Policy & Regulation · entry 02/05
The EU AI Act
Europe regulated AI the way it regulates products: a risk pyramid from banned practices to free use, plus a bolted-on regime for general-purpose models — with reach far beyond Europe.
The pyramid
The Act sorts uses into four tiers. Prohibited: practices deemed unacceptable — social scoring by public or private actors, exploitative manipulation, scraping faces off the internet for recognition databases, most real-time remote biometric identification in public (with carve-outs law enforcement lobbied hard for). High-risk: AI in products already safety-regulated (devices, vehicles) plus listed sensitive domains — hiring, credit, education, essential services, border control. These carry the real obligations: risk management, data governance, documentation, human oversight, accuracy and robustness requirements, conformity assessment before market. Limited risk: transparency duties — chatbots must disclose they're chatbots, synthetic media must be labeled. Minimal: everything else, unregulated. The design principle is proportionality: regulate the use, scale the burden to the harm.
The GPAI bolt-on
Drafted before ChatGPT, the Act met general-purpose models mid-negotiation and grew a second regime. All general-purpose model providers owe technical documentation, downstream information, and a copyright/training-data transparency policy. Models above a compute threshold are presumed to pose "systemic risk" and owe more: adversarial testing, incident reporting, cybersecurity, risk mitigation. It is model-based regulation grafted onto a use-based statute — philosophically messy, practically inevitable, and the part most watched by other jurisdictions drafting their own.
The timeline and the reach
Entered into force August 2024, applying in stages: prohibitions first (early 2025), GPAI obligations next (mid-2025) — and the heavy high-risk machinery, originally slated for 2026–2027, pushed back by a 2026 omnibus amendment toward late 2027 and 2028. The delay is itself a datapoint: the first hard evidence that this Act's deadlines bend under industry pressure, with standards bodies still racing to define what compliance concretely means. The reach is the famous part: like GDPR, it applies to anyone serving EU users, so the "Brussels effect" makes one bloc's rulebook a default global engineering constraint — cheaper to build one compliant pipeline than two.
The honest critiques
From safety advocates: thresholds and carve-outs leave real gaps, and enforcement capacity is unproven. From industry: compliance cost lands hardest on small players (incumbents can afford lawyers), definitions wobble at the edges, and Europe risks regulating a market it doesn't lead. Both critiques are partly right, which is roughly what a first draft of anything looks like. The Act's deepest contribution may be vocabulary: risk tiers, conformity, systemic-risk models — the terms every subsequent debate now uses.
Failure mode
Treating it as Europe's problem. Teams outside the EU discover late that an EU user base, an EU enterprise customer's procurement checklist, or a product embedded in someone's high-risk workflow pulls them into scope — and that documentation debt compounds: evidence not collected during training can't be retro-fitted at audit time. If the EU market matters to you at all, read the high-risk list against your roadmap now, not at the first customer questionnaire.