged for is service and assurance, never access to the weights, which the asset lock of § 6 protects; and surpluses return to the public mission rather than to members. Partial self-financing is the realistic target, covering the recurrent costs of maintaining a family rather than the capital cost of frontier training. The proposal does not carry that capital cost, because the compute it needs is capacity already built and funded in the AI Factories and on the EuroHPC machines; what it must fund recurrently is training runs on allocated capacity, evaluation, certification, and staff. What that costs depends on the allocation terms, and their discussion goes beyond the scope of this article. The comparison that matters is with what the proposal does not carry: EOSAI buys no accelerators, builds no data centre, and funds no frontier training run, which is where the capital expenditure in this field lies, and it is that gap the distillation route exists to exploit.
6 The Member-state and Union Pathways as Complements
After the consortium in § 5, a single Member State can lead. France and Germany have each put national resources behind Mistral and SOOFI (TechCrunch, 2026 on Mistral; Federal Ministry for Economic Affairs and Energy, 2025 on SOOFI), on a national rather than continental scale. Any Member State with the scientific capacity, the industrial base, and the political will can take this pathway forward. Italy is one such case, and the one the working example of § 5 draws on: supercomputing capacity in public, industrial, and defence hands, the IT4LIA AI Factory at CINECA (EuroHPC Joint Undertaking, 2026a), and a plural ecosystem of Italian models, including those trained on Leonardo with CINECA (surveyed in Floridi and Lovecchio (2026)). What no Member State has yet done is organise such assets behind a European rather than a national programme. The distinctive resource such a pathway opens is the national defence budget. Defence is primarily a Member-State competence. A Member State that treats sovereign AI as part of its defence and industrial base has instruments available that no Union-level actor has, and can commit those instruments on a national timescale.Footnote 23 The White Paper for European Defence of March 2025 recognises AI, together with quantum, cyber, and electronic warfare, among its seven priority capability areas, and the ReArm Europe Plan anticipates the mobilisation of up to €800 billion over four years, principally through additional national fiscal space and SAFE loans, part of which can, at national discretion, support the AI infrastructure that defence capability requires.Footnote 24
The disadvantage of the Member-State-led pathway is that it reproduces at the level of institutions the fragmentation identified by the Draghi and Letta Reports at the level of markets.Footnote 25 One Member State moves quickly, whereas twenty-seven each committing resources for their own national efforts is the sub-scale European failure mode already visible in the SOOFI–Mistral–EuroLLM–ALIA–Apertus–Amália sequence, Swiss and multinational entries included, the last of them an adaptation of EuroLLM rather than a model trained from scratch (Barcelona Supercomputing Center, 2025) on ALIA; Simplício et al., 2026 on Amália): programmes that are assets only taken together, as § 3 argued, and a failure mode when pursued apart. Therefore, from the outset, the Member-State-led pathway requires an architecture that allows the national programme to federate with the consortium and with any subsequent Union structure. Federation is the price of avoiding sub-scale failure, and what it buys is concrete: access to the certified family and to the shared evaluation and certification pipeline, and a share in an audited service already constituted to pass the Level 4 gate, all of which a programme that stays outside must build again at national scale. A Member State that leads should design its programme as the national contribution to the European public capability, not as a self-standing national capability that will later need to be unwound.
The Union-led pathway sits at the other end of the timescale. A Joint Undertaking under Article 187 TFEU is the institutional form that has already delivered EuroHPC, and that has, under Council Regulation (EU) 2026/150, absorbed the AI Gigafactories mandate.Footnote 26 The form is precedented, operationally proven, and capable of holding both continental legitimacy and multi-decade stability. It is also the form CADA itself anticipates: the Leadership Initiatives may be implemented through joint undertakings, and a Union-led EOSAI would give the frontier-AI objective its implementing institution. This is not the ‘CERN for AI’ that Irgens and Hoos (2026) argue the Commission has claimed without delivering, and the test they set for such a body, autonomy, longevity, and trust, is one the Joint Undertaking form is built to meet: the pathway rests on precedent, not on a new frontier laboratory. However, there are two potential limitations. First, the timescale: three to five years from Council regulation to full operation is the realistic horizon, faster than a regulation-based agency but slower than a private consortium. Second, and more consequentially for the argument here, the Union has no defence budget that can be directly earmarked to a civilian Joint Undertaking. The instruments directly available to a civilian EOSAI, Digital Europe Programme, Horizon Europe, the EuroHPC Joint Undertaking, the InvestAI Facility, are themselves civilian, and the European Defence Fund appropriations that separately support AI in defence cannot simply be redirected to them. Thus, a Union-led EOSAI is a fully civilian programme, whose defence-adjacent capabilities are downstream consequences of the civilian design rather than programme objectives.
The division of labour follows. The consortium pursues compliance services in civilian-regulated sectors and defence-adjacent contracts under appropriate governance. A Member-State-led programme commits national defence funding at scale with proportionate governance restrictions. A Union-led Joint Undertaking sustains the civilian European public capability across the decades, with defence a beneficiary rather than a programme objective.
Federation is a governing relationship and four constitutional features give it content. First, the base weights, training artefacts, and evaluation infrastructure are publicly owned: vested, during the consortium stage, in a dedicated foundation under the law of the hosting Member State, with the public computing partner as anchor member, and transferred to the Joint Undertaking at maturity. Second, each organ is the AI Act provider for what it releases, and bears the provider’s duties. Third, the public mission carries rights with it: open access to the models under the OSAID standard, research access to the artefacts, and a contestation channel for allocation and access decisions, because an uncontestable public capability would reproduce the arbitrariness it exists to end. And fourth, the openness commitment attaches to the civilian base, with defence-funded variants owned and governed by the funding Member State under its own security rules, and returning to the civilian base only what can be released on the base’s own open terms, which is where the improvements that are not security-sensitive belong, so that the freedom to use for any purpose is neither compromised in the base nor extended where it cannot apply. Together the four answer the objection that openness alone does not redistribute power in AI (Widder et al., 2024): what redistributes it is not the licence but the ownership, the duties, the access rights, and the channel through which allocation can be contested. These features need an authority to bear them: a board appointed by the foundation’s public members, with the computing partner’s seat permanent; release, access, and disposal reserved to the public majority; an asset lock drafted to survive member exit, and to rank the public mission ahead of member claims in insolvency so far as the law of the hosting Member State permits, which is a criterion for selecting that Member State rather than an assumption about any of them; and transfer to the Joint Undertaking secured in advance, written into the foundation’s statutes and each member’s accession commitments, so that the Council regulation creating the Undertaking finds assets already bound to move rather than a divestment still to be litigated. Finally, openness has a constitutional review of its own: EOSAI adopts the AI Act’s systemic-risk classification as its internal trigger, so that a model crossing the threshold, which under the Act multiplies the provider’s duties rather than forbidding release, undergoes a public release review through the contestation channel just named. A release restricted on that review would fall outside the OSAID commitment, which continues to govern the civilian base; the point of the design is that any such limit is set publicly, which is what distinguishes a public limit from a provider’s discretion.
One final observation on the sequence. The Commission’s stated preference is to network and strengthen what already exists in Europe rather than build new infrastructure.Footnote 27 EOSAI is consistent with that preference. It creates no new compute infrastructure: the EuroHPC supercomputers, the AI Factories, and the Gigafactories tendered from July 2026 are intended to add to it. It creates no new research network: the RAISE pilot launched in November 2025 already coordinates that.Footnote 28 It creates no new regulator for the market: supervision of general-purpose AI models remains with the AI Office, and its Service Desk provides implementation support. What it creates is internal governance over its own releases, which is what the four constitutional features above establish, and what any provider must have. What EOSAI adds is the production and certification of the foundation models themselves, which none of the existing components is constituted to do. Nor is the proposal alone in its family: the CERN Model principles that Irgens and Hoos (2025) wrote for the Confederation of Laboratories for Artificial Intelligence Research in Europe (CAIRNE), the CERN-for-AI debate to which Irgens and Hoos (2026) contribute, and the EuroStack report (Bria et al., 2025) all argue for European public digital capability. What EOSAI adds to that family is the route: three vehicles, each with the legal form its resources require, sequenced so that the fastest starts first and the most durable arrives last.
7 Conclusion: Rules Require Infrastructure
Digital sovereignty is not won by regulation alone. The past decade has proved it. Europe has the world’s most comprehensive rules for AI, yet it does not control the design and supply of the models those rules are meant to govern. Providers who dislike the rules withdraw the models; those who accept them do so on terms they can revise; when a home government restricts export, the models are withdrawn on those instructions. Whichever route closes access, Europe becomes a jurisdiction that others must legally consider but can technically ignore. The pattern of the three years to 2026 is one of demotion: access to lesser models under conditional licences, with data flows subject to a foreign sovereign’s compulsion. A polity in that position is not sovereign over the infrastructure on which its economy and the public functions listed in § 3 depend. Rome had a name for a comparable condition: civitas sine suffragio, membership of the order with its obligations intact and its decisions made elsewhere. Europe is acquiring the digital version: full exposure to the infrastructure, no voice in its terms. Rome conferred that status on communities it had subdued; Europe’s is not conferred but assumed, the residue of regulating what it chose not to provide. That makes it worse as a predicament and better as a prospect, since what a polity does to itself it can also undo. The demotion is the polity’s, and derivatively that of everyone whose data, health, and security its institutions hold: civitas sine suffragio likewise turned on a community’s standing, not an individual’s grievance. The republican tradition built its account of liberty on precisely this contrast: unfree is whoever depends on another’s will, and a master’s kindness does not make the servant free (Pettit, 1997; Skinner, 1998). The tradition theorises persons, and it reaches the polity through them: a polity whose infrastructure answers to another’s discretion cannot secure for those it serves the standing it exists to secure, so the domination is of citizens through their institutions. Freedom in that sense is not a private good that each party may bargain away on its own account, but a standing of the polity, which its institutions exist to secure and cannot contract out. The power at issue is arbitrary in the tradition’s precise sense: no channel of contestation runs from those affected to those who decide. Thus, in recent episodes, access was restored through negotiations within the American administration, and the licences governing future releases and services are subject to revision at the provider’s discretion. Nor do the standard remedies reach far enough: non-discrimination duties, interoperability mandates, and common-carrier rules bind a provider only while it is present, and presence is what cannot be compelled. The Union can regulate the models offered on its market, but it cannot require that a model be offered, prevent a provider from withdrawing it or lowering its quality, or override the export controls of the provider’s home state. Diversification and interoperability reduce exposure; what provision distinctively secures is continuity under public, contestable control when the supplier withdraws or is withdrawn. A public capability is what securing that freedom looks like for infrastructure: standing established, not kindness solicited.
The correction is a public institution that produces the models themselves. Genuinely open source, by the OSAID v1.0 standard, not by marketing claim. Compliant by design, not by remediation. Trained on documented, lawfully sourced data, with the OSAID data information published as a development artefact. Deployable under Union jurisdiction, with multi-decade availability that does not depend on one provider’s continuing strategy, ownership, or survival. It can be done. The three pathways of §§ 4–6 differ in resource base and timescale, and none substitutes for the others.
None of this requires an unknown technology or an unprecedented legal form. Some components exist, others rest on an adopted legal or funding framework, and others are scheduled or still before the legislator. The candidate teachers exist, under terms intended to meet OSAID. The compute infrastructure exists in EuroHPC and the AI Factories, with the Gigafactories put out to tender on 30 July 2026, their award expected early in 2027 and construction to follow. The regulatory framework exists in the AI Act and the GDPR, and CADA would complete it: with CADA adopted, compliance-by-design ceases to be a burden and becomes the qualification the strictest procurement tier demands. The industrial base exists. The scientific communities exist in CAIRNE, ELLIS (the European Laboratory for Learning and Intelligent Systems), and the national research systems. What is missing is the institution that federates these components to produce the public capability that EOSAI names. Building that institution is a matter of decision, not of invention.
The proposal can fail in three ways. It fails if the consortium becomes a subsidy vehicle without a shipped, certified family within its first two years: the institution the other pathways were to build on would then become a cautionary tale instead. It fails if the Member-State programmes decline federation and reproduce, with public money, the sub-scale sequence seen in § 6. And it fails if certification outruns adoption, delivering compliant models that no ministry, hospital, or bank deploys, in which case the burden-to-advantage conversion discussed in § 1 remains a thesis.
One question remains, because the proposal is itself a move in the same game it describes: the other players move next, and two replies are open to them, with a third worth naming because it is no threat at all. The first is retaliation: export controls extended from models to their inputs. Against EOSAI, the exposed surface is smaller by design: the teachers are European, and the principal remaining exposure is hardware, above all the accelerators inside the Gigafactories, for which AMD, Nvidia, and Qualcomm have signed letters of intent with the Commission (Chee, 2026). That residue is not the condition diagnosed here: a public procurement process, alternatives in principle, and a Union instrument aimed at the gap leave channels of contestation that an export directive and a licensor’s discretion do not. It is a dependence the Chips Act 2.0 proposal exists to address, and one this article leaves aside. The second is pre-emption: a foreign release, timed and marketed as ‘open’, to capture adoption before a European family ships. The OSAID gate filters that move: a licence that excludes jurisdictions, reserves arbitrary revocation, or prohibits or discriminatorily restricts modification and redistribution fails the definition, no matter how the release is marketed, and a release that genuinely met it would arrive not as a threat but as another candidate teacher, subject to the compatibility and provenance tests of § 3. The third is imitation, and it is not adverse: other polities building public capabilities of their own would confirm the diagnosis rather than contest it, and a world of open public models is the anti-autarkic outcome to which § 2 committed the design. None of the three restores the condition that the proposal exists to end: dependence at another’s discretion.
I close on the philosophical claim under the strategic one. Rules without infrastructure produce a protected dependency, which is not sovereignty: this is the older lesson that regulatory frameworks presuppose the infrastructure that carries them.Footnote 29 Infrastructure without rules produces power without legitimacy, which is not the European project. Between the two failures sits the patient whose hospital appeared in § 2, whose records follow its provider into whichever jurisdiction can compel it, and whose vote reaches no one who decides whether the service continues. The Union has written the rules; the decade ahead decides whether it builds what they presuppose. EOSAI is one proposal for how to do so, and the case for beginning is already made. A decade of rule-making left Europe with rules without models. The correction, and the measure of it, is models under Europe’s own rules.
Notes
European Commission (2026a) for CADA and the Tech Sovereignty Package, which also carries the Chips Act 2.0 proposal, the updated EU Open Source Strategy, and the Strategic Roadmap for Digitalisation and AI in Energy. The AI Act is Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 of 8 July 2026, in force since 27 July, which defers the high-risk application dates to 2 December 2027 and 2 August 2028; the proposal is European Commission (2025f). On the turn from self-regulation to hard law, Floridi (2021).
Garante per la protezione dei dati personali (2023, 2024): provvedimento n. 112 of 30 March 2023 and provvedimento n. 755 of 2 November 2024, imposing the €15 million sanction, suspended on 21 March 2025 and annulled in its entirety (Court of Rome 2026; R.G. 4785/2025, judgment n. 4153/2026, Judge Damiana Colla). The annulment turned on jurisdiction: the Irish Data Protection Commission has held lead-supervisory-authority competence over OpenAI’s cross-border processing in the European Economic Area since 15 February 2024.
Meta (2025). All Llama 4 models are multimodal, so the exclusion reaches the whole family; the restriction does not extend to end users of a product or service incorporating such a model.
Open Source Initiative (2025), assessing Llama 3.x. The OSI holds that the licence fails the Open Source Definition in every version from Llama 2 onwards: the 700-million-monthly-active-users scale restriction, the conditions on training other models on Llama outputs, and, from Llama 3.2, the EU exclusion (Meta, 2024, 2025).
The directive was issued by Commerce Secretary Howard Lutnick on 12 June 2026 under United States export-control authority; Anthropic (2026a, 2026b) records receipt at 5:21 pm ET. The figure for the US institutions to which Mythos 5 was restored is Reuters (2026a); Murphy (2026) covers the Austrian response.
The letter is from Alexander Pröll, Austrian State Secretary for Digitalisation; it was released the following day and reported in Murphy (2026). Pröll puts the choice as one between being ‘architects of our technological future’ and remaining ‘mere administrators of decisions made elsewhere’.
Reuters (2026b), citing three sources familiar with the meetings; Z.ai was formerly Zhipu AI. The rejoinder arrived within days: Moonshot AI, Alibaba-backed but not among the three companies named, launched Kimi K3 on 16 July 2026 and published the weights on 27 July under a bespoke licence rather than an established open-source one (Moonshot 2026a, b). What one ministry permits today it can restrict tomorrow, and the options reported bore on releases still to come.
United States Congress (2018); its duties attach to providers of electronic communication services and remote computing services, and its reach is assessed in European Data Protection Board and European Data Protection Supervisor (2019). Electronic health data will be governed Union-wide by the European Health Data Space (Regulation (EU) 2025/327), applicable from 26 March 2027. The pattern is what Farrell and Newman (2019) call weaponized interdependence: jurisdiction over central nodes yields visibility and denial.
European Commission (2026a), Articles 16 to 18 and Annex II for the four Union assurance levels, including the Level 3 designation exception, of which a GDPR adequacy decision is one cumulative condition, and its absence at Level 4. Of the eight operational objectives of the Cloud and AI Leadership Initiatives, the third is advancing the Union’s capabilities in frontier AI, implemented where appropriate through joint undertakings (recital 26).
Distillation in its modern form is Hinton et al. (2015); its ancestor, model compression, is Bucilă et al. (2006); the methods are surveyed in Xu et al. (2024). The eighteen-to-thirty-month horizon of § 3 is a planning assumption informed by the release cycles of EuroLLM and SOOFI, not derived from the survey. § 7 sets a deliberately stricter failure criterion, a certified family shipped within the consortium’s first two years, which is the § 4 milestone with six months’ grace rather than the upper bound of that horizon.
EuroLLM Consortium (2025). EuroLLM-22B was trained on the MareNostrum 5 supercomputer at the Barcelona Supercomputing Center.
Federal Ministry for Economic Affairs and Energy (2025); SOOFI Consortium (2026) for the model’s specification and benchmarks. Its third version, of 22 July 2026, discloses that rephrased GPQA items had entered the QA-base dataset through a benchmark split labelled as training data, removes the affected scores, and recomputes the suite means symmetrically for every model, leaving relative rankings unaffected.
Neither test is run in this article: compatibility and provenance alike are early deliverables of the institution I propose, not results I claim.
The prohibition is Sect. 1(b)(v) of Meta’s Llama 2 Community License, which excepted Llama 2 and its derivative works. From Llama 3.1 the clause becomes a conditional permission: outputs may train other models, provided that a resulting model which is distributed or made available takes a name beginning with ‘Llama’; the separate ‘Built with Llama’ display and attribution-notice retention apply only where the Llama Materials, their derivatives, or copies of them are themselves distributed or incorporated. The EU exclusion first appears in the Llama 3.2 Acceptable Use Policy of 25 September 2024 (Meta, 2024) and is carried into Llama 4 (Meta, 2025).
Open Source Initiative (2024) for the four freedoms and for the data information it requires. On open licensing as a governance structure, Weber (2004); on whether openness alone redistributes power, Widder et al. (2024), answered in § 6; on the benefits open weights carry and on assessing misuse as marginal risk, Kapoor et al. (2024), the standard the release review of § 6 applies.
European Commission (2025d) for InvestAI, which aims to mobilise €200 billion, announced at the AI Action Summit of February 2025 and taken forward by the AI Continent Action Plan (European Commission, 2025a); Council of the European Union (2026) for EuroHPC’s implementing mandate; EuroHPC Joint Undertaking (2026b) for the call of 30 July 2026, for up to seven facilities with joint Union and Member-State funding, and bids closing on 12 November 2026; Chee (2026) for the public-funding total of up to €10 billion.
The Article 187 TFEU Joint Undertaking form has been used for the Innovative Medicines Initiative, the Fuel Cells and Hydrogen JU, the Clean Sky JU, and, most relevantly for the present argument, the EuroHPC JU.
Public compute below market rate, or public capital on terms a private investor would refuse, supplies the advantage that is one of the four cumulative conditions of Article 107(1) TFEU; the vehicle must therefore be remunerated at market terms, or fall within de minimis, a block exemption, or an approved scheme, or be notified for approval.
The Commission’s role in defence remains constrained, and Union-level instruments such as the European Defence Fund and SAFE are not available for civilian AI infrastructure as such, whatever a dual-use variant might attract.
AQ responses still owed to Springer for the record: Q3 — Council Regulation (EU) 2026/150 is a legal instrument, not a journal article; not applicable. Q4 — the Commission’s White Paper for European Defence is a government report, not a journal article; not applicable. Q5 — Garante provvedimento n. 755/2024 is an administrative ruling, not a journal article; not applicable. Q7 — Murphy (2026) is a Reuters news piece, not a journal article; not applicable. Q8 — Regulation (EU) 2024/1689 is cited narratively in footnote 1, not as a bracketed author-date citation, hence not picked up automatically. Q9 — Regulation (EU) 2026/1744 is a legal instrument, not a journal article; not applicable. Q10 — the US CLOUD Act (Public Law 115-141) is an act of legislation, not a journal article; not applicable. Reference list — the eight "European Commission" entries are out of sequence They currently run: 2025f, 2025d, 2025g, 2025b, 2025a, 2025c, 2026a, with 2025e stranded much later near the CLOUD Act references. They should run in order: 2025a, 2025b, 2025c, 2025d, 2025e, 2025f, 2025g, then 2026a. European Commission (2025e): ReArm Europe, announced on 4 March 2025 and framed by the Joint White Paper of 19 March, with SAFE (Security Action for Europe) mobilising up to €150 billion in loans to Member States. SAFE funds pass through Member-State budgets under national procurement authority.
Draghi (2024); Letta (2024): markets alone will not close the gap, and continental-scale public infrastructure is needed where private capital has not delivered. What such infrastructure also requires is capability inside the institution that builds it (Kattel & Mazzucato, 2018), which is why the failure modes of § 7 are capability failures rather than funding gaps.
Council of the European Union (2026). The same amendment also added a dedicated quantum-technologies pillar to the EuroHPC JU mandate.
European Commission (2025c), adopted on 8 October 2025; previewing it three weeks earlier at the Commission’s Research and Innovation Days, the director responsible described the approach as ‘networking of what exists in Europe and strengthening of what exists, instead of creating new infrastructures’ (Greenacre, 2025).
European Commission (2025g). RAISE is a virtual institute for AI in science, supported by €140 million in dedicated Horizon Europe funding, €33 million under the 2025 work programme and €107 million under 2026–27; its mandate is research coordination, not foundation-model production.
Frischmann (2012) for the systematic case. The literature on the extension of sovereignty to the digital divides (Floridi, 2020; for a taxonomy and critical evaluation, Fratini et al., 2024): Couture and Toupin (2019), Pohle and Thiel (2020), and Edler et al. (2023), who conceive technology sovereignty as state-level agency rather than territorial sovereignty over something. On non-domination and infrastructure together, Rahman (2017, 2018); § 7 states why its repertoire narrows here.
References
AMD (2024). AMD Completes Acquisition of Silo AI to Accelerate Development and Deployment of AI Models on AMD Hardware. Press release, 12 August 2024. https://www.amd.com/en/newsroom/press-releases/2024-8-12-amd-completes-acquisition-of-silo-ai-to-accelerate.html. Accessed 26 July 2026.
Anthropic (2026a). Statement on the US government directive to suspend access to Fable 5 and Mythos 5, 12 June 2026. https://www.anthropic.com/news/fable-mythos-access. Accessed 22 July 2026.
Anthropic (2026b). Redeploying Claude Fable 5, 30 June 2026, updated 1 July 2026. https://www.anthropic.com/news/redeploying-fable-5; Supported countries and regions. https://www.anthropic.com/supported-countries. Accessed 22 July 2026.
Barcelona Supercomputing Center (BSC-CNS) (2025). ALIA: la primera infraestructura pública, abierta y multilingüe de IA en Europa. https://www.bsc.es/es/noticias/noticias-del-bsc/alia-la-primera-infraestructura-p%C3%BAblica-abierta-y-multiling%C3%BCe-de-ia-en-europa. Accessed 31 July 2026.
Bologa, A. (2025). Burying the Brussels Effect? AI Act Inspires Few Copycats. CEPA (Center for European Policy Analysis), 23 April 2025. https://cepa.org/article/burying-the-brussels-effect-ai-act-inspires-few-copycats/. Accessed 3 August 2026.
Bradford, A. (2020). The Brussels Effect: How the European Union Rules the World. Oxford University Press. https://doi.org/10.1093/oso/9780190088583.001.0001
Bradford, A. (2023). Digital Empires: The Global Battle to Regulate Technology. Oxford University Press. https://doi.org/10.1093/oso/9780197649268.001.0001
Bria, F., Timmers, P., & Gernone, F. (2025). EuroStack – A European Alternative for Digital Sovereignty. Bertelsmann Stiftung.
Bucilă, C., Caruana, R., & Niculescu-Mizil, A. (2006). Model compression. In Proceedings of the 12th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, 535–541. https://doi.org/10.1145/1150402.1150464
Chee, F. Y. (2026). EU aims for seven AI gigafactories with €10 billion plan in race with US, China. Reuters, 30 July 2026. https://www.reuters.com/world/china/eu-aims-seven-ai-gigafactories-with-10-billion-plan-race-with-us-china-2026-07-30/. Accessed 6 August 2026.
CNBC (2026). Cohere to acquire German AI company Aleph Alpha as it looks to expand in Europe, 24 April 2026. https://www.cnbc.com/2026/04/24/cohere-aleph-alpha-germany-ai-europe-expansion.html. Accessed 4 August 2026.
Council of the European Union (2026). Council Regulation (EU) 2026/150 of 16 January 2026 amending Regulation (EU) 2021/1173 establishing the EuroHPC Joint Undertaking.
Court of Rome (Tribunale Ordinario di Roma), Sezione Diritti della Persona e Immigrazione (2026). Judgment n. 4153/2026, case R.G. 4785/2025, 18 March 2026. Annulment of Garante provvedimento n. 755.
Couture, S., & Toupin, S. (2019). What does the notion of ‘sovereignty’ mean when referring to the digital? New Media & Society, 21(10), 2305–2322. https://doi.org/10.1177/1461444819865984
Draghi, M. (2024). The Future of European Competitiveness. Report to the European Commission. September 2024.
Edler, J., Blind, K., Kroll, H., & Schubert, T. (2023). Technology sovereignty as an emerging frame for innovation policy. Defining rationales, ends and means. Research Policy, 52(6), 104765. https://doi.org/10.1016/j.respol.2023.104765
Engler, A. (2022). The EU AI Act will have global impact, but a limited Brussels effect. Brookings Institution. https://www.brookings.edu/articles/the-eu-ai-act-will-have-global-impact-but-a-limited-brussels-effect/ Accessed 14 July 2026.
EuroHPC, J. U. (2026b). The EuroHPC Joint Undertaking launches the AI Gigafactories Call, 30 July 2026. https://www.eurohpc-ju.europa.eu/eurohpc-joint-undertaking-launches-ai-gigafactories-call-2026-07-30_en. Accessed 2 August 2026.
EuroHPC Joint Undertaking (2026a). EuroHPC JU signs contract to boost AI capabilities with IT4LIA AI Factory. 22 April 2026. https://www.eurohpc-ju.europa.eu/eurohpc-ju-signs-contract-boost-ai-capabilities-it4lia-ai-factory-2026-04-22_en. Accessed 31 July 2026.
EuroHPC Joint Undertaking (2026c). Inauguration of SOL, a New Quantum Computer Together with LISA: the Upgrade of the Leonardo Supercomputer, 11 June 2026. https://www.eurohpc-ju.europa.eu/inauguration-sol-new-quantum-computer-together-lisa-upgrade-leonardo-supercomputer-2026-06-11_en. Accessed 4 August 2026.
EuroLLM Consortium (2025). EuroLLM-22B: The best fully open European-made LLM. https://eurollm.io and https://huggingface.co/blog/eurollm-team/eurollm-22b. Accessed 14 July 2026.
European Commission (2025f). Digital Omnibus on AI Regulation Proposal, COM(2025) 836, 19 November 2025.
European Commission (2025d). InvestAI initiative. Announced at the AI Action Summit, Paris, 11 February 2025.
European Commission (2025g). Resource for AI Science in Europe (RAISE): launch. Press release, 3 November 2025.
European Commission (2025b). Apply AI Strategy, October 2025.
European Commission (2025a). AI Continent Action Plan, COM(2025) 165, 9 April 2025.
European Commission (2025c). A European Strategy for Artificial Intelligence in Science, COM(2025) 724 final, 8 October 2025.
European Data Protection Board and European Data Protection Supervisor (2019). Joint Response to the LIBE Committee on the impact of the US CLOUD Act on the European legal framework for personal data protection, 10 July 2019.
European Commission (2026a). Proposal for a Regulation establishing a framework of measures for strengthening Europe’s cloud and AI ecosystem (Cloud and AI Development Act), COM(2026) 502 final, 2026/0138(COD), 3 June 2026. https://digital-strategy.ec.europa.eu/en/policies/cloud-and-ai-development-act. Accessed 14 July 2026.
European Commission (2025e). White Paper for European Defence: Readiness 2030, joint with the High Representative of the Union for Foreign Affairs and Security Policy, 19 March 2025.
Farrell, H., & Newman, A. L. (2019). Weaponized interdependence: How global economic networks shape state coercion. International Security, 44(1), 42–79. https://doi.org/10.1162/isec_a_00351
Federal Ministry for Economic Affairs and Energy (2025). Bundeswirtschaftsministerium fördert Aufbau eines europäischen KI-Sprachmodells als Basis für industrielle KI. Press release, 18 November 2025. https://www.bundeswirtschaftsministerium.de/Redaktion/DE/Pressemitteilungen/2025/11/20251118-bundeswirtschaftsministerium-foerdert-aufbau-eines-europaeischen-ki-sprachmodells.html. Accessed 2 August 2026.
Floridi, L. (2020). The fight for digital sovereignty: What it is, and why it matters, especially for the EU. Philosophy & Technology, 33(3), 369–378. https://doi.org/10.1007/s13347-020-00423-6
Floridi, L. (2021). The End of an Era: from Self-Regulation to Hard Law for the Digital Industry. Philosophy & Technology, 34(4), 619–622. https://doi.org/10.1007/s13347-021-00493-0
Fratini, S., Hine, E., Novelli, C., Roberts, H., & Floridi, L. (2024). Digital sovereignty: A descriptive analysis and a critical evaluation of existing models. Digital Society, 3(3), 59. https://doi.org/10.1007/s44206-024-00146-7
Frischmann, B. (2012). Infrastructure: The Social Value of Shared Resources. Oxford University Press. https://doi.org/10.1093/acprof:oso/9780199895656.001.0001
Garante per la protezione dei dati personali. (2023). Provvedimento n. 112 del 30 marzo 2023. OpenAI, ChatGPT.
Garante per la protezione dei dati personali (2024). Provvedimento n. 755 del 2 novembre 2024 nei confronti di OpenAI: sanzione amministrativa di €15.000.000 e campagna di comunicazione istituzionale.
Greenacre, M. (2025). Commission to adopt AI in science strategy on October 7. Science|Business, 18 September 2025. https://sciencebusiness.net/news/ai/commission-adopt-ai-science-strategy-october-7. Accessed 2 August 2026.
Hinton, G., Vinyals, O., & Dean, J. (2015). Distilling the Knowledge in a Neural Network. arXiv, 1503.02531. https://doi.org/10.48550/arXiv.1503.02531
IBM and Red Hat (2019). IBM Closes Landmark Acquisition of Red Hat for $34 Billion; Defines Open, Hybrid Cloud Future. Press release, 9 July 2019. https://www.redhat.com/en/about/press-releases/ibm-closes-landmark-acquisition-red-hat-34-billion-defines-open-hybrid-cloud-future. Accessed 4 August 2026.
Irgens, M., & Hoos, H. (2025). The CERN Model: Ten Key Principles for Big Science ‘Made in Europe’. Version 1.0, 1 December 2025. CAIRNE. https://cairne.eu/wp-content/uploads/2025/12/cern-model-10-principles.pdf. Accessed 2 August 2026.
Irgens, M., & Hoos, H. (2026). Viewpoint: The EU’s ‘CERN for AI’ is nothing of the sort. Science|Business, 29 January 2026.
Kapoor, S., Bommasani, R., Klyman, K., Longpre, S., Ramaswami, A., Cihon, P., Hopkins, A., et al. (2024). Position: On the Societal Impact of Open Foundation Models. In Proceedings of the 41st International Conference on Machine Learning, PMLR 235: 23082–23104. . Accessed 4 August 2026. https://proceedings.mlr.press/v235/kapoor24a.html
Kattel, R., & Mazzucato, M. (2018). Mission-oriented innovation policy and dynamic capabilities in the public sector. Industrial and Corporate Change, 27(5), 787–801. https://doi.org/10.1093/icc/dty032
Letta, E. (2024). Much More Than a Market: Speed, Security, Solidarity. Report to the European Council, April 2024.
Floridi, L., & Lovecchio, M. (Eds.), L’Italia nell’era dell’IA: crescita, sfide e prospettive di una rivoluzione in corso. Fondazione Leonardo ETS, March 2026. Accessed 4 August 2026. https://www.fondazioneleonardo.com/stories/italia-era-ia-crescita-sfide-prospettive-floridi
Meta (2024). Llama 3.2 Acceptable Use Policy, 25 September 2024. https://www.llama.com/llama3_2/use-policy/. Accessed 26 July 2026.
Meta (2025). Llama 4 Community License Agreement and Acceptable Use Policy. https://www.llama.com/llama4/use-policy/. Accessed 14 July 2026.
Microsoft (2024). Microsoft and Mistral AI announce new partnership to accelerate AI innovation and introduce Mistral Large first on Azure. Azure blog, 26 February 2024. https://azure.microsoft.com/en-us/blog/microsoft-and-mistral-ai-announce-new-partnership-to-accelerate-ai-innovation-and-introduce-mistral-large-first-on-azure/. Accessed 2 August 2026.
Mistral, A. I. (2025). Mistral Large 3. Model card, 2 December 2025. https://docs.mistral.ai/models/model-cards/mistral-large-3-25-12. Accessed 7 August 2026.
Moonshot, A. I. (2026a). Kimi K3. Company blog, 16 July 2026. https://www.kimi.com/blog/kimi-k3. Accessed 27 July 2026.
Moonshot, A. I. (2026b). Kimi K3 License. Model repository, 27 July 2026. https://huggingface.co/moonshotai/Kimi-K3/raw/main/LICENSE. Accessed 27 July 2026.
Mueller, M. (2020). Against sovereignty in cyberspace. International Studies Review, 22(4), 779–801. https://doi.org/10.1093/isr/viz044
Murphy, F. (2026). Austria urges Europe to host Anthropic following US curbs on AI access. Reuters, 28 June 2026.
Open Source Initiative (2024). The Open Source AI Definition (OSAID) v1.0, released 28 October 2024. https://opensource.org/ai/open-source-ai-definition. Accessed 14 July 2026.
Open Source Initiative (2025). Meta’s LLaMa license is still not Open Source. By J. Maris, 18 February 2025. https://opensource.org/blog/metas-llama-license-is-still-not-open-source. Accessed 26 July 2026.
OpenEuroLLM Consortium (2026). OpenEuroLLM: First year progress and next steps, 6 March 2026. https://openeurollm.eu/blog/first-year-progress-and-next-steps. Accessed 3 August 2026.
OpenEuroLLM Consortium (2025). Project launch, roadmap, and deliverables schedule. https://openeurollm.eu; https://www.openeurollm.eu/deliverables. Accessed 26 July 2026.
Pettit, P. (1997). Republicanism: A Theory of Freedom and Government. Clarendon. https://doi.org/10.1093/0198296428.001.0001
Pohle, J., & Thiel, T. (2020). Digital sovereignty. Internet Policy Review, 9(4). https://doi.org/10.14763/2020.4.1532
Rahman, K. S. (2017). Democracy Against Domination. Oxford University Press. https://doi.org/10.1093/acprof:oso/9780190468538.001.0001
Rahman, K. S. (2018). The New Utilities: Private Power, Social Infrastructure, and the Revival of the Public Utility Concept. Cardozo Law Review, 39(5), 1621–1689.
Regulation, E. U. 2024/1689. Artificial Intelligence Act, as amended by Regulation (EU) 2026/1744.
Regulation, E. U. 2025/327. European Health Data Space.
Regulation, E. U. 2026/1744. Digital Omnibus on AI, amending Regulations (EU) 2024/1689, (EU) 2018/1139, and (EU) 2023/1230. OJ, 24 July 2026.
Reuters (2026a). US allows Anthropic to release Mythos AI to ‘trusted’ US organizations. 26 June 2026. https://www.reuters.com/technology/us-releases-anthropic-model-mythos-some-us-companies-semafor-reports-2026-06-26/. Accessed 26 July 2026.
Reuters. (2026b). Beijing is looking at curbing overseas access to China’s top AI models, sources say. 7 July 2026. https://www.reuters.com/world/beijing-is-looking-curbing-overseas-access-chinas-top-ai-models-sources-say-2026-07-07/. Accessed 25 July 2026.
Siegmann, C., & Anderljung, M. (2022). The Brussels Effect and Artificial Intelligence: How EU Regulation Will Impact the Global AI Market. Centre for the Governance of AI. arXiv:2208.12645. https://doi.org/10.48550/arXiv.2208.12645
Simplício, A., Vinagre, G., Ramos, M. M., Tavares, D., Ferreira, R., Attanasio, G., Alves, D. M., et al. (2026). AMALIA: A Fully Open Large Language Model for European Portuguese. In Proceedings of PROPOR 2026, 380–391. Salvador: Association for Computational Linguistics.
Skinner, Q. (1998). Liberty before Liberalism. Cambridge University Press. https://doi.org/10.1017/cbo9781139171274
Solaiman, I. (2023). The Gradient of Generative AI Release: Methods and Considerations. In Proceedings of the 2023 ACM Conference on Fairness, Accountability, and Transparency, 111–122. https://doi.org/10.1145/3593013.3593981
SOOFI Consortium. (2026). A sovereign, open-source foundation model for German and English. Technical report, 10 July 2026 (v2, 13 July 2026; v3, 22 July 2026). arXiv:2607.09424. https://doi.org/10.48550/arXiv.2607.09424
Swiss AI Initiative (EPFL, ETH Zurich, and CSCS). (2025). Apertus-70B. Model card, 2 September 2025. https://huggingface.co/swiss-ai/Apertus-70B-2509. Accessed 31 July 2026.
Swisscom (2026). Fastweb and Vodafone. https://www.swisscom.ch/en/about/fastweb-and-vodafone.html. Accessed 31 July 2026.
TechCrunch (2026). What is Mistral AI? Everything to know about the OpenAI competitor. 4 July 2026. https://techcrunch.com/2026/07/04/what-is-mistral-ai-everything-to-know-about-the-openai-competitor/. Accessed 2 August 2026.
The Register (2007). Germany and France split on Google-beater. 2 January 2007. https://www.theregister.com/2007/01/02/germany_quits_quaero/. Accessed 31 July 2026.
TOP500 (2026). TOP500 list, 67th edition, June 2026. https://top500.org/lists/top500/2026/06/. Accessed 27 July 2026.
United States Congress (2018). Clarifying Lawful Overseas Use of Data Act (CLOUD Act), Public Law 115–141, Division V.
Weber, S. (2004). The Success of Open Source. Harvard University Press. https://doi.org/10.4159/9780674044999
Widder, D. G., Whittaker, M., & West, S. M. (2024). Why ‘open’ AI systems are actually closed, and why this matters. Nature, 635, 827–833. https://doi.org/10.1038/s41586-024-08141-1
Xu, X., Li, M., Tao, C., Shen, T., Cheng, R., Li, J., Xu, C., Tao, D., & Zhou, T. (2024). A Survey on Knowledge Distillation of Large Language Models. arXiv, 2402.13116. https://doi.org/10.48550/arXiv.2402.13116
Funding
No specific funding was received for the preparation of this article.
Author information
Authors and Affiliations
Corresponding author
Ethics declarations
Competing interests
I hold no financial interest in Fastweb+Vodafone, CINECA, or any of the other industrial candidates named in § 5, and receive no compensation from them; the pairing is proposed on institutional and strategic grounds only. I am Editor-in-Chief of Philosophy & Technology; this article is submitted under the journal’s procedure for editor submissions, with handling and decision delegated to an independent editor. No other financial or non-financial competing interests are declared. Use of large language models: in accordance with the journal’s editorial policy, I declare substantive use of large language model tools for source retrieval and verification, editorial review, and document preparation, under my direction and review; the arguments, judgements, and final text are my responsibility. Data, materials, and code availability, ethics approval, and consent: not applicable.
Additional information
Publisher’s Note
Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations.
Rights and permissions
About this article
Cite this article
Floridi, L. Rules Without Models: Why Europe Must Build the AI It Regulates. Philos. Technol. 39, 162 (2026). https://doi.org/10.1007/s13347-026-01171-9
Accepted:
Published:
Version of record:
DOI: https://doi.org/10.1007/s13347-026-01171-9
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.