Current view on the EU AI Act, its enforcement trajectory, its compliance implications, and where it sits in the global AI governance landscape. Dated, revisable, diff-tracked.
State of the view as of 2026-05-12
What the EU AI Act does well
- First comprehensive AI regulation. Sets a procedural baseline for the field. Other jurisdictions are watching, adapting, or building on.
- Risk-tiered approach. Most AI systems escape heavy regulation. Heavy obligations focus on high-risk categories where the regulatory case is strongest.
- Provider / deployer distinction. Recognizes that responsibility is shared across the AI value chain.
- GPAI tier addresses foundation-model concerns. Distinct treatment for general-purpose models reflects the asymmetric capability and impact concentration.
- Harmonized standards path. Once harmonized standards (especially ISO 42001) are formally adopted, compliance has a defined safe harbor.
- Brussels effect potential. EU regulations historically shape global practice (GDPR precedent). AI Act likely to influence non-EU jurisdictions and global AI vendor practices.
- Penalties have teeth. Up to €35M or 7% global turnover gets attention.
- Transparency obligations for limited-risk. AI-generated content labeling, chatbot disclosure: light obligations broadly applicable, low compliance cost.
- AI Office as central coordinator. EU-level body for consistency across Member States.
What the EU AI Act does poorly
- Definitional ambiguity. What counts as an "AI system" under Article 3 was contested through drafting and remains imperfect. Recitals help; edge cases (rule-based systems, simple statistical models) face uncertainty.
- High-risk classification complexity. Annex III categories + Annex I product references + carve-outs + Article 6(3) exemptions for systems "intended to perform narrow procedural task" or "not posing significant risk" create classification work that is itself non-trivial.
- GPAI threshold methodology. Training-compute threshold (10^25 FLOP currently) is rough proxy. Capability-based assessment more meaningful but more contested. Threshold will likely be revised.
- Implementation guidance lag. AI Act passed mid-2024; implementation guidance from Commission, AI Office, national authorities is rolling out through 2025-2026. Providers and deployers face uncertainty during ramp-up.
- Harmonized standards not yet harmonized. Until standards-based safe harbor is operational, compliance assessment is harder.
- Conformity assessment capacity. Notified Bodies for high-risk third-party assessment need to be designated and resourced. Capacity question for 2026-2027.
- Sector-specific tailoring uneven. Some sectors (medical devices, automotive) have established conformity assessment frameworks the AI Act folds into; others face from-scratch implementation.
- Innovation impact contested. Industry critics argue compliance cost suppresses EU AI competitiveness; regulators argue trust enables adoption. Real-world data on innovation impact will emerge through 2026-2028.
- SME / startup support uneven. Regulatory sandboxes provided; access and operational depth varies by Member State.
- Extraterritorial reach is broad. Non-EU providers whose AI outputs are used in EU are in scope. Enforcement against non-EU entities is procedurally complex.
Where the evidence currently sits
- Prohibited practices ban in effect since 2 February 2025. Limited enforcement activity visible publicly so far; some clarifications via Commission guidance.
- GPAI Code of Practice developed through 2024-2025 stakeholder process; published mid-2025. Voluntary; signing the Code helps with compliance.
- GPAI obligations applicable since 2 August 2025. Compliance activity by major model providers (Anthropic, OpenAI, Google, Meta, Mistral, Cohere, others) visible publicly.
- National competent authorities designated by Member States by mid-2025 (some lagging). DE designated multiple authorities reflecting federal structure.
- AI Office operational since late 2024.
- Harmonized standards process ongoing through CEN-CENELEC JTC 21; ISO 42001 harmonization in progress.
- High-risk obligations applicability approaching for August 2026. Major implementation activity visible for in-scope systems.
- First enforcement actions plausibly visible 2026-2027 as obligations take effect and authorities resource enforcement.
- Global influence: UK / Singapore / Canada / Brazil / Japan AI strategy publications reference the AI Act explicitly. Some non-EU jurisdictions (states / provinces) considering AI Act-influenced legislation.
Personal calibration
- Working assumption for AI-feature engagement work touching EU: AI Act applicability is real and compliance evidence is increasingly expected. Don't wait until enforcement to start mapping.
- Working assumption for AI system classification: classification (prohibited / high-risk / limited-risk / minimal-risk / GPAI) is the foundational question. Get classification clear before deeper compliance work.
- Working assumption for GPAI relationships: model provider AI Act compliance posture is a vendor due-diligence axis. Track per provider.
- Working assumption for transparency obligations: chatbot disclosure, deepfake labeling, AI-content labeling apply to limited-risk systems broadly. Low cost; build into product defaults.
- Working assumption for high-risk: if a system might be high-risk, get clarity early. The obligations are substantial and time-to-comply is significant.
- Working assumption for own work: AI Act fluency increasingly expected for AI / SRE work. Read the operative articles and recitals; understand the enforcement trajectory; bridge to implementation frameworks.
What would shift this view
- First substantial enforcement actions (plausibly 2026-2027) — will clarify interpretive ambiguities and signal enforcement priorities.
- ISO 42001 harmonization completion — will provide formal safe harbor and clarify compliance path.
- Article 6(3) clarification — the high-risk exemption for "narrow procedural" or "not significant risk" systems is currently underspecified. Commission guidance expected.
- GPAI threshold revision — 10^25 FLOP threshold is provisional. Revision likely as model capabilities outpace compute-only measurement.
- Notified Body capacity emergence — sufficient third-party conformity assessment capacity is foundational for high-risk obligation enforcement.
- Brussels effect data — clear evidence of non-EU jurisdiction adoption of AI Act-aligned provisions would reinforce the regulation's global weight.
- AI Act review (scheduled 2028 and periodically) — Commission review may produce amendments.