Field Dispatch

Cédric O's Pirouette

In November 2023, in the closing hours of the European Union's trilogue negotiations on the AI Act, the rapporteurs from the European Parliament, the Council of the European Union, and the European Commission convened in Brussels to settle…

2026-08-02 19 min read Dispatches
Companion to Quiet Autocomplete

In November 2023, in the closing hours of the European Union’s trilogue negotiations on the AI Act, the rapporteurs from the European Parliament, the Council of the European Union, and the European Commission convened in Brussels to settle the bill’s foundation-model provisions. The provisions were, by that point, the most-fought-over clause set in the bill’s three-year drafting history. The labs wanted them gutted. The civil-society coalition wanted them tightened. The French government, with the Italian and German governments in concert, wanted them softened to a degree that civil-society organizations described as effectively decorative.

The French government’s negotiating position was prepared, in substantial part, by Mistral AI. Mistral AI’s chief lobbyist for European Union policy, at the time, was a man named Cédric O.

Until 2022, Cédric O had been the Secretary of State for the Digital Transition of the French Republic. He had served in that role for three years. He had personally chaired meetings of the French Interdepartmental Committee on Generative AI. He had personally negotiated, on France’s behalf, the bilateral and multilateral coordination of the EU AI Act’s early drafts. He had, in short, been a senior architect of the regulatory regime he was now being paid to dismantle.

His transition from public office to Mistral was preceded by a referral to the Haute Autorité pour la transparence de la vie publique, the French government’s independent ethics authority, known by its acronym HATVP. The HATVP reviewed the proposed transition under the standard provisions of French public-service law, which prohibit former ministers from accepting positions in industries they had regulated for a defined cooling-off period.

The HATVP issued a written prohibition.

Cédric O accepted the position at Mistral.

In the spring of 2023, in the role HATVP had told him in writing he should not take, he began to lobby his former colleagues in the French government against the foundation-model provisions of the EU AI Act. The lobbying was extensive. It was documented in reporting by Bloomberg, by Politico Europe, by the Brussels-based watchdog Corporate Europe Observatory, and by Le Monde. The lobbying was, by all accounts of the trilogue negotiations, materially decisive. The foundation-model provisions emerged from trilogue dramatically softer than civil-society organizations had advocated and meaningfully softer than the European Parliament’s pre-trilogue position.

The revolving door only looks like two rooms. It is one figure seen twice — the regulator on the way in, the lobbyist on the way out.

Throughout the period of this lobbying, Cédric O continued, simultaneously, to sit on the French government’s Interdepartmental Committee on Generative AI. He was, in effect, both the regulator and the regulated: the lobbyist for the bill’s softening and the government adviser informing the French negotiating position the lobbyist was lobbying.

The HATVP’s prohibition was not formally challenged in court. It was not appealed. It was simply ignored.

By the time of the AI Act’s final passage in early 2024, Mistral AI had been valued at approximately six billion euros. Cédric O’s equity position in the company, by his own disclosure to the French Senate’s Committee on Economic Affairs, was worth approximately twenty-three million euros.

The HATVP, asked for comment on his continued role at Mistral after the prohibition, said that its prohibitions are advisory, not enforceable. French law does not provide criminal penalties for ministers who decline to comply with HATVP determinations. The case became, by quiet acknowledgment within the French civil service, an instructive example of what the regulatory regime governing post-ministerial conduct is capable of producing in practice.

Cédric O is not the scandal. The architecture that produced no friction against him is.

A regulator who becomes a lobbyist for the entity he previously regulated, against an ethics authority’s written determination, while sitting on the government body advising the negotiation he is now influencing, while holding a twenty-three-million-euro equity position in the firm whose interests he is paid to advance — this is not a description of a particular individual’s bad judgment. The HATVP wrote the prohibition. No one enforced it. The French government’s Interdepartmental Committee continued to seat him. No one objected. The Brussels lobbying register recorded his meetings. No one read it.

This is the capture-of-capture pattern that the second book in this series, The Ratchet, identified at the institutional level. The Ratchet documented how the apparatus of regulatory oversight, professionalized over four decades, becomes structurally incapable of regulating the entities it was created to oversee. Cédric O is the personal-level instantiation of the same pattern. The regulator becomes the lobbyist becomes the equity holder. The institutions provide the path. The institutions do not provide the friction.

There are seven other documented instances of this pattern in the European Union legal-architecture record. None of them is quite as cleanly documented as Cédric O. None of them carries quite the same explicit HATVP-prohibition-and-violation paper trail.

Thierry Breton, the European Commissioner for the Internal Market until September 2024 and one of the principal architects of the AI Act, joined the global advisory council of Bank of America within months of leaving Brussels. The Commission’s own ethics committee reviewed the appointment and cleared it, with conditions, in December 2024. Transparency campaigners objected that it carried him through the revolving door well inside the two-year cooling-off period the EU imposes on departing commissioners.

In the United States, the comparable record is the eight-page disclosure filed by David Sacks, the venture capitalist whom the Trump administration designated as “AI and crypto czar” in December 2024. Of the roughly seven hundred technology investments Sacks’s disclosure listed, four hundred forty-nine were AI companies, the sector his czar role gives him discretionary authority over. The disclosure did not specify which.

The Sacks disclosure was filed. It was published. It was not, as of May 2026, the subject of any formal Office of Government Ethics inquiry.

These are not individual scandals. They are points on a curve. The curve is the rate at which senior regulatory personnel transition from the body they regulated for, into the body they regulated, with the body they regulated for then continuing to seat them in advisory roles while they advise the body they now work for on the body that now seats them. The curve has a name in the academic literature: regulatory capture — visible here at the individual level, as a sequence of dated decisions, each one disclosed, none of them prohibited in any way that mattered.

The HATVP issued the prohibition. The prohibition is in the public record. The violation is in the public record. The equity payout is in the public record. The lobbying meetings are in the public record. The simultaneous seating on the Interdepartmental Committee is in the public record. The softened foundation-model provisions are in the public record. The valuation of Mistral is in the public record.

Each segment of the loop is on file with a French or European authority. The whole thing is documented. The whole thing was, by every formal measure, transparent. Transparency, in this case, achieved nothing.

To see why the question is worth asking, it helps to follow the bill it was asked about. From the people who drafted it, through the register that recorded who lobbied them, to the carve-out that the lobbying produced.


The EU AI Act had a small number of named authors, and the record gives all of them.

On the Parliament side, the foundation-model provisions were shepherded by two co-rapporteurs: Brando Benifei, an Italian Social Democrat, on the internal-market committee, and Dragoş Tudorache, a Romanian liberal, on the civil-liberties committee. On the Council side, the file was led during the decisive December 2023 trilogue by Carme Artigas, Spain’s Secretary of State for Digitalization and Artificial Intelligence, because Spain held the rotating Council presidency that month. On the Commission side stood Thierry Breton and Margrethe Vestager, the Executive Vice-President responsible for the broader digital portfolio.

These were the people Cédric O was lobbying, or lobbying around. The Commission had published its original proposal in April 2021. Parliament adopted its negotiating mandate in June 2023. The trilogue reached political agreement after a marathon three-day session that closed on the eighth of December 2023. Parliament gave final adoption on the thirteenth of March 2024, the Council on the twenty-first of May, and the Act was signed on the thirteenth of June and published in the Official Journal on the twelfth of July. Five named people, a three-year clock, a public calendar.

What the calendar does not show is the money standing next to it.


In October 2025, the Brussels watchdog Corporate Europe Observatory and the German group LobbyControl published the most recent comprehensive accounting of what the digital industry spends to be in the room when bills like the AI Act are drafted. The figure was one hundred fifty-one million euros a year, up from one hundred thirteen million in 2023, a thirty-three-percent increase in two years. The top ten spenders accounted for forty-nine million of it, a third of the total. Meta led at ten million. Microsoft, Apple, and Amazon followed at seven million each. Google and Qualcomm at four and a half. The numbers descend from there into the trade associations and the second-tier firms, but the shape is the point: a third of the declared lobbying budget of an entire continent’s digital-policy apparatus belongs to ten companies, and the people those companies are lobbying are the five named individuals above.

The register that holds these numbers is public. Anyone may read it. The summaries of the meetings between Commission AI officials and OpenAI, Anthropic, and Google during the Act’s drafting are in it. The numbers are disclosed because the law that created the register required the disclosure. The register is, in the language the previous sections established, transparent.

It is also, by the watchdogs’ own account, almost never read by the people the disclosures are nominally meant to protect.


The lobbying bought a specific clause, and the clause is worth reading, because it is the thing that the whole apparatus of named authors and declared spend actually produced.

In September 2022, fourteen months before Cédric O’s November lobbying, OpenAI had submitted a seven-page document to Commission and Council officials titled, with the flatness of a tax form, the “OpenAI White Paper on the European Union’s Artificial Intelligence Act.” Its argument was narrow and effective: that general-purpose systems like GPT-3 should not be classified as inherently high-risk. The white paper was not public. TIME obtained it under a freedom-of-information request and published the story in June 2023, ten months after the document was filed, by which point its argument had already done its work. The final text dropped the earlier draft language that would have classed general-purpose AI as inherently high-risk. The general-purpose systems were moved instead into a separate, lighter regime governed by codes of practice.

This is the part civil society lost. It is also the part that explains why a French startup’s lobbyist mattered so much in November 2023: the foundation-model chapter was the last place where the bill might still have bitten the model makers rather than the people who merely deploy their models. Mistral’s framing — repeated by Cédric O and echoed by the German firm Aleph Alpha with the German government — was “rules for apps, not model makers.” The model makers should be regulated lightly; the obligations should fall downstream, on the companies that build products on top of the models. The two startups pushed that line into the French and German Council positions and nearly killed the foundation-model chapter outright. What survived was softer than the Parliament had wanted and far softer than Access Now, EDRi, and Amnesty had advocated.

And the bill kept a second door, wider than the first. Article 2, paragraph 3, exempts any AI system used “exclusively for military, defence or national security purposes, regardless of the type of entity carrying out those activities.” Anything dual-use that a member state chooses to declare as having a national-security application falls out of the regulation entirely. The member states with the strongest intelligence services — France, Germany, the Netherlands — kept that language broad over civil-society objection. The chapter you are reading sits in a book whose first chapter described a single software platform sold to the IAEA, the CDC, the NHS, ICE, and a Pentagon kill chain. Article 2(3) is the clause that lets the kill-chain half of that platform out of Europe’s flagship AI law by declaration.


The same pattern wrote itself in the United States, except that there the bill was an executive order and the loop ran faster, because an executive order can be revoked on a morning.

President Biden signed Executive Order 14110 — “Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence” — on the thirtieth of October 2023, eight days before the EU trilogue convened. It too had named authors. Arati Prabhakar, the director of the Office of Science and Technology Policy, had signaled that August that the order was being expedited. Bruce Reed, a deputy chief of staff, was the senior White House coordinator. Ben Buchanan was the President’s special adviser for AI. And Elizabeth Kelly, a special assistant to the President for economic policy, helped draft it. That detail matters because of where she went next.

She went to run the institute the order created. In February 2024, the Commerce Department named Kelly the inaugural director of the US AI Safety Institute, the body stood up to evaluate frontier models under the authority of the order she had helped write. She lasted one year. In February 2025, with the new administration in office, she departed. The order she helped draft had been revoked on the new President’s first day, the twenty-third of January 2025, folded into a sweep of “Initial Rescissions of Harmful Executive Orders.” The safety infrastructure she had personified was disassembled by the same instrument that built it, in the opposite direction, fifteen months later.

The replacement order, Executive Order 14179 — “Removing Barriers to American Leadership in Artificial Intelligence” — also had named authors, and they came from the other direction. Michael Kratsios, the new OSTP director, had been the first administration’s chief technology officer and had spent the interregnum as a managing director at Scale AI. David Sacks, a venture capitalist, was named special adviser for AI and crypto, the post the press called “AI czar.” The order directed the two of them, with the national security adviser, to produce an action plan within a hundred eighty days. The plan, “Winning the Race,” arrived in July 2025: ninety-plus federal actions, three pillars, strongly deregulatory, with an explicit goal of removing “ideological bias” from federal AI systems. Its reported lead authors were Sacks and a former Andreessen Horowitz general partner, Sriram Krishnan, who had himself moved from the venture firm into a senior White House AI-policy role that January.

The EU loop took three years and ran through a register. The US loop took fifteen months and ran through a signature. The personnel moved the same direction: out of the firm, into the office that governs the firm, and — in Kratsios’s and Krishnan’s case — into the office directly from the firm.


Then the US loop did something the EU loop had not. It turned on the states.

By the end of 2025 the federal government had no AI statute, but several states did. California’s was the consequential one, and its history is a two-year demonstration of how a regulation gets sanded down to something the regulated can live with. State Senator Scott Wiener’s first bill, SB 1047 — the Safe and Secure Innovation for Frontier Artificial Intelligence Models Act — would have imposed safety obligations on the largest frontier developers keyed to compute thresholds. OpenAI opposed it. Meta opposed it. Google opposed it. Anthropic, alone among the major labs, was cautiously supportive. Governor Newsom vetoed it on the twenty-ninth of September 2024, reasoning that it fixed on compute thresholds rather than the context in which a model is deployed.

Wiener came back a year later with a smaller bill. SB 53 — the Transparency in Frontier Artificial Intelligence Act — kept the disclosure spine and dropped most of the teeth. Large developers must publish a safety framework on their websites, whistleblowers get protections, the attorney general can levy civil penalties up to a million dollars per violation, and the state gets a public cloud cluster called CalCompute. Newsom signed it on the twenty-ninth of September 2025, a year to the day after the veto. It took effect on the first of January 2026, the first frontier-AI safety law in force anywhere in the United States. It is also, by design, a transparency law: it requires the developers to publish. Not to behave.

Three months after California passed even that, the federal government moved to erase it. On the eleventh of December 2025, the President signed an executive order — “Ensuring a National Policy Framework for Artificial Intelligence.” It directed the Attorney General to stand up an “AI Litigation Task Force” to challenge state AI laws as preempted or unconstitutional. It directed the chair of the Federal Trade Commission to issue, within ninety days, a policy statement asserting that the FTC Act preempts state laws requiring “alterations to the truthful outputs of AI models.” And it directed Commerce and the Office of Management and Budget to condition federal funding on state cooperation with the national framework. David Sacks publicly took credit for the order. There was no public-comment process; reporting indicated that the industry input had come through the same channels that produced the action plan he had co-authored. NPR’s report led with an observation. The order “may not be legal.”

The target was the bias-audit and content-moderation laws. California’s transparency obligations are likely safer, being adjacent to national security, but Colorado’s broader high-risk-AI statute sits squarely in the litigation task force’s path. The federal government had spent a year declining to regulate the labs. Then, when a state did it instead, it spent a single executive order trying to stop the state. The same office that would not write the rule sued to prevent anyone else from writing it.


There was a layer beneath all of it that no one had to revoke, because it had never been binding in the first place.

The National Institute of Standards and Technology had published the AI Risk Management Framework in January 2023, led by Elham Tabassi, a NIST information-technology chief of staff, with extensive public engagement. Three workshops, two comment drafts, a request for information. The generative-AI profile that followed in July 2024 was drafted by a NIST team working alongside a public working group whose participants included OpenAI, Anthropic, Google, Microsoft, Meta, and the rest of the major labs. They sat at the table next to the ACLU, the AI Now Institute, and EPIC. The industry comment volume pushed three things in particular: alignment with international standards — that is, harmonization downward toward weaker regimes — flexibility in implementation, and, above all, the clarification that the framework was voluntary.

It was already voluntary. The labs had helped write a framework that asked them to manage their own risks and bound them to nothing, and then, in their comments, made sure of it. When the administration changed, the institute itself was rewritten. In June 2025 the Commerce Secretary announced that the US AI Safety Institute would become the Center for AI Standards and Innovation, explaining that “censorship and regulations have been used under the guise of national security” and that “innovators will no longer be limited by these standards.” Roughly seventy-three NIST staff were laid off in the restructure. The body built to evaluate frontier models for safety was renamed for innovation in under eighteen months from its founding, and the word “safety” came out of the door.


The United Kingdom had the same architecture and a quieter failure.

At Bletchley Park in 2023, nine companies — AWS, Anthropic, Google, Google DeepMind, Inflection AI, Meta, Microsoft, Mistral, OpenAI — pledged to give the UK government early, priority access to their models for safety research. The pledge was a headline. The implementation was a patchwork. Anthropic provided a model for pre-deployment evaluation. Google DeepMind built an active partnership. And OpenAI — the company whose white paper had set the EU template three years earlier — had, by the account of trade reporting in 2026, still not actually had its technology trialed by the UK institute months after the “landmark agreement” was announced. There was no statute compelling pre-deployment access. The commitments were voluntary, the parliamentary committee noted the gap, and no legislation followed. The institute itself, meanwhile, was renamed: the AI Safety Institute became the AI Security Institute in early 2025, the same pivot from safety to security that the United States and France would make in the same window.

Three jurisdictions, three institutes founded to watch the frontier, three renamings within roughly a year that took the word “safety” out and put a softer word in its place. The watchdogs renamed themselves before anyone had to defund them.


Which returns the chapter to the man it is named for, and to the only figure in it that has gone up.

By the time the AI Act passed, Mistral AI was valued at roughly six billion euros, and Cédric O’s equity position in it was worth, by his own disclosure to the French Senate, approximately twenty-three million.

He was prohibited in writing from the lobbying that helped get the bill softened. He did the lobbying. The bill was softened. The equity is the measure of how much.

That is the whole of the accounting, and it balances. The named drafters did their work in public. The register recorded the spend in public. The white paper surfaced, eventually, in public. The carve-out sits in the published text. The executive orders were signed and rescinded and signed again in public. The institutes renamed themselves in public. Cédric O disclosed his stake to the Senate, in public.

Every line item is on file with some authority that exists to receive it. The HATVP received the conflict. The Senate received the equity. The Transparency Register received the meetings. NIST received the comments. The Federal Register received the orders. Each authority did exactly what it was built to do, which was to write the thing down.

None of them was built to do anything about it.

That is the discovery. Transparency is not the opposite of capture. Transparency is the form capture takes once it has stopped being afraid of the light. The record is complete, the record is public, the record is true. And the regulator still became the lobbyist became the equity holder, the bill still softened, the institutes still renamed themselves, the czar still held his portfolio, and the only number on any of these ledgers that moved in a clear direction was the one in Cédric O’s name.

The book had assumed, going in, that the problem was secrecy: that somewhere a door was closed, and that if it could be opened the capture would be visible and therefore stoppable. The door was open the whole time. Everyone walked through it in full view. The question the next chapters take up is what kind of faculty you would need, and whether anyone still has it, to look at a fully disclosed public record and recognize that it describes a crime that no one will ever be charged with.

You would need to be able to read all the filings at once. You would need to be the outsider who performs the cross-reference. And you would need to still believe, against the evidence of the open door, that performing it would change anything at all.

Get updates on the Evil Robots series

Newsletter essays on AI escape, deception, and the humans who built them.