Compiled by Sarah Willrich.
Articles
You Don’t Have to Sell It to Be Bound by It: GPAI and the EU AI Act
Eliška Andrš examined whether the European Union’s Artificial Intelligence (AI) Act still governs internal use AI models that never reach the market. Andrš explained that despite exceptions for research and development, most internal AI models may ultimately still be covered by premarket enforcement. Andrš also argued that the European Commission should not ignore AI systems which run behind closed doors.
There is one possible way for the European Commission’s enforcement powers to reach a model before market placement. Where the provider plainly intends to place it on the EU market, it is arguable that the European Commission can verify whether the development-stage obligations conditioning lawful placement have been met. An immediate premarket check of this kind is not alien to European regulatory design. Under Article 26(7) of the Deforestation Regulation, customs authorities may verify compliance before the product enters circulation, and Articles 56 and 60 of the Regulation concerning the Registration, Evaluation, Authorisation and Restriction of Chemicals (REACH) make the placing of the most hazardous substances conditional on prior authorisation.
The Forensic Gap in AI Safety Laws
Christopher David LaRoche highlighted an important gap in the mandatory reporting laws for AI safety incidents recently passed by state legislatures in California, Illinois, and New York: They do not clarify what happens after an incident is reported. LaRoche explained why existing investigative powers are insufficient for the unique forensic challenges of AI cases. To address the gap, he suggested regulators require labs to preserve data from incidents and create dedicated teams to assist investigators.
The challenges outlined above are technical problems with existing, if sometimes incomplete, technical solutions. But the actors most able to carry them out—in terms of capability, expertise, and access—are the firms themselves. Firms possess the lion’s share of the relevant data (such as the model versions and operating environment) and the workers needed to make sense of it, such as interpretability expertise.
Put simply, having “grown,” trained, and run their own models, firms know their products better than outsiders do. Firms also have commercial reasons to conceal much of their development, introducing an organizational layer of opacity on top of the technical ones. In the case of internally deployed models, firm employees may be the only actors who know the systems exist. This gives firms a default epistemic advantage—not just control of the data but knowledge over how to interpret it—over outsiders.
Podcasts
Lawfare Daily: Far-Right Gains and a Political Reckoning in Germany:Natalie Orpett sat down with Constanze Stelzenmüller to discuss the German political scene, where a far-right party, the Alternative für Deutschland, is making a strong showing in state elections. They talked about what the party stands for, why its emergence is alarming the pro-democracy community, and what it all means for Germany, for Europe, for the United States, and for the future of Western democracies.
Announcements
*Lawfare *is hiring a Program Assistant for our AI Research Program and seeking applications for the 2026-2027 Student Contributor Program. Learn more and apply at the links above.
To commemorate the 25th anniversary of the Sept. 11, 2001, terrorist attacks on the United States, Lawfare has published a series of pieces in which editors and contributors examine how 9/11 remains—or doesn’t—embedded in current legal and policy frameworks. Read the collection here.
*Support *Lawfare
*Follow us on Twitter, Facebook, YouTube, and LinkedIn. Become a material supporter on Patreon. Sign up to receive *Lawfare