Europe and the United Kingdom are fine-tuning their approach to AI model testing as a deadline looms for the U.S. government to set rules of the road.
Why it matters: U.S. allies for years have been grappling with the same AI safety questions the Trump administration now faces.
Wherever the U.S. lands in its AI framework, architects of the EU and U.K. approaches say it would be just the start.
The big picture: President Trump began his second term by scrapping his predecessor's AI strategy and pursuing an anti-regulatory regime.
But as AI models became increasingly powerful fast, the Trump administration has found itself developing an oversight framework and deciding exactly what should be covered.
Under Trump's executive order, the administration is due to release its voluntary AI framework by Aug. 1.
The Trump administration is weighing a unified pitch from OpenAI and Anthropic to create "an equal playing field" where highly capable models are all covered, regardless of whether they're open- or closed-source, according to one source familiar with the discussions.
The EU, meanwhile, has treated AI safety as a sustained technical and policy project for several years.
It's a fluid approach to cybersecurity use cases where previous events inform future rules.
Zoom in: One lesson from Europe is to start with specific threat scenarios.
Researchers begin with historical data on threats such as biological weapons, then measure how much AI increases a bad actor's capabilities and whether that creates a systemic risk to society, CEO and co-founder of AI evaluation firm EquiStamp Chris Canal told Axios.
Other key lessons from the EU process include tying benchmarking — testing AI models against standardized evaluations to measure their capabilities and risks — to specific scenarios, such as bioweapons or government database hacks.
The EU also emphasizes multiple, independent verifications rather than relying solely on companies' own assessments.
Canal worked with the EU and U.K. governments to shape their approaches to AI regulation.
Zoom out: The EU commits to getting buy-in from the scientific community, grounding AI risk thresholds in peer-reviewed science before embedding them into policy and pushing researchers to publish their methodologies.
By comparison, the U.S. relies mainly on internal or industry-driven standards.
Technical experts are also flocking to the private sector, particularly in the U.S. and U.K.
What they're saying: "There have been several times where we're working with someone on the [U.K.] government side, and they suddenly put in their two weeks' notice, maybe less, and then they have a great position at OpenAI," Canal said.
The bottom line: Governments are beginning to coalesce around cyber risks, but the U.S. and its allies are only beginning to map AI's broader challenges.