Skip to main content
How the EU Built a 60-Expert Panel to Govern GPAI ModelsEU AI Act & GPAI
5 min readFor AI Governance Leaders

How the EU Built a 60-Expert Panel to Govern GPAI Models

The EU AI Act's Scientific Panel of Independent Experts started on June 1, 2026, with 60 appointed members. This isn't just another advisory group. It's a governance body with enforcement powers: it can trigger systemic risk investigations, request documentation from model providers, and influence whether a General-Purpose AI Model is designated as high-risk under Article 52.

For governance leaders building internal AI oversight structures, the panel's design offers a blueprint for balancing technical depth with regulatory authority.

The Challenge

General-Purpose AI Models operate at a scale and speed that outpace traditional regulatory review. A model trained on 10^25 FLOPs (the threshold for presumed systemic risk under Article 51) can reach millions before regulators understand its failure modes. Market surveillance authorities in 27 member states can't individually develop the expertise to evaluate foundation models, assess emergent capabilities, or distinguish between ordinary product issues and Union-level systemic risks.

The AI Office needed a structure that could:

  • Maintain current technical knowledge across machine learning, socio-technical impacts, and adversarial risks
  • Act independently from commercial AI providers
  • Coordinate expertise across member states without creating a bureaucratic bottleneck
  • Exercise enforcement powers (qualified alerts, information requests) while remaining an advisory body

The Environment and Constraints

Article 68 of the EU AI Act established the panel's legal basis but left critical design questions to implementing regulations. The Commission had to balance competing requirements:

Geographic representation: At least one expert per EU member state and EFTA/EEA country, with a maximum of three per country and 80% from EU/EFTA/EEA nations. This created a floor of roughly 30 experts and a ceiling of 60.

Independence requirements: Experts cannot have conflicts of interest with AI systems or General-Purpose AI Model providers. In a field where most leading researchers have consulting relationships, equity positions, or employment history with major labs, this constraint significantly narrowed the candidate pool.

Multidisciplinary scope: The call for applications specified expertise areas including model evaluation, risk assessment, technical mitigations, and systemic risk analysis. No single expert profile could cover this range.

Operational tempo: The panel must respond to qualified alert triggers and information requests on timelines measured in weeks, not months. This ruled out structures that require full-panel consensus for routine decisions.

The Approach Taken

The Commission's implementing regulation (EU 2025/454) created a tiered operating model:

Full panel of up to 60 experts serving two-year renewable terms, ensuring continuity and allowing expertise to compound over cycles.

Rapporteur system for specific tasks, with compensation for experts taking lead roles on evaluations or alert development. This allows the panel to work in parallel on multiple investigations without requiring 60-person meetings.

One-third authorization threshold for information requests under Article 91(3). A rapporteur can trigger a formal documentation request from the AI Office with support from at least 20 panel members. This balances accessibility (you don't need full consensus) with legitimacy (you can't act unilaterally).

Simple majority for qualified alerts under Article 90. If the panel identifies a concrete, identifiable Union-level risk, a majority vote launches the Article 52 designation process, potentially subjecting the provider to Article 55 obligations: risk assessment and mitigation, serious-incident reporting, and cybersecurity measures.

Secretariat for administrative support, separating expert judgment from process management.

Public transparency with confidentiality protections: Expert declarations of interest, opinions, recommendations, and stakeholder hearing records are published. Confidential business information remains protected, but the panel's reasoning doesn't.

The call for applications closed September 14, 2025. Appointments followed on June 1, 2026, with the full member list published on the Commission's website.

Results and What's Measurable

The panel is now operational with 60 appointed experts representing the required geographic distribution and gender balance. The structure is in place; effectiveness will be measured by:

Alert responsiveness: How quickly can the panel move from initial concern to qualified alert? The rapporteur model should enable investigation in weeks, not quarters.

Information request utilization: Will the one-third threshold prove low enough that legitimate concerns get escalated, or will it create too many requests for the AI Office to process?

Cross-border coordination: Can a panel spanning 30+ countries develop shared evaluation methodologies and risk thresholds, or will national perspectives fragment the technical consensus?

The first qualified alert will be the real test. It will reveal whether the panel can translate technical findings into actionable regulatory triggers without either over-alerting (creating compliance noise) or under-alerting (missing genuine systemic risks).

What They'd Likely Do Differently

The two-year term creates a knowledge continuity problem. Just as experts develop institutional knowledge of the AI Office's processes and build relationships with market surveillance authorities, their terms expire. Staggered appointments would preserve continuity.

The 80% EU/EFTA/EEA requirement may limit access to expertise concentrated in other jurisdictions, particularly for evaluating models trained outside Europe. A consultative mechanism for non-member technical specialists could supplement the core panel without compromising independence.

The simple majority threshold for qualified alerts is untested. If early alerts prove too sensitive (triggering Article 52 processes for edge cases), expect pressure to raise the bar. If they're too conservative, member states may develop parallel alert mechanisms.

Takeaways for Your Team

If you're building an internal AI governance structure, the Scientific Panel's design offers three lessons:

Separate expertise from execution. The panel advises; the AI Office enforces. Your model risk committee shouldn't also own the validation queue. Independence requires structural separation.

Build decision tiers. Not every question needs full committee review. Rapporteurs, working groups, and threshold voting (one-third for information requests, majority for alerts) let you scale expertise without creating bottlenecks.

Make independence verifiable. Public declarations of interest and conflict management systems aren't just compliance theater. They're what allow the panel's technical judgments to carry regulatory weight. Your governance body's credibility depends on visible independence from the teams it oversees.

The panel's real test starts now: can 60 experts, operating under public transparency and strict independence requirements, keep pace with General-Purpose AI Model development while providing enforcement support across 27 member states? Your internal governance structure faces the same tension at a smaller scale.

You Might Also Like