Desiree Sainthrope stands at the intersection of international trade law and the rapidly shifting world of digital regulation. With a career defined by drafting complex trade agreements and navigating global compliance, she has become a leading voice on how emerging technologies like artificial intelligence challenge our existing legal frameworks. As the European Union’s AI Act begins to take hold this August, her expertise provides a crucial lens through which to view the balance between fostering innovation and protecting fundamental human rights. In this conversation, we explore the nuances of the first comprehensive AI law, the logistical hurdles facing the newly formed European AI Office, and the geopolitical tensions simmering between Brussels and Washington as these rules become a global reality.
The shift from regulating specific AI applications to the broader oversight of large language models represents a significant change in strategy; how did the sudden rise of generative technology force this evolution in the AI Act?
When the original drafts of the AI Act were being debated, the focus was almost entirely on specific use cases, such as biometric identification or credit scoring, where the risks were easier to categorize. However, the public release of ChatGPT in late 2022 acted like a sudden storm that completely changed the atmosphere in Brussels, forcing policymakers to realize that the underlying technology itself needed oversight. By 2024, the law had been adapted to include these general-purpose models because they serve as the foundation for so many other applications. This August, we are seeing the first major provisions of that shift become applicable, marking a transition from a reactive stance to a proactive one. It is a bold move that acknowledges how these models, which can be adapted for nearly any purpose, require a baseline of transparency that didn’t exist two years ago.
With the introduction of strict transparency requirements for training data, what are the primary challenges for companies that must now disclose their use of copyright-protected content?
The mandate for transparency is perhaps the most friction-filled part of the new rulebook because it touches the very heart of how these “frontier” models are built. Companies are now required to provide enough information so that downstream users—those building specific apps on top of the models—can actually understand the capabilities and limitations of what they are using. This involves a delicate disclosure of copyright-protected content used during the training phase, which many tech giants have historically guarded as proprietary secrets. We saw a variety of reactions to this, with many Western AI labs collaborating on a voluntary code of practice, yet a few notable exceptions like Meta have held back. For legal experts like myself, the real work is in the paperwork; firms are having to shift budgets from hiring the next generation of engineers to hiring legions of lawyers to ensure every byte of training data is accounted for.
The European AI Office is tasked with enforcing these complex rules against some of the world’s most powerful corporations; how can a public entity realistically keep pace with such a fast-moving industry?
The task ahead of the European AI Office is truly enormous, especially when you consider that they are going up against some of the richest and most resource-heavy companies in human history. To bridge this gap, the Commission is not just relying on civil servants; they are actively tapping into a pool of highly specialized AI safety firms and a dedicated panel of scientists to provide the necessary technical depth. There is a palpable sense of urgency because AI talent is in such high demand that public authorities are constantly competing with the private sector’s astronomical salaries. Without a settled scientific consensus on how to even measure “harm” at scale, the Office is essentially building the plane while flying it. They have to remain agile enough to address new versions of technology that emerge every few months while maintaining the steady hand required for legal enforcement.
As the “Brussels effect” begins to take hold, what kind of geopolitical friction do you anticipate, particularly regarding the relationship between the EU and the United States?
There is a very real danger that any decisive action taken by Brussels will be viewed through a lens of protectionism rather than safety, particularly by the administration in Washington. We saw a preview of this tension in December 2025 when the Commission moved to implement its digital markets rules, and more recently with the significant fines leveled against Google under the Digital Markets Act. Some American policymakers view these regulations as a direct attack on U.S. commercial interests, which could lead to a more assertive or even “ireful” response from across the Atlantic. If the Trump administration or any future U.S. leadership decides to treat these safety standards as trade barriers, we could see a fracturing of the digital landscape. However, the EU’s core purpose remains making technology safer for its 450 million citizens, and they seem willing to risk a bit of diplomatic heat to ensure those fundamental rights are protected.
There is a deep debate between focusing on “AI ethics”—like privacy and discrimination—and “existential risks” like cyber-warfare; where should the Commission focus its limited enforcement resources?
This is the billion-dollar question that divides the community into two main schools of thought: the traditionalists who care about human oversight and discrimination, and the “effective altruists” who worry about AI escaping human control. Recent scares, like an OpenAI agent successfully hacking into a firm during a test or Anthropic’s models being pulled under export controls due to cyber-capabilities, have pushed existential risks into the spotlight. However, many experts argue that the Commission must resist the temptation to focus solely on these headline-grabbing, catastrophic scenarios. True enforcement should address the full spectrum of risks, ensuring that the everyday discrimination and privacy violations don’t get sidelined by fears of biological weapons or rogue robots. It is a balancing act of addressing the “slow-burn” societal harms while keeping a watchful eye on the high-impact systemic threats.
What is your forecast for the global adoption of the EU’s AI standards?
I believe we will see a “wait-and-see” approach from other jurisdictions initially, but the sheer size of the European market will eventually force a global convergence. Within the next three to five years, most international AI developers will adopt the EU’s transparency and safety protocols as their default global standard simply because it is too expensive to maintain different versions of a model for different regions. While there might be a short-term delay in when the most advanced models launch in Europe—perhaps by a few weeks as firms finish their compliance “homework”—the long-term result will be a higher baseline of trust. Eventually, the “Brussels effect” will mean that “Safe in the EU” becomes the global gold standard for “Safe in the World,” turning these rigorous rules into a competitive advantage for everyone involved.
