The first standard that makes AI red teaming verifiable is Korean: Europe regulates by risk but evaluates on its word.
Seoul has just published the first official standard which says how an AI red teaming must be conducted, by whom, and with what traces. In Europe, the evaluation of the most powerful models still relies on the self-attestation of those it is supposed to control. This contrast draws the real front line of AI governance: not who has the biggest regulations, but who owns the machinery of proof.
What Seoul just published
In July, the Korean Ministry of Science and ICT and cybersecurity agency KISA released two documents: an AI security threat response manual and an AI security red teaming guide. These are not ambiance recommendations. The guide describes the expected composition of test teams (security experts, but also AI engineers, lawyers and specialists in the business field), the accepted approaches (black box, gray box, white box depending on the risk), a taxonomy of eight categories of threats, from prompt injection to hallucinations, five levels of severity based on the real impact, and a cardinal principle: red teaming does not stop at production, it repeats itself.
In other words, a Korean company which claims “we have tested our AI” can now be confronted with an official reference system which makes it possible to verify what this phrase covers. These guides prepare for the entry into force of the Korean framework law on AI, whose administrative sanctions become possible at the beginning of 2027, at the end of the grace period. A factual line, and let’s move on: the important thing is not the sanction, it’s the frame of reference.
Europe has the regulations, not the infrastructure of proof
The AI Act requires suppliers of systemic risk models to conduct adverse tests. But the way they are conducted is governed by a Code of Good Practice to which suppliers voluntarily adhere, and which these same suppliers helped to write. Who makes up the test team, using what method, with what access to the model, what enforceable documentation? On each of these questions, the evaluated entity decides for itself. The Commission gains enforcement powers over general-purpose models on August 2. She will be able to demand accountability; it does not yet have a public standard saying what red teaming worthy of the name should look like.
It is a choice of regulatory philosophy, and it must be named: Europe wrote the law of evidence before having built the workshop that manufactures it. A regulation without an enforceable evaluation framework produces certificates, not proof.
The control machinery must be public
It will be objected to me that the ecosystem will take care of it: audit firms, red teaming providers, certifiers. Very good, but the question remains: who sets the standard against which these actors measure themselves? If the answer is “the model suppliers themselves”, then the evaluation will remain a service purchased by the controlled, framed by the controlled, published when it suits them. The Korean lesson can be summed up in one sentence: it is the public authorities which wrote the reference system, and this is what makes it enforceable against everyone. European sovereignty in matters of AI will not only be played out on chips or models, but on the ownership of this control machinery: evaluation benchmarks, methods of access to models, public testing infrastructure.
What businesses can demand without waiting for Brussels
The good news is that a general management, a DPO or a CISO does not need to wait for a European guide to import this logic into their contracts. Three requirements are enough to change the nature of the relationship with an AI supplier: the composition and independence of the team which tested the system, the method and scope of the test (what did it cover, under what conditions of access to the model), and the documentation provided, dated and replayable. These are exactly the elements that an AI management system of the ISO 42001 type allows you to organize on the client side: not believing the certificate, but keeping a record of what it proves and what it does not prove.
The first official standard in the world that makes red teaming auditable has just been published, and it is not European. The useful question is not to be sorry, but to decide who, in Europe, will write ours: the public authorities, or the entities that need to be controlled.