Why Europe's AI Rulebook Is Quietly Copying Silicon Valley's Playbook
The European Union created the world's first comprehensive AI regulation, but a new analysis reveals it's inadvertently adopting the same Silicon Valley logic it aimed to constrain. The EU's approach combines binding rules in the 2024 AI Act with a voluntary industry code of practice, effectively making Big Tech companies co-stewards of their own regulation rather than subjects of independent oversight.
What Is Technosolutionism and Why Does It Matter in AI Governance?
Technosolutionism is the belief that technology itself, rather than democratic institutions or public oversight, can solve complex social and political problems. In the context of AI governance, this means assuming that technical standards, industry self-regulation, and voluntary commitments can adequately manage the risks posed by powerful AI systems. The concern is that this approach prioritizes technological fixes over democratic accountability and public input.
The EU's regulatory framework reflects what researchers call "sociotechnical imaginaries," or shared visions of desirable futures embedded in policy design. The 2024 AI Act frames AI as a tool that "contributes to a wide array of economic, environmental and societal benefits" while simultaneously acknowledging it "may generate risks and cause harm to public interests and fundamental rights." This dual narrative creates a structural tension: the EU wants to regulate AI's risks, but it's delegating significant responsibility for managing those risks to the very companies that profit from AI development.
How Does the EU's Hybrid Regulatory Model Actually Work?
The EU's AI governance strategy combines two distinct instruments. The 2024 AI Act provides binding, enforceable rules with a risk-based approach. The 2025 General-Purpose AI Code of Practice, by contrast, is voluntary and relies on commitments made by industry players themselves. This combination creates what researchers describe as a "hybrid model" where Big Tech is not merely an object of regulation but also a co-producer of regulatory standards in sensitive areas like systemic risk management.
The distribution of responsibilities between EU institutions and Big Tech companies reveals the core problem. Rather than establishing independent regulatory bodies with the power to audit, test, and enforce compliance, the EU framework allows dominant corporations,primarily US-based companies like Google, OpenAI, Microsoft, and Anthropic,to largely police themselves through voluntary commitments. This mirrors the "Trust and Safety" model that has become standard in the social media industry, where companies employ their own teams to manage content moderation and policy enforcement.
Steps to Understand the Risks of Regulatory Capture in AI Governance
- Regulatory Capture Risk: When the companies being regulated have significant influence over the rules that govern them, they can shape those rules to minimize compliance costs and maximize their competitive advantages, undermining the original intent of regulation.
- Technosolutionist Bias: The EU's framework assumes that technical standards and industry codes can adequately address systemic risks, when in fact many AI risks are fundamentally political, social, and economic in nature and require democratic deliberation.
- Reliance on Private Infrastructure: By delegating governance to Big Tech platforms, the EU creates dependency on private companies' technical systems, data, and decision-making processes, which are not subject to public transparency or democratic accountability.
- Surveillance Capitalism Integration: Most dominant AI companies operate surveillance capitalist business models that treat human experience as raw material for behavioral data, creating inherent conflicts of interest when these same companies are tasked with governing AI safety.
The research traces how the EU's approach evolved from the 2019 High-Level Expert Group on AI report, which emphasized "trustworthy AI" and ethics, through to the 2024 AI Act and 2025 Code of Practice. At each stage, the framework shifted toward greater reliance on industry self-governance and voluntary commitments, rather than strengthening independent public oversight.
The dominant AI companies in the EU market remain overwhelmingly US-based, including Google and its subsidiary DeepMind, OpenAI, Anthropic, Microsoft, Amazon, and Nvidia. While some European alternatives like French startup Mistral and Chinese competitors like DeepSeek exist, the regulatory framework is effectively designed around the needs and capabilities of these dominant US corporations.
What Are the Democratic Alternatives to Europe's Current Approach?
The research identifies a fundamental gap between the EU's stated commitment to democratic governance and the technosolutionist logic embedded in its regulatory instruments. Rather than assuming that technology companies can self-regulate effectively, alternative approaches would prioritize independent public institutions, transparent decision-making processes, and meaningful participation by civil society, labor representatives, and affected communities.
The core issue is that the EU has created a regulatory framework that mirrors Silicon Valley's approach to governance rather than challenging it. By combining mandatory rules with voluntary industry codes, and by delegating significant responsibility for systemic risk management to Big Tech companies themselves, the EU has reproduced the same technosolutionist logic that has allowed surveillance capitalism to flourish globally. The result is a regulatory system that may appear comprehensive on paper but lacks the independent oversight and democratic accountability necessary to genuinely constrain the power of dominant AI companies.