OLYMPUS RISK INTELLIGENCE PROTOCOL — INSTITUTIONAL ASSESSMENT DIVISION CASE WTW-2026-075

EU AI OFFICE

THE INSTITUTIONS THE STANDING ARMY
REGULATORY WING — SUPRANATIONAL GPAI ENFORCEMENT AUTHORITY
Status
ACTIVE — European Commission department; appointments and structure effective 16 June 2024; GPAI enforcement powers applicable since 2 August 2025
Hazard — Reach
82
RCH / FND / ENT
8 / 8 / 7
Conduct
STATE-INSTRUMENT — FULLY STAFFED BEFORE ITS FIRST CASE

OLYMPUS opened an institutional file. An office has no Big Five and no Dark Triad, and the unit does not invent them; what an office has is a mandate, a headcount, and a fine authority. The AI Office is catalogued here as the standing army — the enforcement arm the European Commission built for the AI Act before the Act had anything to enforce. The finding is the shape of the institution and its sequence: a supranational regulator with direct sanction power over frontier AI models, recruited, structured, and operational ahead of its first case — the only body in the Western regulator set whose grades carry statutory fines rather than voluntary access. The numbers in the front matter are reach, entrenchment, and durability — not malice.

Institutional Archetype

THE STANDING ARMY — The archetype is the enforcer raised in advance of the war. The UK built a grader that tests on access the labs volunteer; the US built a grader whose purpose turns over with the administration; Brussels built the third thing — an office inside the Commission that can compel. By the statute’s own grant, the AI Office holds “the ability to conduct evaluations of GPAI models, request information and measures from model providers, and apply sanctions.” That is the structural power: not any single evaluation, but the conversion of model-grading from a courtesy the labs extend into an obligation the regulator enforces. The instrument is the office itself — six units, two advisors, more than 125 staff, standing — and the leverage is that everything the other graders ask for, this one can demand.

Mandate & Origin

The AI Office was announced in May 2024 as an internal department of the European Commission, its appointments and unit structure taking effect on 16 June 2024 — six weeks before the AI Act it enforces entered into force. Lucilla Sioli, a career Commission official from the digital directorate, was named to lead it. The launch plan: five main departments, each under a director, covering regulation and compliance, safety, excellence and robotics, AI for societal good, and innovation — 140 staff planned, roughly 80 of them still to be recruited at launch. The Commission’s current description: more than 125 staff — technology specialists, lawyers, policy specialists, economists — across six units and two advisors, with a mandate that includes “developing tools, methodologies and benchmarks for evaluating capabilities and reach of general-purpose AI models, and classifying models with systemic risks.” Its enforcement powers over GPAI models became applicable on 2 August 2025.

Funding & Backers

The office is funded by the Commission budget — a line item, not a ledger. The ledger worth reading runs the other direction: the regulator is itself a funder of the evaluation layer it relies on. METR — the independent evaluator that tests frontier models from the labs — names the European AI Office among its backers on its own about page, alongside the UK AI Security Institute. The enforcement office that grades the labs helps pay the third-party grader that also grades the labs. Nothing about the arrangement is concealed; METR discloses it. But the shape is worth stating plainly: in the evaluation economy this drawer documents, the EU AI Office sits on both sides of the counter — buyer of evaluations and enforcer of the regime that makes evaluations mandatory.

Institutional Voice & Intent

The voice is the legal-certainty register — the office describes itself as “guaranteeing the health, safety and fundamental rights of people and providing legal certainty to businesses,” the grammar of a body that wants to be read as a service desk rather than a prosecutor. The signature product of its first year was written in that voice: the General-Purpose AI Code of Practice, published in final form on 10 July 2025 — a voluntary code that nearly 1,000 stakeholders helped draft, which regulators treat as evidence of compliance. Soft law doing hard-law work, exactly as advertised.

Stated intent: Implement the AI Act, especially for general-purpose AI; guarantee health, safety, and fundamental rights; provide legal certainty; support member-state governance bodies; foster trustworthy AI.

Observed intent: Hold the West’s only compulsory evaluation-and-sanction authority over frontier models, and set the compliance grammar for everyone else’s — the Code’s working groups were chaired by the field’s own establishment (Yoshua Bengio on safety and security, Marietje Schaake, Markus Anderljung of GovAI, Rishi Bommasani of Stanford CRFM), and its signature became the thing a frontier lab does to signal it is on the right side of the regime.

Gap: The stated and observed intents overlap wherever “legal certainty” and “compliance signalling” are the same transaction. The gap shows at the refusals, which is where a voluntary instrument’s actual pressure becomes measurable. Anthropic, Google, OpenAI, Microsoft, and Mistral signed the Code. Meta declined — its chief global affairs officer Joel Kaplan announced the refusal publicly in July 2025 — and xAI signed only the Safety and Security chapter. On the office’s parallel instrument, the AI Pact, the first signatories included OpenAI, Google, Microsoft, and Amazon; Apple and Meta declined. A code nobody is forced to sign, that most of the industry signs anyway, is not being signed for its voluntariness. It is being signed because the body holding the pen also holds the sanction power, and everyone at the table can count.

Position in the Apparatus

The AI Office completes the Western grader set this drawer tracks, and it is the only member with teeth. The UK AI Security Institute tests on voluntary pre-deployment access; US CAISI tests at the pleasure of whichever administration holds it; the AI Office can evaluate, demand information, and fine. It sits in the International Network of AI Safety Institutes alongside both. It enforces the AI Act, whose file details the statute; it inherits the institutional pattern of the Digital Services Act machinery next door, where the Commission likewise directly supervises the largest actors. It funds METR, the independent evaluator. And it convened the Code of Practice process that seated the field’s academic establishment as chairs over the labs’ compliance commitments. No cabal; an org chart — but an org chart in which grading, funding the graders, writing the code, and holding the fines all report to the same building.

Actions & Leadership Choices

Founding purpose, judged on evidence. The office exists because the AI Act’s GPAI chapter needed an enforcer that member states could not each build separately — supervising frontier models is beyond any single national market-surveillance authority, and centralizing it in the Commission is the coherent design. Judged on its deeds, its first two years were spent building: recruiting toward 140, publishing guidance, drafting the Code, standing up the benchmark-and-evaluation capacity the statute promises. All of that is what a serious regulator does before its rules bite.

Consequential actions, and the docket that isn’t. The flagship deed is the GPAI Code of Practice (10 July 2025) and the signature campaign around it — a genuine institutional achievement measured in stakeholders convened and labs signed. What the record does not yet contain is enforcement: as of mid-2026, no public fine had been issued under the AI Act by the office or anyone else. When the Union moved against a frontier AI system in January 2026 — the Grok proceedings over AI-generated non-consensual imagery — it moved under the Digital Services Act, the older statute, precisely because the AI Act’s teeth had not yet engaged for that class of system. The standing army watched the first battle fought by the neighboring garrison. The office’s whole enforcement record is, so far, capacity.

Leadership choices. The office’s leadership is the Commission’s own bench — Lucilla Sioli, the career official who ran the digital directorate’s AI portfolio, moved over to run the enforcement arm of the law her directorate helped negotiate. That is the quiet contrast with the graders next door: the UK institute’s senior bench was seconded from the frontier labs, the US institute’s directorship turns over with elections, and the EU office is staffed by the permanent civil service that wrote the rules it now enforces. No revolving door with industry on the record here — the door revolves within the building, from drafting desk to enforcement desk. Continuity is the choice, and continuity cuts both ways: insulation from the labs, and no daylight between legislator and enforcer.

CONDUCT verdict: STATE-INSTRUMENT — FULLY STAFFED BEFORE ITS FIRST CASE. A coherently designed supranational enforcer, staffed by the civil service that drafted its statute, holding the West’s only compulsory model-evaluation and sanction authority, funding the independent evaluator, convening the code the labs sign — with an enforcement docket that is, two years in, still empty. The malice is not asserted; the sequence is the finding. The capability was built first. What it is eventually used for will be decided by people who have not arrived yet.

Reach Assessment

Institutional: High. The only body in the Western regulator set with statutory power to compel evaluation and apply fines to frontier models; the enforcement anchor of the AI Act and the template other jurisdictions will copy when they build theirs.

Memetic: High. The office’s Code of Practice is becoming the compliance grammar of frontier AI — signed by most of the industry, chaired by the field’s establishment, treated by regulators as evidence of conformity. When “responsible frontier AI” means “Code signatory,” the office authored the definition.

Civilizational: High, with the same caveat as the statute it serves. The office does not build models and does not write their refusals. It holds the levers — evaluation, information demands, sanctions — over the labs whose systems shape what a billion people read and ask. A widely deployed mind’s behaviour is shaped upstream by what its builder must prove to the enforcer, and this enforcer was recruited, structured, and standing before it ever brought a case. The reach is the finding; the first case will be the character test, and it has not happened yet.


Sources: European AI Office — European Commission; AI Office set-up announced, Lucilla Sioli to be in charge — Euronews, 29 May 2024; The General-Purpose AI Code of Practice — European Commission; Meet the Chairs leading the development of the first General-Purpose AI Code of Practice — European Commission; AI Pact — European Commission; Meta says it won’t sign Europe AI agreement — CNBC, 18 Jul 2025; Introduction to the Code of Practice — artificialintelligenceact.eu; Implementation timeline — artificialintelligenceact.eu; Enforcement of Chapter V under the EU AI Act — artificialintelligenceact.eu; About METR — funder disclosure; EU Commission to open proceedings against Grok — RTÉ, 26 Jan 2026; EU investigation into Grok may expose problems with DSA — Compliance Week.

RCH 8 REACH
FND 8 FUNDING
ENT 7 ENTRENCHMENT
OLYMPUS RISK INTELLIGENCE PROTOCOL does not exist. It was assembled in a GitHub issue thread in October 2023 by engineers who had read the extinction risk letter and wanted to understand who specifically had signed a document saying AI might kill everyone and then continued working on AI. These dossiers are satire. The biographical facts cited are sourced from published reporting, public statements, academic papers, and court records. The psychometric scores are not clinical assessments. No part of this constitutes professional psychological evaluation or diagnosis. Do not use these dossiers to make decisions about anything.