欧盟的 AI 监管,终于动真格的了。
9月第一周,欧盟 AI 办公室依据新生效的《人工智能法》,向全球 30 余家前沿 AI 公司发出了正式的信息请求函(RFI)。名单包括 OpenAI、Google、Anthropic、Meta 这些老面孔,也包括一些中国和中东的模型公司。问询内容覆盖模型安全措施、独立专家评估、部署后监控机制。
这不是"发个调查问卷了解一下"的那种问询。这是依法发出的正式执法动作,企业有义务在规定时间内回复,不回复或者回复不实都有法律后果。
这是欧盟 AI 法 8 月 2 日执法权限正式激活后的首轮正式执法动作。靴子落地了,而且比很多人预想的要快、要重。
欧盟为什么第一个动手?
全球主要经济体里,欧盟不是 AI 技术最强的,也不是 AI 公司最多的,但它是第一个把 AI 监管落到实处的。原因很现实:欧盟在 AI 技术上没有主场优势,但在规则制定上有主场优势。
美国有 OpenAI、Google、Anthropic、Meta,技术是美国最强。中国有百度、阿里、字节、讯飞,应用是中国最多。欧盟呢?没有能打的前沿模型公司,也没有特别大的 AI 应用生态。但欧盟有一样东西别人比不了:它有 4.5 亿消费者的统一市场,还有一套成熟的监管体系。
既然技术上追不上,那就用规则来卡位。欧盟当年在数据隐私上用 GDPR 确立了全球规则,现在在 AI 监管上想用同样的剧本——用欧盟的市场规模和法律体系,把自己的规则变成全球标准。
这个策略能不能成?不好说。但有一点是确定的:任何想在欧洲做生意的 AI 公司,都得遵守欧盟的规则。不管你是美国的还是中国的,只要你服务欧盟用户,就得受欧盟监管。这就是 4.5 亿用户统一市场的分量。
第一轮执法查什么?
这次 RFI 的核心内容,集中在几个关键问题上:
第一,模型的安全评估是怎么做的。 有没有做红队测试?测试覆盖了哪些风险领域?测试的结果是什么?这是最基础的问题,但也是最容易看出问题的地方。很多公司的"安全评估"就是走个过场,真要拿出详细数据来不一定有。
第二,有没有独立第三方参与评估。 欧盟明确倾向于"独立专家评估",不是公司自己测自己。这一点如果执行到位,会大大提高安全评估的可信度——但也会大大增加模型上线的成本和时间。
第三,部署以后的监控机制。 模型上线了以后,有没有持续监控滥用情况?有没有发现新的风险?发现了以后怎么处理?这部分是很多公司的薄弱环节——上线前安全测试做了一堆,上线以后就不管了。
这些问题看起来都是技术问题,实际上是法律问题。如果一家公司的答案不能让欧盟满意,下一步可能就是正式调查、罚款、甚至限制在欧盟的服务。罚款上限是全球营业额的 6%,对于千亿美金级别的公司来说,就是几十亿美金的量级。
全球 AI 治理的分水岭
欧盟这次动手,标志着一件事:AI 的"野蛮生长"阶段,正式结束了。
过去几年,前沿 AI 公司基本处于"自己管自己"的状态。做什么模型、怎么上线、有什么风险,基本上都是公司自己说了算。安全框架是自愿的,测试标准是自己定的,评估结果是自己发布的。
现在不一样了。有一个拥有 4.5 亿用户市场的监管机构,依法要求你回答问题,而且有罚款的权力。这是质的变化。
接下来会发生什么?大概率是这样的:
短期内,大公司会配合——该回复回复,该调整调整。毕竟 6% 的全球营业额罚款不是闹着玩的。中小公司可能会抱怨合规成本太高,但也没办法。
中期看,全球其他监管机构会跟进。美国已经在搞自己的安全测试框架,中国也有备案制。欧盟先动了,其他人不会落后太多。最终会形成一种"监管竞逐"的局面,谁的规则更合理、更可执行,谁就掌握话语权。
长期看,AI 监管会变成一个国际议题。因为模型是无国界的——一个模型在美国训练、在欧洲使用、在中国部署,到底归谁管?这个问题没有简单答案,但必须有人来回答。
Pachocki 说"没人做好准备",欧盟至少先迈出了第一步。准备充不充分是一回事,动不动手是另一回事。
明天见。
EU AI regulation is finally getting real.
In the first week of September, the EU AI Office, under the newly enforced AI Act, sent formal Requests for Information (RFI) to more than 30 frontier AI companies worldwide. The list includes familiar names like OpenAI, Google, Anthropic, and Meta, as well as some Chinese and Middle Eastern model companies. The questions cover model safety measures, independent expert evaluations, and post-deployment monitoring mechanisms.
This isn't "sending a survey to learn more" kind of inquiry. This is a formal enforcement action issued under law — companies are obligated to respond within the specified timeframe, and failure to respond or false responses carry legal consequences.
This is the first formal enforcement action since the EU AI Act's enforcement powers officially activated on August 2. The boot has dropped, and it's faster and heavier than many expected.
Why Is the EU the First to Act?
Among the world's major economies, the EU isn't the strongest in AI technology, nor does it have the most AI companies — but it's the first to put AI regulation into practice. The reason is practical: the EU doesn't have home-court advantage in AI technology, but it has home-court advantage in rule-making.
America has OpenAI, Google, Anthropic, Meta — the strongest tech. China has Baidu, Alibaba, ByteDance, iFlytek — the most applications. What about the EU? No frontier model companies that can compete, no particularly large AI application ecosystem. But the EU has one thing others can't match: a unified market of 450 million consumers, and a mature regulatory system.
Since it can't catch up technologically, it's positioning itself through rules. The EU established global rules on data privacy with GDPR back in the day, and now it wants to use the same playbook for AI regulation — using its market size and legal system to turn its rules into global standards.
Will this strategy work? Hard to say. But one thing is certain: any AI company that wants to do business in Europe has to follow EU rules. Whether you're American or Chinese, if you serve EU users, you're subject to EU regulation. That's the weight of a 450-million-user unified market.
What's the First Round of Enforcement Checking?
The core content of this RFI is focused on several key issues:
First, how the model's safety assessment was conducted. Was red-teaming done? What risk domains did testing cover? What were the test results? This is the most basic question, but also the one where problems show most easily. Many companies' "safety assessments" are just going through the motions — they might not actually have detailed data to show.
Second, whether independent third parties participated in the assessment. The EU clearly favors "independent expert evaluation," not companies testing themselves. If this is enforced properly, it will greatly increase the credibility of safety assessments — but it will also greatly increase the cost and time of getting models to market.
Third, post-deployment monitoring mechanisms. After the model goes live, is abuse continuously monitored? Are new risks being discovered? How are issues handled once found? This is the weak spot for many companies — lots of safety testing before launch, then nothing once it's live.
These questions all seem like technical issues, but they're actually legal issues. If a company's answers don't satisfy the EU, the next step could be formal investigation, fines, or even restrictions on service in the EU. The fine cap is 6% of global turnover — for hundred-billion-dollar companies, that's billions of dollars.
A Watershed for Global AI Governance
The EU acting now marks one thing: AI's "wild west" phase is officially over.
For the past several years, frontier AI companies have basically been in a "self-regulating" state. What models to build, how to launch them, what risks they carry — it was all basically up to the companies themselves. Safety frameworks were voluntary, testing standards were self-defined, evaluation results were self-published.
Now it's different. There's a regulator with a 450-million-user market, legally demanding answers, with the power to fine. That's a qualitative change.
What happens next? Probably something like this:
In the short term, big companies will comply — they'll respond, they'll adjust. 6% of global turnover in fines is no joke. Smaller companies may complain about compliance costs being too high, but there's no way around it.
In the medium term, other global regulators will follow suit. The US is already working on its own safety testing framework, and China has its filing system. The EU moved first, others won't fall far behind. Eventually there will be a "regulatory race" — whoever's rules are more reasonable and more enforceable will hold the high ground.
In the long term, AI regulation will become an international issue. Because models are borderless — a model trained in the US, used in Europe, deployed in China — who has jurisdiction? There's no simple answer to that question, but someone has to answer it.
Pachocki said "nobody is prepared." The EU at least took the first step. Whether the preparation is adequate is one thing. Whether you act is another.
See you tomorrow.
EU AI Act · first enforcement · RFI · 30 companies · safety assessment · independent review · global AI governance · regulatory race · GDPR playbook