EU AI Act position

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Current view on the EU AI Act, its enforcement trajectory, its compliance implications, and where it sits in the global AI governance landscape. Dated, revisable, diff-tracked.

State of the view as of 2026-05-12

What the EU AI Act does well

  • First comprehensive AI regulation. Sets a procedural baseline for the field. Other jurisdictions are watching, adapting, or building on.
  • Risk-tiered approach. Most AI systems escape heavy regulation. Heavy obligations focus on high-risk categories where the regulatory case is strongest.
  • Provider / deployer distinction. Recognizes that responsibility is shared across the AI value chain.
  • GPAI tier addresses foundation-model concerns. Distinct treatment for general-purpose models reflects the asymmetric capability and impact concentration.
  • Harmonized standards path. Once harmonized standards (especially ISO 42001) are formally adopted, compliance has a defined safe harbor.
  • Brussels effect potential. EU regulations historically shape global practice (GDPR precedent). AI Act likely to influence non-EU jurisdictions and global AI vendor practices.
  • Penalties have teeth. Up to €35M or 7% global turnover gets attention.
  • Transparency obligations for limited-risk. AI-generated content labeling, chatbot disclosure: light obligations broadly applicable, low compliance cost.
  • AI Office as central coordinator. EU-level body for consistency across Member States.

What the EU AI Act does poorly

  • Definitional ambiguity. What counts as an "AI system" under Article 3 was contested through drafting and remains imperfect. Recitals help; edge cases (rule-based systems, simple statistical models) face uncertainty.
  • High-risk classification complexity. Annex III categories + Annex I product references + carve-outs + Article 6(3) exemptions for systems "intended to perform narrow procedural task" or "not posing significant risk" create classification work that is itself non-trivial.
  • GPAI threshold methodology. Training-compute threshold (10^25 FLOP currently) is rough proxy. Capability-based assessment more meaningful but more contested. Threshold will likely be revised.
  • Implementation guidance lag. AI Act passed mid-2024; implementation guidance from Commission, AI Office, national authorities is rolling out through 2025-2026. Providers and deployers face uncertainty during ramp-up.
  • Harmonized standards not yet harmonized. Until standards-based safe harbor is operational, compliance assessment is harder.
  • Conformity assessment capacity. Notified Bodies for high-risk third-party assessment need to be designated and resourced. Capacity question for 2026-2027.
  • Sector-specific tailoring uneven. Some sectors (medical devices, automotive) have established conformity assessment frameworks the AI Act folds into; others face from-scratch implementation.
  • Innovation impact contested. Industry critics argue compliance cost suppresses EU AI competitiveness; regulators argue trust enables adoption. Real-world data on innovation impact will emerge through 2026-2028.
  • SME / startup support uneven. Regulatory sandboxes provided; access and operational depth varies by Member State.
  • Extraterritorial reach is broad. Non-EU providers whose AI outputs are used in EU are in scope. Enforcement against non-EU entities is procedurally complex.

Where the evidence currently sits

  • Prohibited practices ban in effect since 2 February 2025. Limited enforcement activity visible publicly so far; some clarifications via Commission guidance.
  • GPAI Code of Practice developed through 2024-2025 stakeholder process; published mid-2025. Voluntary; signing the Code helps with compliance.
  • GPAI obligations applicable since 2 August 2025. Compliance activity by major model providers (Anthropic, OpenAI, Google, Meta, Mistral, Cohere, others) visible publicly.
  • National competent authorities designated by Member States by mid-2025 (some lagging). DE designated multiple authorities reflecting federal structure.
  • AI Office operational since late 2024.
  • Harmonized standards process ongoing through CEN-CENELEC JTC 21; ISO 42001 harmonization in progress.
  • High-risk obligations applicability approaching for August 2026. Major implementation activity visible for in-scope systems.
  • First enforcement actions plausibly visible 2026-2027 as obligations take effect and authorities resource enforcement.
  • Global influence: UK / Singapore / Canada / Brazil / Japan AI strategy publications reference the AI Act explicitly. Some non-EU jurisdictions (states / provinces) considering AI Act-influenced legislation.

Personal calibration

  • Working assumption for AI-feature engagement work touching EU: AI Act applicability is real and compliance evidence is increasingly expected. Don't wait until enforcement to start mapping.
  • Working assumption for AI system classification: classification (prohibited / high-risk / limited-risk / minimal-risk / GPAI) is the foundational question. Get classification clear before deeper compliance work.
  • Working assumption for GPAI relationships: model provider AI Act compliance posture is a vendor due-diligence axis. Track per provider.
  • Working assumption for transparency obligations: chatbot disclosure, deepfake labeling, AI-content labeling apply to limited-risk systems broadly. Low cost; build into product defaults.
  • Working assumption for high-risk: if a system might be high-risk, get clarity early. The obligations are substantial and time-to-comply is significant.
  • Working assumption for own work: AI Act fluency increasingly expected for AI / SRE work. Read the operative articles and recitals; understand the enforcement trajectory; bridge to implementation frameworks.

What would shift this view

  • First substantial enforcement actions (plausibly 2026-2027) — will clarify interpretive ambiguities and signal enforcement priorities.
  • ISO 42001 harmonization completion — will provide formal safe harbor and clarify compliance path.
  • Article 6(3) clarification — the high-risk exemption for "narrow procedural" or "not significant risk" systems is currently underspecified. Commission guidance expected.
  • GPAI threshold revision — 10^25 FLOP threshold is provisional. Revision likely as model capabilities outpace compute-only measurement.
  • Notified Body capacity emergence — sufficient third-party conformity assessment capacity is foundational for high-risk obligation enforcement.
  • Brussels effect data — clear evidence of non-EU jurisdiction adoption of AI Act-aligned provisions would reinforce the regulation's global weight.
  • AI Act review (scheduled 2028 and periodically) — Commission review may produce amendments.

See also