France’s AI alignment report puts frontier AI risk management first

Publication date
October 9, 2026
share

On 29 July, French Senator Vanina Paoli-Gagin delivered Pour une filière française et européenne de l’IA alignée to the Prime Minister. The report, produced by the French parliamentary mission on AI alignment, argues that France should approach advanced AI much as it does aviation or nuclear power. In those industries, regulators decide what level of risk is acceptable, and operators have to show they can stay within those limits. AI developers would likewise have to provide quantitative evidence that their systems meet safety thresholds set in advance. We can start putting these requirements in place without waiting for alignment to be solved.

A parliamentary report does not oblige anyone to act, and plenty have been welcomed and then quietly shelved. Still, this one had unusual timing, arriving eight days after OpenAI disclosed its role in the Hugging Face breach, and four days before the Commission’s powers to enforce the AI Act’s general-purpose AI rules became applicable. The question was whether the EU would actually use those powers. The report argued that it should, and called for the funding, expertise and model access regulators would need to do so.

At SaferAI, we’ve argued from the start that AI governance should be built around risk management, so we welcome the report’s support for that approach.

Europe’s evaluation capacity

Does Europe have the capacity to evaluate frontier models independently? The report is unusually frank about where Europe falls short:

When the mission wrote its report, INESIA, France’s AI safety institute, had neither legal personality nor a dedicated budget. The €13.5 million it drew on was a reallocation from an existing Inria programme, and researchers rarely had access to model weights or inference traces. Recommendation 23 would give INESIA its own legal status, a protected multi-year budget and permanent leadership. Some of this has started to move. In September, Inria launched the €13.5 million research programme that serves as INESIA’s scientific roadmap. The structural questions, legal status and a budget of its own, remain open. As Germany and Spain build their own institutes, the French experience offers a lesson: bringing existing bodies together only works if the resulting institute has a clear mandate, dedicated funding and accountable leadership.

The report contrasts France’s resources with those of the UK AI Security Institute. It cites £240 million in cumulative funding through 2030, more than 100 researchers, and around 30 models tested before deployment. That record rested on contractual access agreed voluntarily with developers, an arrangement that showed its limit in September when leading American labs, at their government’s request, held their newest models back from UK pre-release testing. Recommendation 24 would anchor access in law instead.

At the EU level, meanwhile, the AI Office can conduct model evaluations under the AI Act, including through independent third parties. Its systemic risk division has around 30 staff and needs external evaluation capacity to support enforcement.

The report proposes a European evaluation institute with 100 posts and an annual budget of roughly €50 million. It also sets out three conditions for the institute’s researchers: pay competitive with the market, access to compute, and freedom to publish.

We have been making the case for this capacity throughout 2026. Regulators need independent evidence about the models they oversee if they are to enforce the rules effectively. Our evaluation of GLM 5.2, published as the Commission’s GPAI enforcement powers took effect, found that it is close behind frontier models on key hacking and biology benchmarks while lacking frontier safeguards. It shows what independent European researchers can already do at a small scale. The Paoli-Gagin report proposes the staffing and funding needed to support that work at the scale enforcement will require.

Enforcing the AI Act

The UK’s experience also shows how uncertain model access can be. The US has reportedly asked developers to withhold new models from UK testers until a US government review is complete.

The AI Act already gives the Commission powers to require access to models for evaluation, subject to the conditions in the law. The report explicitly supports enforcing its rules for general-purpose AI models in Recommendation 26. The staffing and funding proposed in the report would help regulators put those powers to use.

Recommendation 16 proposes a process for validating models before deployment. Independent red teams would carry out adversarial testing under published, standardized protocols, with reproducible evaluation suites submitted to the supervisory authority. Developers would make commitments in advance about what they would do if their models crossed specified capability thresholds.

Insurance and public procurement

Two further recommendations would give developers a financial reason to keep improving their risk management after meeting their legal obligations.

Recommendation 11 calls for a legal definition of an “alignment incident,” notification to the regulator within 72 hours, and mandatory insurance, with premiums tied to how mature a developer’s risk management is, as judged by independent audits and public ratings much like those used in finance. Recommendation 32 would bring comparable ratings into public procurement. It also calls for developers to publish frontier safety frameworks with verifiable commitments, and for a G7 initiative to list non-cooperative providers of high-risk models.

For any of this to work, insurers and buyers need assessments they can trust and compare, which is one reason we publish the Frontier AI Risk Management Tracker. In our latest analysis, the average company scored 22 percent on frontier AI risk management. That average would rise to 59 percent if companies adopted practices already in use among their peers. Much of the improvement is available now. Insurance costs and procurement decisions could give companies a stronger reason to adopt those practices.

Funding alignment research

The report also makes a case for public investment in reliability research. Recommendation 2 proposes a European ARPA dedicated to safe-by-design AI (something we’ve called for previously), with a base program of €65 million a year and the European Competitiveness Fund as the funding vehicle. Its remit would be the high-risk, high-reward research that the market does not finance.

There is an industrial argument here as well. Safety-critical sectors account for 10.2 percent of gross value added in the EU, compared with 8.3 percent in the US. On the report’s reasoning, Europe has a particular economic interest in making AI reliable enough for those sectors to use. Reliability could be a source of comparative advantage.

A possible route for this funding is already taking shape. The report links its proposal to the breakthrough innovation agency raised at the Franco-German Council of Ministers on 17 July 2026. It argues that fundamental alignment research should be part of that cooperation’s remit, alongside work on frontier capabilities.

Over the coming months, we will be watching the Commission’s call for third-party model evaluation capacity, intended to be operational by 2027; the first formal GPAI enforcement actions under the AI Act; and the research agenda of the Franco-German innovation agency. Those decisions will show how much of the report’s approach makes it into funded research, working institutions, and enforcement.


SaferAI contributed to the parliamentary mission from March 2026. Chloé Touzet and Alice Teilhard de Chardin served on the mission’s pro bono core team, and the report cites SaferAI research, including our work on the economic case for European investment in AI reliability and our European ARPA proposal.

Back to top


Publication date
October 9, 2026
share
More like this
  • 25.08.2026
Better evaluations are not enough. AI governance needs a better evaluation pipeline.
Alice Teilhard, Jack Kengott — with comments from Jakub Krys, May Dixit, Benedict Bruckamp, Chloe Touzet, Henry Papadatos, and Renn Karageorgieva