What the programme reveals
The summit ran for the tenth time, and the organiser had announced more than 10,000 visitors and 300 speakers. Before the trip I counted words in the programme preview of 2 July. Across thirteen pages, “agent” appears 37 times, “sovereign” 21 times, “trust” 16 times, “governance” 15 times, “risk” and “safety” ten times each and “regulation” three times. The count says nothing about the quality of the talks, but it shows that the industry wanted to discuss agents first and control right after.
The main stage opened with a panel on power, control and responsibility. The afternoon brought a panel on the safety of AI systems, for which the programme announced Zico Kolter (board of OpenAI, Carnegie Mellon) and Alice Xiang (Sony), and day one closed with a conversation on building safe systems in an unsafe environment. Alongside ran a dedicated forum on sovereign AI, which brought together government representatives and infrastructure providers and asked whether Europe has to detach itself from Big Tech.
Three threads ran through it
Safety is treated as an engineering task. Those who spoke about safety spoke about attacks on models, observability in operation and safeguards that can be tested. One panel description called responsibility an engineering constraint, and that is how it was handled.
Sovereignty means compute, energy and procurement. The debate was less about the models than about what they run on. Chips, data centres, power supply and the question of what the public sector buys dominated the sovereignty forum.
Regulation addresses the providers. Since 2 August 2026 the European Commission can enforce the obligations for providers of general-purpose AI models. It may request documentation, evaluate models itself, demand corrective measures and impose fines of up to 15 million euros or three per cent of worldwide annual turnover. I have not found a report of any opened proceedings to date. The Digital Omnibus, by contrast, postponed the obligations for high-risk systems to December 2027 or August 2028, depending on the category.
Supervision therefore now covers the part of the AI Act that concerns a handful of large model providers, while the part that reaches operators inside companies still has a grace period. The United States sets the same emphasis: California’s SB 53 covers developers only above a training effort of 1026 operations and ties the stricter duties to more than 500 million dollars in annual revenue. Whoever talks about regulation is therefore talking, on both sides of the Atlantic, about a small number of very large companies.
Who spoke where
The preview names just under 70 speakers. I sorted them by organisation; the assignment is mine and debatable in borderline cases.
| Background | Speakers |
|---|---|
| Providers of models, chips and AI technology | about 28 |
| Companies that use AI | about 22 |
| Research, civil society, culture | about 14 |
| Governments and authorities | 5 |
So the operators were not missing. “Adopt AI” gave them a stage of their own that covered adoption, scaling and customer service. The preview, by contrast, filled the sessions on safety and control on the main stage and the sovereignty forum with providers, researchers and supervisors. I did not find a session in the preview that brings the two together and asks what safety and regulation mean for whoever builds a model into a business process.
No provider’s safety framework answers whether an assistant’s reply rests on the right document, whether an agent was allowed to trigger a booking, or whether a result can still be traced after six months.
The grace period until December 2027 changes nothing about that. It moves a deadline, and whoever waits until then builds systems that can hardly be made verifiable afterwards. The operator decides those questions, with the means that were demanded on stage for the large systems: criteria fixed in advance, tests before acceptance and a log that reproduces the run. That is why we put a check between model and result in each of our systems. We describe what a log looks like that stands up to Article 12 of the AI Act in a separate article, and how to agree acceptance criteria for a non-deterministic system in another.
The gap in the programme
Almost everything said about risk and regulation assumed a provider who controls its model, that is, who runs it behind an interface, maintains safety filters and can be written to by an authority. I noticed that only on the second day. The assumption does not hold for open models, whose weights anyone can download and change, and they were hardly discussed. Yet a model like Qwen3.8-27B runs on a single graphics card today. The second text on this conference explains why I consider this the most important omission.
What this text does not do
This text rests on my visit and on the programme preview from July. I did not see every stage, and the final programme may have differed from the preview. I therefore do not report statements by individual speakers; the names and topics mentioned come from the preview.
Sources
- World Summit AI 2026, organiser’s programme preview (PDF, as of 2 July 2026). The organiser’s website now shows the 2027 edition; the preview can no longer be retrieved there. worldsummit.ai
- Help Net Security, “EU begins enforcing AI Act, putting AI models under the microscope”, 4 August 2026, helpnetsecurity.com
- Future of Privacy Forum, “California’s SB 53: The First Frontier AI Law, Explained”, fpf.org
- European Commission, questions and answers on the guidelines for providers of general-purpose AI models, digital-strategy.ec.europa.eu