The train carrying the foundational models has already left. Europe has another one.

The train carrying the foundational models has already left the station. Europe has another one. · V-PROOF Journal
V-PROOF Protocol › Journal › Opinion
July 28, 2026
Opinion · EU AI Act · Digital Sovereignty

The train of foundational models has already left the station.
Europe has another one.

The race for artificial intelligence cannot be won by computing power or metrics alone. Europe does not compete in that arena, nor should it try to. It competes in another: verifiable trust, legal sovereignty, and the ability to turn regulation into strategic infrastructure.

EU AI Act The Brussels Effect AI Governance
GB
Gil Blancafort
Founder · V-PROOF Protocol
Coverage · Expansion

This opinion piece is an expanded version of the arguments the author presented in *Expansión* in the article “Startups Are Playing by the New Rules of Risk in AI” (July 2026), which also featured founders from NeuralTrust, Clarity AI, and Maia, among others. The underlying debate deserves more space than a headline can provide.

Europe cannot win the race in terms of computing power.

I’ll be blunt: that ship has already sailed. The world’s most powerful foundational models are trained by companies with access to tens of thousands of state-of-the-art chips, continent-scale cloud infrastructure, and research budgets that exceed the GDP of some member states. Trying to win there, chip by chip, parameter by parameter, is the wrong strategy. Not because Europe is incapable of innovating, but because that’s not the arena where the game is still up for grabs.

And yet, there is one race that Europe can win. One in which its starting point is a real competitive advantage, not just a rhetorical aspiration. That race is called trust.

"Europe cannot win the AI race with computing power or foundational models. That ship has already sailed. But it can win with trust and legal sovereignty."

What sets the European ecosystem apart is not a lack of technological ambition. It is the presence of something that the most heavily regulated global markets—banking, healthcare, the public sector, and critical infrastructure—urgently need and cannot create artificially: a credible legal framework, a foundation of fundamental rights, and the ability to translate that foundation into verifiable technical evidence.

The key question is not how many parameters our best model has. It is whether the organization deploying it can demonstrate that it controlled the model, monitored its decisions, and can prove this to a regulatory authority without having to reconstruct anything after the fact.

Regulation as the export of standards. Influence without the use of force.

There is a recurring pattern in the history of the European Union that is evident in the GDPR, the DORA, the NIS2 Directive, and now the EU AI Act: Brussels enacts legislation with sufficient rigor and technical specificity to ensure that compliance in Europe becomes the de facto standard for any company seeking access to its markets.

A tech company in San Francisco or Shanghai that wants to operate in the European financial sector has no choice but to comply with the AI Act. It will have to comply. And in doing so, it will build its systems in accordance with the requirements Europe has defined: documented risk management, verifiable logs, and demonstrable human oversight. That is strategic influence exercised without firing a single missile.

€35 million
Maximum Penalty for Prohibited Practices · Art. 99.3 EU AI Act
Aug. 2
The date on which most of the provisions of the AI Act take effect
2027
High-Risk AI Systems: Requirements Effective in December

The “Brussels effect” is nothing new. We saw it with data protection: today, global privacy policies are drafted with the GDPR in mind. We’ll see it with AI: organizations that build their governance systems in accordance with the AI Act will set the standards that the rest of the world will have to adopt in order to gain access to the most heavily regulated markets on the planet.

That is regulatory power. And it is the kind of power where Europe has a structural advantage. Not because we have taken technological leadership away from anyone, but because we have spent decades building the framework of rights and obligations that is now becoming a market requirement.

"American and Asian companies that want to operate in Europe will have to comply with European regulations. In effect, the EU AI Act is becoming a global standard for the world's most heavily regulated markets."

Gil Blancafort · Expansión, July 2026

"AI you can trust " isn't just a slogan. It's what buyers in regulated industries need.

There is a recurring debate on the boards of directors of financial institutions, hospitals, and public agencies: the question is not whether AI works. It does. The question is whether the organization can demonstrate that it is using it responsibly to its clients, its regulators, and its own oversight bodies.

There is a technical answer to that question. It does not require a statement of intent or an internal policy document. It requires evidence: which version of the system was active, what controls were applied, who approved them, and when. This evidence must be generated at the time each action is taken, not reconstructed six months later when the audit takes place.

The banking, healthcare, and public sectors don't just want AI to work. They want to be able to demonstrate that they are using it responsibly. That demonstration must be technically verifiable—not just a claim.

The concept of “AI you can trust” is being mentioned with increasing frequency in the European technology sector. This is no coincidence: it is perfectly aligned with the legal certainty that the European Commission is seeking to achieve with the new regulations. And it has a specific implication for organizations that deploy AI in regulated environments: trust cannot be merely a promise from the provider. It must be verifiable from the outside.

Evidence that can only be verified by the party that generated it is not evidence. It is a statement. The difference between the two—between verifiable technical evidence and a statement of compliance—is exactly the difference between what the AI Act requires and what most organizations have today.

August 2 is not the end of a countdown. It is the beginning of a new normal.

Feb. 2025
Prohibited Practices, Enforcement Begins
Prohibition of social scoring systems, subliminal manipulation, and biometric categorization. Penalty: up to 35 million euros or 7% of global revenue.
Aug. 2, 2025
General-Purpose Models (GPAI) · Application
Requirements for GPAI model providers: transparency, copyright policies, and a summary of training data. The generative model ecosystem is entering the regulatory arena.
Aug. 2, 2026
Competent national authorities, as established
Member states must have designated their supervisory authorities. The European enforcement framework is beginning to operate in a coordinated manner.
Dec. 2, 2027
High-risk systems, full implementation
Articles 9, 12, and 14 in effect: risk management with verifiable traceability, event logs with guaranteed integrity, and documentation of human oversight. The actual deadline for organizations with high-risk systems that are deployed or under development.

The timeline is not a distant prospect. It is a process that is already underway. Organizations that reach December 2027 without having built the evidence infrastructure required by the AI Act will not have to catch up all at once: they will have accumulated months of Exposure without demonstrable coverage.

The question isn't whether we need to prepare. It's how long it takes to build a verifiable chain of evidence from the source, compared to how much time we have left. And the answer to the first question is longer than many boards of directors assume.

Digital sovereignty isn't something you simply declare. It's built layer by layer.

Europe has the opportunity to turn its regulatory strength into technological infrastructure. This is not mere rhetoric: it is the practical application of decades of work to build a framework of rights, obligations, and standards that the rest of the world is beginning to adopt out of market necessity.

But that opportunity won’t materialize on its own. It requires European organizations—and those operating in Europe—to build governance systems that not only meet the formal requirements of the AI Act but can also demonstrate compliance. To auditors. To supervisory authorities. To their own boards of directors.

That demonstration must be technically verifiable, generated at the time of each action, and verifiable from outside the organization without relying on its own infrastructure. That is the difference between a declaration of compliance and evidence of compliance.

Trust in AI cannot be based solely on the word of those who deploy it. It must be verifiable. That is the standard Europe is establishing, and it is the kind of competitive advantage that cannot be replicated with more computing power.

The train of foundational models has indeed already left the station. But there’s another train at the station: the one representing verifiable trust as a strategic infrastructure. That train departs from Europe. And you don’t buy a ticket with chips—you build it with architecture.

Would you like to assess your position regarding the AI Act?

Identify your evidence gaps before the regulator does.

The Strategic Assessment analyzes your systems, processes, and regulatory role to determine what evidence you must be able to provide and how to gather it by December 2027.

Contact V-PROOF

90-minute executive session · No obligation · Starting at €3,500

Previous
Previous

The first requirement of the AI regulation is not technical. #ARTICLE 50 AI ACT

Next
Next

The First AI Governance Magic Quadrant: What Gartner Measures and Where the Verifiable Evidence Stands