Under a mechanism the authors call 'co stewardship,' the AI companies being regulated by Europe also help run the room where the rules are written.
Europe's AI rulebook was supposed to constrain the largest AI companies. A [peer-reviewed study published August 21, 2026 in Internet Policy Review](https://policyreview.info/articles/analysis/brussels-technosolutionism-sociotechnical-imaginaries) argues the rules instead gave those same companies a structural seat at the rule-making table, through a voluntary Code of Practice whose signatories now help the regulator operationalize the rules they are subject to.
The study, by Alvaro Oleart of the Université libre de Bruxelles and Alejandro Flores Moleón of the Universidad Autónoma de Madrid, empirically compares three EU AI instruments: the 2024 AI Act, the 2025 General-Purpose AI (GPAI) Code of Practice, and the 2019 High-Level Expert Group's "Ethics Guidelines for Trustworthy AI." The authors name the resulting arrangement "co-stewardship," a hybrid governance model in which large technology companies are both regulated entities and participants in defining how regulation works.
The Code of Practice is the operational center of that arrangement. The European Commission published it in 2025 and describes it as a voluntary route by which providers of general-purpose AI models can demonstrate compliance with the AI Act until harmonized technical standards are in place. Non-signatories have to show the Commission they are compliant some other way. The Code has three chapters, Transparency, Copyright, and Safety and Security, and was drafted by 13 independent experts with input from "over 1,000 stakeholders," according to the Commission.
The current signatories include Amazon, Anthropic, Google, Microsoft, Mistral AI, and OpenAI, plus other providers. They sit in a signatory task force chaired by the EU AI Office, the new body inside the Commission that will enforce the GPAI rules. The AI Act's GPAI provisions entered into application on August 2, 2025, and the AI Office becomes the enforcer one year later for new models and two years later for models already on the market.
That is the mechanism the authors flag. The regulated companies are not merely consulted on the rules; they help operationalize them. The Code's risk-assessment methods, transparency templates, and safety-and-security guidance are written and run with the signatories in the room. The underlying compute and cloud on which model training and serving depend is, in most cases, supplied by the same firms or their infrastructure peers. Oleart and Flores Moleón link this to a dependence on privately controlled technical infrastructure that they argue can narrow democratic intervention in how AI is deployed across Europe.
The Commission's "over 1,000 stakeholders" figure is real but addresses a different question. The Code's consultation process did draw input from model providers, small and medium AI companies, academics, AI safety experts, rightsholders, and civil society. Process breadth, however, is not the same as structural control over how the rules are operationalized, and the authors' claim is about the latter: the small set of actors who can supply the standards, the risk methods, and the infrastructure that compliance actually requires.
The trajectory is not fixed. The GPAI Code of Practice is a transitional instrument, since the Commission treats it as standing in until harmonized European standards are available, and the standards are still being written. The AI Office task force's remit, and any move toward public or independent technical infrastructure for AI training and serving, are the live decision points. The study gives those decisions a name. Whether the next decade of AI deployment in Europe is shaped by a small set of corporate incentives or by a broader public-interest frame is, for now, still being negotiated in that room.