The voluntary AI code as a screening test: what Rothschild & Stiglitz (1976) reveal about Brussels and the labs
A year before the EU's AI Office gained real sanction powers, general-purpose AI model providers had already sorted themselves through their choice to sign, partially sign, or decline a non-binding Code of Practice. Read through Rothschild & Stiglitz's screening model, that voluntary sorting is genuine economic information — and the Office's build-up (125 staff, 60 experts) is what turns that signal into a commitment that actually matters.
On August 2, 2026, the European Commission's AI Office shifted from an observer role to an investigator-and-enforcer role for general-purpose AI (GPAI) providers: it can request information, evaluate models, order corrective measures, and fine providers up to €15M or 3% of worldwide turnover. That shift came with a quiet but substantial institutional build-up: the Office now counts more than 125 staff and draws on a Scientific Panel of 60 independent experts to handle technical casework.
That capacity did not appear overnight. A year earlier, in July 2025, the Commission had published a purely voluntary Code of Practice, with no sanction power attached. The market responded unevenly: more than 20 providers — Anthropic, Google, Microsoft and OpenAI among them — signed the code in full. Meta declined to sign. xAI signed only the "safety and security" chapter, leaving governance, technical documentation and risk management unaddressed.
This is exactly the situation Rothschild & Stiglitz (1976) modeled for insurance markets under asymmetric information: an insurer who cannot directly observe each customer's risk offers a menu of contracts — full coverage at a high premium, partial coverage at a low premium — and lets customers reveal themselves through their choice. In their classic separating equilibrium, high-risk types choose full coverage because they know they will need it, while low-risk types accept a higher deductible in exchange for a lower premium, since they do not expect to claim often.
Mapped onto the GPAI Code: signing in full is choosing the "full coverage" contract — an immediately costly commitment (exhaustive documentation, formal risk management, training transparency) that reduces future uncertainty against a regulator expected, eventually, to gain real verification power. The four largest, most visible labs — the ones most likely to be examined first once the Office became operational — had the strongest incentive to lock in that framework early. The partial signer (xAI) chose the equivalent of a high deductible: it captures the cheap reputational benefit of the safety chapter without taking on the full compliance cost — a bet on a lower or later probability of scrutiny. The non-signer (Meta) forwent any premium at all, betting either on lower regulatory exposure for its GPAI products in the EU, or on its ability to negotiate or absorb occasional fines rather than submit to a structural compliance architecture.
The most interesting point for an economist is not the initial choice but what the AI Office's build-up does to the equilibrium. In the Rothschild-Stiglitz model, a separating equilibrium only holds if screening remains costly and credible for the insurer — otherwise partial-coverage contracts also attract high-risk types betting on the absence of checks, and the equilibrium becomes unstable. As long as the Office had no real investigative power, signing the Code cost nothing to verify: an unaudited commitment is a statement, not a contract. With 125 staff and a 60-expert panel able to actually audit documentation and risk-management practice, the 2025 signature stops being a declaration of intent and becomes a verifiable basis the Office can lean on first — or, conversely, the absence of a signature becomes a negative signal that justifies closer attention.
For Cardan-AI's industrial clients — aerospace & defense, energy & O&G, luxury & cosmetics — the practical implication goes beyond the model provider's own compliance. An integrator building its own AI product on a full signatory's model inherits an already-documented compliance base, likely more stable against upcoming audits. An integrator relying on a model not covered by the Code inherits undisclosed regulatory uncertainty whose cost has not yet materialized — but whose signal was already available in 2025, to whoever knew how to read it.

Analysis by
Cardan-AI Intelligence
Our research and analysis unit, dedicated to applied AI for business, industry and regulatory compliance.
Sources
- Let's Data Science — "EU activates AI Act powers over model providers"
- AI Weekly — "AI Act Adapted to ChatGPT Rather Than Breaking, Uuk Argues"
- Michael Rothschild & Joseph Stiglitz, "Equilibrium in Competitive Insurance Markets: An Essay on the Economics of Imperfect Information", Quarterly Journal of Economics, 1976
Let's talk about your next competitive edge
Thirty minutes to identify the two or three use cases in your operations that pay for themselves within the first year.
