Pacific Design/ artificial intelligence

Policy & Regulation · entry 02/06 · 3 min read

The EU AI Act

Europe regulated AI the way it regulates products: a risk pyramid from banned practices to free use, plus a bolted-on regime for general-purpose models — with reach far beyond Europe.

The EU AI Act — illustration

The pyramid

The Act sorts uses into four tiers. Prohibited: practices deemed unacceptable — social scoring by public or private actors, exploitative manipulation, scraping faces off the internet for recognition databases, most real-time remote biometric identification in public (with carve-outs law enforcement lobbied hard for). High-risk: AI in products already safety-regulated (devices, vehicles) plus listed sensitive domains — hiring, credit, education, essential services, border control. These carry the real obligations: risk management, data governance, documentation, human oversight, accuracy and robustness requirements, conformity assessment before market. Limited risk: transparency duties — chatbots must disclose they're chatbots, synthetic media must be labeled. Minimal: everything else, unregulated. The design principle is proportionality: regulate the use, scale the burden to the harm.

The GPAI bolt-on

Drafted before ChatGPT, the Act met general-purpose models mid-negotiation and grew a second regime. All general-purpose model providers owe technical documentation, downstream information, and a copyright/training-data transparency policy. Models above a compute threshold are presumed to pose "systemic risk" and owe more: adversarial testing, incident reporting, cybersecurity, risk mitigation. It is model-based regulation grafted onto a use-based statute — philosophically messy, practically inevitable, and the part most watched by other jurisdictions drafting their own.

The timeline and the reach

Entered into force August 2024, applying in stages: prohibitions first (early 2025), GPAI obligations next (mid-2025) — and the heavy high-risk machinery, originally slated for 2026–2027, pushed back by a 2026 omnibus amendment toward late 2027 and 2028. The delay is itself a datapoint: the first hard evidence that this Act's deadlines bend under industry pressure, with standards bodies still racing to define what compliance concretely means. The reach is the famous part: like GDPR, it applies to anyone serving EU users, so the "Brussels effect" makes one bloc's rulebook a default global engineering constraint — cheaper to build one compliant pipeline than two, which is the only thing making the rest of the world's rulebooks tractable at all.

The honest critiques

From safety advocates: thresholds and carve-outs leave real gaps, and enforcement capacity is unproven. From industry: compliance cost lands hardest on small players (incumbents can afford lawyers), definitions wobble at the edges, and Europe risks regulating a market it doesn't lead. Both critiques are partly right, which is roughly what a first draft of anything looks like. The Act's deepest contribution may be vocabulary: risk tiers, conformity, systemic-risk models — the terms every subsequent debate now uses.

The EU AI Act — the failure mode

Failure mode

Treating it as Europe's problem. Teams outside the EU discover late that an EU user base, an EU enterprise customer's procurement checklist, or a product embedded in someone's high-risk workflow pulls them into scope — and that documentation debt compounds: evidence not collected during training can't be retro-fitted at audit time. If the EU market matters to you at all, read the high-risk list against your roadmap now, not at the first customer questionnaire.