Expert Forum on Frontier AI: why the next two years will decide the EU's competitiveness, sovereignty and security

21/07/2026

On 15 July 2026 the European Commission's AI Office published Enhancing competitiveness, sovereignty and security of the European Union in frontier AI, a report gathering the outcomes of the first meeting of the Expert Forum on Frontier AI, convened in April 2026 with more than 100 experts drawn from European AI developers, industry and investors, technical research, academia and think tanks.

The central message is blunt: the window for meaningful European action is closing, and the next one to two years will likely prove decisive.

The report comes from the very office (the AI Office) that, from 2 August 2026, will exercise supervisory and sanctioning powers over providers of general-purpose AI models under Regulation (EU) 2024/1689 (AI Act), Article 113. In other words, the body collecting these strategic recommendations is the same body that will enforce the rules.

Here is what the report says, the numbers it puts on the table, and what businesses and public administrations should read into it.

  1. An unusual instrument: what the Expert Forum report is (and what it is not)

Start with the nature of the document.

The report is not a communication, not a legislative proposal, and not even — formally — a Commission position. It is the product of the Expert Forum, the consultative arm of the European Frontier AI Initiative, announced in the Apply AI Strategy of October 2025, with the first proposals presented at the European Digital Sovereignty Summit in Berlin in November 2025.

Within the Initiative, frontier AI means any model or system that advances the state of the art in artificial intelligence capabilities.

The Forum's composition deserves attention: nine European AI developers (participating organisations include, for example, Mistral AI and Black Forest Labs), around fifty technical researchers, some forty experts from business and investors, and around twenty from think tanks and academia — alongside representatives of the Member States and the Commission services. The major non-European developers also take part on the industry side.

Operationally, the AI Office has announced that it will group the recommendations by priority and work on their implementation, continuing the exchanges within the Forum through written contributions and targeted workshops.

  1. The capability trajectory: three years from basic tasks to the limits of testing

The first section of the report captures the technological trajectory. In roughly three years, frontier models have moved from struggling with basic mathematics and coding to performance approaching the limits of what current tests can measure. Within the next decade — or sooner — frontier AI could match or exceed human performance across all cognitive tasks, however uncertain any extrapolation of this kind remains.

According to the experts, two dynamics reinforce each other and make the phenomenon harder to observe from the outside.

First, leading developers increasingly use their own best models to automate the research and development of the next generation. Several experts read these developments as movement towards recursive self-improvement — the threshold at which AI autonomously builds its own next generation, long regarded as a defining moment in the trajectory of the technology.

Second, the most capable models are deployed inside the developing companies before any public release. As a result, capability gains concentrate in a handful of firms and the space for external oversight narrows, leaving public authorities and public opinion with an incomplete picture both of what the frontier can already do and of the risks it carries.

On the front of most interest to cybersecurity practitioners, the report flags offensive cyber capabilities as improving particularly fast, citing the recent identification, by an AI model, of a 27-year-old vulnerability in a hardened open-source operating system used in critical infrastructure.

And it repeats — more than once, and not incidentally — that the same capabilities driving economic and scientific progress amplify a set of systemic risks of direct relevance to the security of the Union and its Member States.

  1. The numbers behind the imbalance: 5% of global compute, 1% of revenues

The report has the merit of lining up a series of figures rarely found together in an institutional document.

On the market: frontier revenues flow almost entirely to a handful of non-European developers, with the two leading firms together reaching reported annualised revenues of around USD 60 billion in spring 2026; the faster-growing of the two multiplied its revenues more than 15-fold in little over a year. The combined revenues of European frontier developers amount to roughly 1% of those of their non-European competitors, while European venture funding in AI stops at around 6% of the global total. The experts add a caveat worth reporting: those revenues come with very large capital raises and sustained operating losses, and a durable business model at the frontier has yet to be demonstrated.

On infrastructure: global AI compute doubles roughly every seven months, the largest individual data centres are scaling towards the gigawatt class (one of the biggest planned non-European sites will exceed 3 GW by 2027), and frontier training keeps growing four to five times a year. The Union, which accounts for around 15% of global GDP, hosts an estimated share of global compute of just 5%. The experts suggest aligning the first figure with the second, which would require a several-fold expansion of European capacity by 2030. The AI Gigafactories are cited as a first step, with expressions of interest worth over EUR 230 billion from 16 Member States — but this first wave, the experts warn, will need to be extended significantly.

The practical bottlenecks, moreover, are not (only) capital: they are energy, permitting and the grid. Industrial electricity prices in the EU in 2025 averaged more than double US levels and roughly 50% above Chinese levels. Hence the proposal for Data Centre Acceleration Zones with a one-stop permitting shop, clean energy on site and reuse of existing grid connections, identifying decommissioned sites such as former coal-fired plants as natural locations.

  1. The four structural barriers and the legal knot of training data

Since frontier AI development is driven globally by private investment, a credible path towards European capabilities starts with removing the structural barriers to attractive market conditions.

The report identifies four barriers: compute infrastructure and energy (the urgent priority for the next two years); growth-stage capital (the tightest financial constraint, to be addressed also through an AI growth facility modelled on national sovereign wealth funds and through financing from the European Investment Bank (EIB) and the European Investment Fund (EIF)); legal clarity on training data; and talent (at once Europe’s greatest strength and its most immediate vulnerability, with the proposal of a pan-European tech visa, digital and portable across Member States).

For readers of these pages, the third point is the one with the greatest legal depth.

The experts describe copyright and data protection rules as factors that decisively shape the conditions for training frontier models in the Union — and therefore, downstream, the very demand for European compute. Two specific concerns emerge: the possibility that the model itself may qualify as personal data, and the issue of reproduction for copyright purposes, in respect of which the current rules are described as not well adapted. Data, in short, remains the pivotal issue.

The suggested solutions are specific: an exemption for model training, to be introduced by amending the GDPR through the Digital Omnibus; an output-based remuneration framework administered by collecting societies; and an extension of the text and data mining exception (currently set out in Articles 3 and 4 of Directive (EU) 2019/790) to address the memorisation problem in copyright law. As a working precedent, the report cites collective licensing models, including a national initiative that trains generative language models on licensed cultural heritage data, so that the resulting models can be shared without sharing the underlying protected material.

Finally, the report values Europe’s wealth of sectoral and private data as a potential differential advantage — rich but fragmented data, for which the European Data Spaces are cited as the instrument of recomposition.

Anyone working in healthcare and life sciences will recognise exactly what this is about.

  1. Selective bets: from the current paradigm to the other layers of the stack

Alongside the structural conditions, the experts recommend a deliberate portfolio of high-risk, high-reward research bets in areas where Europe has a credible path to leadership.

Within the current paradigm, the proposals range from open pipelines that reproduce and improve on what the leading firms do (useful for following the frontier, not for setting it) to open-weight models, read together as a lever of sovereignty and a catalyst for the ecosystem. One passage deserves emphasis: research on trustworthy, safe and secure-by-design AI is flagged as a persistently underfunded agenda, and the experts note (with a touch of paradox the report does not spell out, but which is hard to miss) that Europe lags precisely in the tools needed to implement its own AI rulebook: audit tools, bias detection methods, training data tracing, compliance infrastructure.

The alternative approaches include agentic AI (a key direction, but with an unresolved tension between removing humans from the loop for efficiency and preserving safety and oversight), world models, physical AI and robotics — with a concrete proposal for an embodied intelligence consortium worth around EUR 25 billion over ten years, combining European public investment with binding purchase commitments from the major automotive and industrial manufacturers.

The more original part concerns the other layers of the stack.

The experts identify a specific opportunity in the verification layer now emerging in the global AI stack: hardware-rooted cryptographic proofs capable of verifying properties of AI software and of the hardware it runs on — where the model is located, where the data are processed, that the weights cannot be exfiltrated, that access cannot be cut off. Today such guarantees are largely contractual; no player yet holds a dominant position in this layer, and Europe could put itself forward, for example by identifying the sites for the first demonstrably secure AI cluster. On research instruments, the report records the proposals for a “CERN for AI” and a DARPA-style funding vehicle, complementary to the longer cycles of Horizon Europe.

  1. Access, choice, control, benefit: sovereignty without autarky

The conceptually broadest and most elaborate chapter of the report is the fourth.

Because frontier development is currently concentrated abroad, the EU must in any event strengthen its sovereign capacity to access any frontier model, choose among suppliers, control how models operate within European jurisdictions, and capture their economic benefits. Some experts warn against conflating digital sovereignty with technological autarky — a view this author shares, though it is certainly very difficult to put into practice. Existing strength along the stack can be converted into global influence, without having to build a domestic alternative for every technology.

In support of the urgency, the experts recall a recent case in which European governments were denied timely access to a frontier system with direct security implications (the reference is clearly to the Anthropic Mytos case). This is exactly the scenario of access limited or revoked from outside that I have already had occasion to discuss in an earlier commentary on the Action Plan on Cybersecurity and Artificial Intelligence (COM(2026) 577 final) of 7 July 2026. The two documents should indeed be read together: the action plan builds the operational instruments — the European Blueprint for structured access to advanced AI capabilities expected by the fourth quarter of 2026, and the European model evaluation capacity expected in 2027 — while the Expert Forum report provides their strategic frame.

The convergence is no accident: it is the same policy, seen from the security side and from the competitiveness side.

As for negotiating leverage, the experts locate it first of all in the chokepoints Europe already controls — above all the dominant position of a European company in the equipment for manufacturing advanced semiconductors, without which neither the US nor the Chinese frontier infrastructure could be built in its current form. Protecting these positions is as much a political task as a technical one: economic security instruments work, the experts warn, only where Member States explicitly share the costs of potential retaliation.

On control, the report recommends building a European capacity for audit, evaluation and verification of frontier systems along three mutually reinforcing tracks: pre-release evaluation, third-party audit and continuous monitoring through accredited independent evaluators and public institutional capacity; investment in secure and verifiable infrastructure as a complementary technical layer; and structured coordination with counterpart institutions in partner jurisdictions. It also proposes adding weight to the European position by joining it with that of trusted partners facing similar constraints — the United Kingdom, Canada, Japan, the Republic of Korea, Australia, New Zealand and India — going as far as to suggest convening an inaugural summit of this coalition.

On benefit, finally, three structures: public procurement as a demand-side instrument (with current public spending on foreign hyperscalers cited as evidence of unused leverage); intellectual property and licensing frameworks that protect European data and domain expertise when used in frontier development, preventing European assets from simply subsidising the development of other players’ models; and policies channelling adoption towards sectors of industrial strength and towards use cases of social value — healthcare, education, public services — where market signals alone tend to underinvest.

  1. Institutional speed: the GPAI Code precedent and the 2030 goals

The final chapter addresses the problem that conditions all the others: the pace of frontier development risks outstripping the response capacity of public institutions.

The experts recommend ambitious goals for 2030, repeating that the window for meaningful action is already narrowing.

That the European institutions can — when they choose to — move at the required speed is already proven by the Code of Practice for GPAI models (Article 56 AI Act), drafted by independent experts in under a year through several drafting rounds informed by more than 1,000 stakeholders, then endorsed by the Commission and the Member States and signed by the frontier developers.

The ask is to apply the same targeted urgency to competitiveness, sovereignty and security.

The institutional recommendations are concrete: frontier AI as a first-rank political priority, with dedicated mechanisms to keep political leaders directly and continuously informed; centralised oversight of implementation, for example through a dedicated task force; foresight functions on capabilities and risks within the Commission and the Member States; and information-sharing structures and emergency response frameworks prepared in advance, with activation thresholds and designated responsibilities — because large-scale inter-institutional coordination cannot be organised on the eve of the event.

The experts also call for a significant strengthening of the AI Office’s staffing, for the recruitment of frontier specialists on competitive terms and — a far from obvious point — for public institutions themselves to make active use of the most recent frontier capabilities, tackling early the practical barriers of procurement, data security and technical integration.

  1. Practical implications: reading the report as a map of the next eighteen months

An expert report creates no obligations. But when the body publishing it is the same body that, from 2 August 2026, exercises supervisory powers over GPAI models, and when the announcement is that the recommendations will be grouped by priority and implemented, the document should be read as a reliable map of the regulatory and policy direction of the coming months.

For businesses and public administrations, the steps that can and should be set in motion now fall into place as follows:

  • contracts governing model access: the scenario of access limited or revoked is now in black and white in two Commission documents published in the same month; anyone building products and services on non-European frontier models should keep a close watch on the clauses governing continuity of access, portability, exit and supplier diversification;
  • procurement and supplier diversity: purchasing policies that explicitly value a plurality of providers are recommended at European and national level; contracting authorities and procurement functions would do well to anticipate them;
  • training data: anyone developing or fine-tuning models in the EU should monitor the evolution of the Digital Omnibus amendments to the GDPR and of the debate on the text and data mining (TDM) exception, because that is where the legal certainty of training in Europe will be decided — bearing in mind that, as matters stand, these are proposals and recommendations, not law in force;
  • compute and energy: for projects requiring significant compute, the geography of the AI Gigafactories and of the future acceleration zones will affect costs and timelines; it pays to follow site selection from the very first calls;
  • sectors of social value: healthcare, education and public services are expressly named as targets of adoption incentives; for life sciences, this is a signal to pick up now, not once the calls are published.

Above the operational level, the overall reading.

With this report the Commission completes the picture opened by the action plan on cybersecurity and AI: there, the message was that the security of Europe’s critical infrastructure depends on capabilities that others can revoke; here, the message is that the Union’s entire economic and strategic position depends on those same capabilities — and that the time available to correct the trajectory is measured in months.

In this author’s view, the turning point is exactly this: access to frontier AI stops being a technology choice and becomes a governance variable — of the supply chain, of contracts, of enterprise risk.

Organisations that already treat it that way hold an advantage; the others have, precisely, one to two years.