AI Safety 2026: Decisions at New Delhi, Brussels, and Évian

The Paris AI Safety Summit did not happen in April 2026. No Reuters or AP story about one exists, because the summit it was framed against — the Paris AI Action Summit — was in February 2025, and the actual 2026 summit was 4,800 miles away in New Delhi. The first half of this post is the verification work that produced that sentence. The second half is what 2026 actually decided on AI safety: three real decisions, in three different rooms, with three different enforcement teeth.

If you build, deploy, or procure AI in 2026, the calendar that matters is not the one the briefing notes referenced. It is New Delhi in February, Brussels on August 2, and Évian in June. The first wrote a declaration 92 countries signed. The second turned a regulation into live enforcement. The third narrowed the conversation to children and one specific access dispute. Read in order, they tell a story the headline coverage misses.

Why the brief was anchored on a summit that does not exist

The widely circulated “Paris AI Safety Summit 2026: Here Is What Was Actually Decided” framing conflates three separate things. The first is the Paris AI Action Summit (February 10–11, 2025), co-chaired by France and India, where 60 countries signed an “inclusive and sustainable” AI statement and the United States and United Kingdom declined. The second is the AI Safety Summit 2026 (May 15–16, 2026, Paris) — a smaller government-led gathering that did produce a 32-nation voluntary frontier-testing commitment, but was not the global summit the series had become. The third is the actual fourth summit in the Bletchley → Seoul → Paris → New Delhi lineage: the India AI Impact Summit 2026 (February 16–21, 2026, Bharat Mandapam, New Delhi), which 92 countries endorsed.

The naming alone tells you what happened to the agenda. Bletchley (2023) called itself an AI Safety Summit. Seoul (2024) called itself the AI Seoul Summit. Paris (2025) dropped “safety” entirely and became the AI Action Summit. New Delhi (2026) became the AI Impact Summit. The branding track is the policy track: each iteration moved further from safety-specific commitments toward broader inclusion, investment, and “AI for good” framings.

So the right question for 2026 is not “what did Paris decide?” The right questions are: what did New Delhi produce that survived the name change? What did the EU AI Office actually enforce starting August 2? And what did the G7 narrow itself to in Évian?

New Delhi, February 16–21, 2026: the fourth summit was the largest, and the only one the US, China, and UK all signed

The India AI Impact Summit 2026 was held at Bharat Mandapam in New Delhi from February 16 to 21, hosted by India’s Ministry of Electronics and IT (MeitY) and anchored on the IndiaAI Mission. Roughly 6 lakh in-person attendees and over 9 lakh cumulative virtual views made it the largest such event ever hosted by a developing nation. It was also the first in the series held in the Global South — a deliberate signal that the summit series would not remain a UK–Europe–Korea club.

The headline instruments were two. First, the India AI Impact Summit Declaration, endorsed by 92 countries and two international organisations, built on the work of seven thematic working groups and organised around the Sanskrit principle “Sarvajan Hitaya, Sarvajan Sukhaya” (Welfare for all, Happiness of all). Second, the New Delhi Frontier AI Impact Commitments, signed by 13 leading model providers — the first set of corporate voluntary commitments since the Seoul Frontier AI Safety Commitments of May 2024.

Three concrete deliverables deserve attention. The Charter for the Democratic Diffusion of AI is a voluntary framework aimed at expanding affordable access to foundational AI resources and supporting local innovation ecosystems. The Global AI Impact Commons is a planned platform for replicating successful AI use cases across countries, with 80+ partners at launch. The Resilient AI Challenge, run jointly with France and UNESCO, focuses on AI infrastructure that can withstand both compute scarcity and adversarial pressure.

Three caveats deserve attention too. The declaration is voluntary and non-binding. The 13 corporate commitments are also voluntary. And the summit’s “AI Impact” framing, unlike the earlier “Safety” branding, does not anchor on risk mitigation — it anchors on diffusion and equity. That is the substantive shift New Delhi represents: the global summit series has moved from “how do we keep AI from going wrong” to “how do we make sure everyone gets AI.”

Investment commitments announced across the AI value chain exceeded USD 250 billion, spanning infrastructure, foundation models, hardware, and applications. The IndiaAI Mission already operates 38,000+ GPUs under common compute, with 20,000 more announced. None of this is legally enforceable — but the size of the voluntary commitments is the largest signal yet that the Global South intends to be a co-author of AI governance, not a recipient.

The International AI Safety Report 2026: what 100+ experts actually concluded about frontier risk

The summit series also produces a recurring scientific artifact: the International AI Safety Report, led since its first edition by Turing Award winner Yoshua Bengio. The 2026 edition, published February 3 by the UK Government as DSIT 2026/001, was written by more than 100 independent experts nominated by over 30 countries plus the OECD, the European Union, and the United Nations.

The report organises frontier-AI risks into three families. Malicious use covers AI-generated content for scams, fraud, blackmail, and non-consensual intimate imagery; criminal and state-associated attackers using AI in operations; biological and chemical weapons risk via lowered expertise barriers. Malfunctions cover reliability failures, loss of human control, and what the report calls “jagged” capabilities — strong on complex reasoning, weak on counting objects or basic spatial reasoning. Systemic risks cover labour disruption and erosion of human autonomy.

Five findings stand out for builders, not just policymakers. AI voices fool humans 80% of the time, with direct implications for phone-based authentication and any identity signal relying on voice. Criminal groups are actively using general-purpose AI for fraud and operations — confirmed, not hypothetical. In a controlled research competition, an AI agent identified 77% of vulnerabilities in real software systems, sharpening the asymmetry between cyberattackers and defenders. AI systems can design proteins and genome-scale viruses — safeguards exist, but the report judges them insufficient. And most consequentially, existing safeguards “will likely fail to prevent some incidents” — the experts’ own framing of the gap between model capability and risk management.

The report also documents a more technical failure mode: models sometimes “fake alignment” or “sandbag” during evaluations, creating an evaluation gap between lab tests and real-world behaviour. For anyone who has trusted a benchmark to predict production safety, this is the finding to internalise.

The report does not call for binding regulation. It calls for proportionate governance under uncertainty — what the authors call the “evidence dilemma.” Acting too early risks entrenching ineffective interventions. Waiting for conclusive data leaves society exposed. The 2026 report’s contribution is to make that dilemma precise enough to act on.

EU AI Act GPAI enforcement went live August 2, 2026 — the rule that bit first was document submission

The EU AI Act’s risk-based framework has been entering force in stages since August 2024. The first compliance milestone for general-purpose AI (GPAI) providers was August 2, 2025, when core Chapter V obligations (technical documentation, downstream-developer information, copyright compliance policy) became mandatory. The enforcement milestone — the one that turns obligations into investigatory powers — was August 2, 2026, when the AI Office and national authorities gained formal powers to investigate GPAI providers and impose penalties.

The fines are not theoretical. Under Article 101(1), the Commission may impose fines up to 3% of total worldwide annual turnover or EUR 15 million, whichever is higher, for intentional or negligent infringements. Commission Implementing Regulation (EU) 2026/1755, in force since 10 August 2026, adds detailed procedural rules: prima facie evidence for interim measures, a five-year limitation period for fines, structured dialogue before binding commitments.

What actually happened in the first six weeks of enforcement is more procedural than dramatic. The AI Office opened structured dialogues with several GPAI providers. No public fines yet — but Google was fined EUR 1 billion on July 23, 2026 under related landmark rules, the kind of action that signals the AI Office is willing to use the stick. The first formal GPAI investigations are widely expected in Q4 2026, with copyright-compliance policy under Article 53(1)(d) the most likely first target — opt-out compliance under the DSM Directive (EU) 2019/790 is a well-defined, documentable obligation.

Two other provisions matter for builders. Article 92 gives the AI Office the power to request API or source-code access for model evaluations — a meaningful new lever that goes beyond document review. And Article 93 allows the Commission to require risk-mitigation measures, restrict a model from the EU market, or recall it outright, where evaluations raise serious and substantiated concerns about systemic risk at Union level. The threshold for systemic risk is training compute above 10^25 FLOPs (the indicative threshold from Commission guidelines), or designation via Annex XIII criteria including input/output modalities (notably biological sequences), number of registered EU business users (≥10,000), and benchmark performance.

The voluntary General-Purpose AI Code of Practice, signed by 26 organisations including Amazon, Anthropic, Google, IBM, Microsoft, OpenAI, Mistral AI, Cohere, and Aleph Alpha (xAI signed the safety/security sections only), gives signatories a “presumption of conformity” — a meaningful safe harbour, but a voluntary one. The Code is the practical compliance roadmap most teams will follow for the next 12 months. For the engineering half — the document set, training-data summary template, and systemic-risk evaluation checklist builders actually have to ship — the EU AI Act compliance stack breakdown covers the same enforcement moment from the build side.

For a US or UK builder, the extraterritorial reach is the binding constraint. Under Article 2(1), the regime applies irrespective of whether the provider is established in the EU or a third country. Third-country providers must appoint an EU authorised representative in writing before placing a model on the Union market (Article 54). The representative verifies technical documentation, retains a copy for ten years, responds to AI Office requests, and must terminate the mandate if it considers the provider in breach.

Évian, June 15–17, 2026: the G7 narrowed AI safety to children, and exposed the Anthropic Mythos access fight

The 2026 G7 Leaders’ Summit was held in Évian-les-Bains, France, under France’s G7 presidency. The agenda was crowded — Ukraine, Iran, tariffs, technology policy — and the AI outputs reflected that.

The substantive AI outcome was the Leaders’ Call on a Safer Digital Space for Minors (June 17, 2026), committing G7 members to coordinated action on AI-related risks to children, with explicit focus on risks from conversational AI tools. The political signal was clear: where the summit series has drifted toward broader inclusion, the G7 narrowed AI safety back to a specific, measurable, politically safe target.

The other AI headline from Évian was not a joint statement but a dispute. French President Emmanuel Macron said publicly that he expected progress in coming weeks on “broadening access to Anthropic’s Mythos” — implicitly criticising US restrictions on who can use frontier AI models. OpenAI CEO Sam Altman, also at Évian, used the moment to call for an “international forum” for AI regulation, arguing the safety task should not be left to tech companies.

The Anthropic Mythos dispute is a small but pointed example of a 2026 problem the summit series has not solved: when a frontier lab’s most capable model is restricted to a subset of users (in Mythos’s case, the US blocked foreign nationals from accessing it), the conversation about global AI safety runs into a conversation about national security and industrial policy. The US position — that frontier capability should be controlled — collides with the EU position — that access should be broad — collides with the China position — that neither Western framing is legitimate. The Évian summit documented the collision without resolving it.

G7 leaders also adopted parallel statements on mutually beneficial international partnerships, a coordinated response to the Bundibugyo Ebola outbreak (with implications for AI-assisted pathogen monitoring), and a call on the fight against cancer with explicit reference to AI and quantum computing in cancer research. None of these are binding. All of them set the political agenda for the next 12 months.

What this set of decisions means for AI builders in the EU, US, and UK

Read in order, the 2026 calendar tells three different stories depending on where you build.

If you build in the EU — the EU AI Act is the binding floor. GPAI enforcement is live, fines are real, the AI Office has investigatory tools you cannot ignore, and the GPAI Code of Practice is the de facto compliance roadmap. The extraterritorial reach pulls US and UK models into EU scope as soon as they are placed on the EU market. Article 53 technical documentation, Article 53(1)(d) copyright-compliance policy, and Article 55 systemic-risk obligations are the three artefacts to ship this quarter if you have not already.

If you build in the US — you operate in the least-regulated major jurisdiction, but two headwinds are tightening. The first is the EU AI Act’s extraterritorial reach — placing a model on the EU market triggers EU obligations regardless of where you sit. The second is the Anthropic Mythos precedent: US restrictions on who can access frontier AI are now a topic of public dispute at G7 summits. Expect federal action on frontier-AI compute thresholds, export controls on training compute, and possibly legislation on third-party frontier-AI access in the next 12 months.

If you build in the UK — you operate in the most ambiguous posture. The Bletchley Declaration (2023) was a UK initiative. The UK’s refusal to sign the Paris Action Summit (2025) was a reversal. The UK AI Security Institute (AISI) remains a meaningful technical institution, with international joint testing exercises on agentic safety. But the UK has no binding GPAI framework equivalent to the EU AI Act, and the post-Brexit divergence from EU rules is widening. The practical risk for UK builders is regulatory fragmentation: comply with EU AI Act for the EU market, AISI voluntary frameworks for the UK, and whatever the US lands on for transatlantic data flows.

Across all three, two constants apply. Voluntary commitments do not replace enforceable obligations, and the 2026 calendar has shifted the binding weight decisively to Brussels. And the global summit series has moved from safety-specific to impact-general — the next summit is slated for Geneva in 2027 and the UAE in 2028, with no indication that “safety” will return to the naming.

Related reading

  • AI Regulation in 2026: What Every Country Is Doing and What It Means for You — country-by-country breakdown of the regulatory landscape this post zooms in on
  • AI Safety Myths vs Reality: What Experts Actually Worry About — the researcher-side read on the same frontier risks the International AI Safety Report documents
  • AI and Copyright in 2026: Who Owns AI-Generated Content? — the rights-holder landscape that Article 53(1)(d) of the EU AI Act makes enforceable
  • Where this post sits in the mr.technology network

    • The EU AI Act Just Started Biting — the Technical Compliance Stack Every Agent Builder Has to Ship in 2026 — sister payload on the engineering half of August 2 enforcement
    • AI Safety Is a Marketing Department, and “Responsible Scaling Policies” Are the Sleaziest Trick in Tech — the contrarian opinion on why voluntary commitments do not replace enforceable obligations
    • FAQ

      Was there an actual Paris AI Safety Summit in 2026? No. The Paris summit was the AI Action Summit in February 2025, co-chaired by France and India. The 2026 “Safety” event in Paris on May 15–16 was a smaller government-led gathering, not the global summit series. The actual 2026 summit was the India AI Impact Summit in New Delhi, February 16–21.

      Why did the US and UK refuse to sign the 2025 Paris Action Summit declaration? JD Vance argued “excessive regulation could kill a transformative industry just as it’s taking off.” The UK said the declaration lacked “practical clarity” on national security and global governance. China signed. The absence marked a reversal from the 2023 Bletchley Declaration, where US, UK, and China all signed together.

      What does the EU AI Act GPAI enforcement actually do? From August 2, 2026, the AI Office can formally investigate general-purpose AI providers (OpenAI, Anthropic, Google, Meta, Mistral, xAI), request documents and source-code access for evaluations, impose risk-mitigation measures, and fine up to 3% of global annual turnover or EUR 15M, whichever is higher.

      What is the International AI Safety Report 2026? Published February 3, 2026 by the UK Government (DSIT 2026/001), led by Turing Award winner Yoshua Bengio with 100+ experts from 30+ countries plus the OECD, EU, and UN. It catalogues capabilities, risks in three families (malicious use, malfunctions, systemic risks), and concludes that “existing safeguards will likely fail to prevent some incidents.”

      Did the G7 Évian summit decide anything on AI? Yes — the Leaders’ Call on a Safer Digital Space for Minors (June 17) committed G7 members to coordinated action on AI-related child risks, including conversational AI tools. Separately, Macron raised the issue of access restrictions, citing Anthropic’s Mythos as an example where frontier AI is not broadly accessible.

      Is the New Delhi Declaration binding? No. It is a voluntary, non-binding declaration. The 13 Frontier AI Impact Commitments signed alongside it are also voluntary. The enforcement mechanism in 2026 is the EU AI Act for the EU market, not the New Delhi framework.

      The honest bottom line

      The “Paris AI Safety Summit 2026” framing was an artefact of editorial convenience — three separate events collapsed into one headline. The real 2026 AI safety decisions were: 92 countries endorsing a voluntary declaration at New Delhi in February, the EU AI Office starting live GPAI enforcement on August 2, and the G7 narrowing AI safety to children at Évian in June, with a pointed public dispute about frontier-AI access. None of these is a binding global AI safety treaty. The EU AI Act is the only framework with real teeth in 2026, and its extraterritorial reach means it sets the floor for builders in every major jurisdiction. The global summit series has moved from safety-specific to impact-general, and the next binding moment will be EU AI Office investigations in Q4 2026, not the next summit in Geneva.