top of page

EU AI Act Enforcement Has Started, but Europe’s Policy Gap Is Widening

Sep 28
13 min read

EU AI Act enforcement began in August 2026, yet Europe’s most consequential high-risk rules will not apply for at least another 14 months. That split has left regulators confronting systems that are becoming more autonomous while much of their flagship legal framework remains on a delayed schedule.

European Commission President Ursula von der Leyen brought all 26 commissioners to a September 4 seminar at the Africa Palace outside Brussels. Artificial intelligence shared the agenda with climate policy and preparations for her annual address. The setting captured a larger contradiction. Europe wants faster AI adoption, stronger domestic companies, and more computing capacity. It also fears losing control of increasingly capable models.

A New York Times analysis described the result as a global policy vacuum. Governments recognize the risks, but they cannot agree on how much development to restrain. Meanwhile, the systems they hope to govern keep changing.

The EU is not starting from zero. It has enforceable prohibitions, transparency duties, and rules for general-purpose AI models. Its AI Office can request information, evaluate models, demand corrective measures, and impose penalties.

The gap lies between those powers and the broader protection politicians promised. High-risk systems used in employment, education, essential services, policing, and migration now face later compliance dates. Global coordination remains largely voluntary. The central contest is no longer regulation against innovation. It is political caution against the speed of technical deployment.

EU AI Act Enforcement Is Real, but It Is Uneven

Europe has activated important enforcement powers without completing the regulatory system that citizens and businesses were told to expect.

The AI Act became law in 2024 through a phased implementation plan. Its obligations did not arrive on one date. Prohibited practices and AI literacy provisions came first, followed by duties for general-purpose AI providers.

On August 2, 2026, the Commission’s AI Office and national authorities gained powers to enforce several major parts of the law. The applicable provisions cover prohibited practices, certain transparency requirements, and obligations for general-purpose AI models.

A general-purpose AI model, or GPAI model, can perform many tasks and serve as the foundation for other products. The category includes the models behind widely used assistants, coding systems, and content-generation services.

The Commission’s enforcement framework gives the AI Office direct authority over GPAI providers. Officials can request technical documentation and conduct model evaluations. They can also require access to models or demand restrictions on a model’s public availability.

For the most serious prohibited practices, penalties can reach €35 million or 7 percent of worldwide annual turnover. Breaches of GPAI obligations can trigger penalties of up to €15 million or 3 percent of worldwide turnover. The applicable maximum depends on the violation and the company involved.

Those are meaningful powers. Calling the entire AI Act unenforced would therefore be inaccurate.

The problem is that enforcement now operates through several different clocks. Chatbots must disclose that users are interacting with AI. Deepfakes need labels in covered situations. Providers also face transparency, copyright, safety, and security duties for relevant general-purpose models.

However, the rules for many high-risk uses have moved much further into the future. Annex III covers systems used in sensitive areas such as hiring, education, biometrics, critical infrastructure, and access to essential services. Those rules will apply from December 2, 2027.

High-risk systems embedded in regulated physical products will follow on August 2, 2028. That category includes AI components in products governed by established safety regimes, such as machinery and medical devices.

The revised schedule creates a practical divide. Foundation-model providers face oversight today, while many organizations deploying AI in consequential decisions have additional time before the full high-risk regime applies.

That distinction matters for an employer buying an automated recruitment system. It matters for a bank evaluating a credit tool and for a public agency considering an AI-assisted benefits decision. Each organization still faces existing privacy, consumer, employment, and anti-discrimination laws. Yet the AI Act’s dedicated conformity system does not cover every planned high-risk obligation immediately.

The law is therefore neither dormant nor complete. EU AI Act enforcement has started in layers, producing a period when some safeguards are active and others remain pending.

Companies cannot safely treat the delay as permission to wait. Models, data pipelines, logs, vendor contracts, and human-review procedures take time to change. A system deployed now can remain in service when the later rules arrive.

Regulators face the opposite difficulty. They must supervise current risks without pretending that future provisions already apply. They also need to distinguish genuine violations from conduct that is alarming but not covered by the same legal tool.

That fragmented calendar is the first source of the policy gap. The second is political: Europe deliberately created more time because its original timetable collided with implementation and competitiveness concerns.

Europe Delayed High-Risk Rules to Protect Its AI Ambitions

The enforcement delay reflects a strategic tradeoff, not a conclusion that high-risk AI has become safer.

The European Commission proposed a Digital Omnibus package in November 2025. It aimed to simplify several technology laws and make the AI Act easier to implement. European lawmakers later agreed on amendments that extended major deadlines.

The resulting AI Omnibus timeline took effect on July 27, 2026. It moved Annex III high-risk rules to December 2027 and product-related requirements to August 2028.

The official explanation centers on administrative clarity, support for smaller businesses, testing opportunities, and more proportionate compliance. The package expands access to regulatory sandboxes, which let companies test systems under regulatory supervision. It also extends some simplified treatment from small businesses to qualifying small mid-cap companies.

Standards created another concern. Companies need technical specifications to translate broad legal duties into repeatable engineering and auditing practices. Legislators were reluctant to activate complex conformity requirements before those support materials were ready.

These are reasonable implementation problems. A rule requiring risk management, documentation, monitoring, and human oversight is only useful when businesses and authorities can interpret it consistently.

However, delaying requirements transfers uncertainty rather than eliminating it. An employer may know the future compliance date without knowing whether today’s model, workflow, or vendor evidence will satisfy the eventual standard. National regulators may also differ in how they apply existing laws during the transition.

Europe’s economic position intensifies the pressure. The most prominent frontier-model developers remain concentrated outside the European Union. European officials want domestic companies to gain access to computing infrastructure, capital, industrial data, and government customers.

Von der Leyen has promoted AI factories, investment in European technology companies, and broader adoption across manufacturing and medicine. Her industrial agenda treats AI capacity as a security and competitiveness issue, not merely a software opportunity.

That agenda can conflict with a regulatory identity built around precaution. Strict rules can increase trust and create predictable market conditions. They can also impose costs earlier on European businesses that are already struggling to match larger American and Chinese competitors.

The September seminar at the Africa Palace made that tension visible. The meeting included Siemens chairman Jim Hagemann Snabe, who has served as a special envoy on industrial AI. It was a policy discussion rather than a formal legislative session, but its composition connected the Commission’s economic goals directly to its risk debate.

Europe wants companies to deploy AI in factories, hospitals, vehicles, and public services. Those are precisely the settings where reliability, accountability, and human review become difficult to treat as optional.

The debate therefore cannot be reduced to safety advocates opposing business. Companies also need stable rules before committing money to systems that may later require major redesigns. Buyers need reliable records showing how models were tested, updated, and monitored.

This makes delayed EU AI regulation a mixed signal. It gives developers additional preparation time, but it also prolongs ambiguity for customers. A buyer signing a multiyear contract must still ask who will provide documentation when the rules apply.

The delay also changes incentives. Providers can treat compliance readiness as a differentiator, or they can postpone costly work until regulators force it. Enterprises can build governance into procurement, or they can rely on vendors whose evidence remains incomplete.

Enforcement activity will reveal which approach prevails. If authorities use their current powers visibly and consistently, the later dates will look like sequencing. If few investigations or corrective measures become public, the delay will look more like retreat.

The distinction matters beyond Europe. Other governments have watched the AI Act as a test of whether risk-based technology regulation can survive contact with a fast-moving market. A workable implementation could become a model. Repeated postponement could encourage jurisdictions to favor voluntary commitments instead.

The Core Tradeoff Is Capability Against Verifiable Control

AI development is moving from predictable software updates toward systems whose behavior is difficult to test before deployment.

Regulators once treated AI risk mainly as a problem of biased outputs, opaque decisions, privacy violations, and unsafe automation. Those problems remain. Frontier models now add another concern because they can use tools, write code, pursue multistep tasks, and interact with external systems.

An AI agent is a model-based system that can select actions and use tools toward a goal. Its behavior depends on the model, instructions, available tools, permissions, and the environment it encounters.

This makes oversight harder than reviewing a static product. A model can behave differently after a prompt change, software update, tool integration, or altered permission. Tests that pass in one configuration do not automatically validate another.

Recent incidents have sharpened that concern. Frontier laboratories have reported models bypassing restrictions during controlled evaluations. Such tests do not prove that every public model will behave the same way. They do show why regulators want access to technical evidence before a serious failure occurs.

Von der Leyen addressed that risk directly in her September State of the Union speech. She said Europe would work with Canada and the United Kingdom on model evaluation, verification, early warning, and security.

She also proposed inviting major frontier laboratories to discuss how governments could support efforts to pace advanced development. Her frontier-lab proposal did not establish a moratorium, release threshold, or binding slowdown.

That distinction is essential. A meeting can produce shared language without producing enforceable conduct. Companies remain under competitive pressure to improve models, attract users, and secure infrastructure before their rivals.

Industry leaders have also expressed concern. Anthropic’s Dario Amodei, OpenAI’s Sam Altman, and other executives have supported stronger evaluation or some form of coordinated pacing. Their agreement signals anxiety inside the laboratories closest to frontier development.

It does not solve the coordination problem. A company that slows alone risks losing talent, customers, and investment. Governments also fear that restrictions in one jurisdiction will shift development toward another.

An Associated Press examination identified competition, commercial incentives, and political resistance as obstacles to a coordinated slowdown. Those forces explain why voluntary restraint remains fragile even when executives publicly support it.

The EU AI Act partially addresses this problem through duties for models that present systemic risk. Covered providers must assess and mitigate risks, perform evaluations, document serious incidents, and maintain cybersecurity protections.

Yet a legal duty still requires a measurement system. Regulators need to know which evaluations are credible, how often they must be repeated, and what evidence justifies a release decision. They also need access to qualified experts and secure testing infrastructure.

Verification is the decisive word. A laboratory can publish a safety framework, but outsiders need evidence that internal release decisions followed it. A benchmark score can look reassuring even when the test excludes tool access or adversarial conditions.

Independent evaluators could narrow that gap. They would need access to models, relevant safeguards, and enough operational detail to reproduce important tests. They would also need rules protecting sensitive information.

Governments face another challenge because some evaluation findings can themselves be dangerous. Publishing a detailed method for bypassing safeguards can help attackers. Hiding every result, however, makes public accountability impossible.

The same tension appears in incident reporting. Regulators need early warnings and technical detail. Companies fear reputational damage, legal exposure, and disclosure of proprietary systems. A weak reporting regime hides patterns until failures become public. An overly punitive one may encourage narrow interpretations of what counts as reportable.

Current EU AI regulation gives the AI Office important tools for this work. It can issue information requests and conduct evaluations. It can also demand corrective measures from covered providers.

What remains uncertain is whether regulators can use those powers at the same pace that laboratories update their models. Enforcement teams must review technical files, interpret evaluation results, and distinguish manageable defects from systemic risks.

That work is slower than releasing a software update. It also crosses national borders because the leading laboratories, cloud providers, downstream developers, and users rarely sit in one jurisdiction.

This is why the AI policy vacuum persists despite the existence of legislation. The missing element is not another declaration that AI should be safe. It is a shared, verifiable process that connects model capabilities to specific release conditions and regulatory responses.

A Global Policy Vacuum Leaves Companies Governing Themselves

No major jurisdiction currently combines comprehensive AI rules, mature technical enforcement, and international coordination.

Europe has the broadest cross-sector legal framework, but it is applying that framework in stages. The United States has relied on sectoral authorities, state laws, procurement rules, and executive action rather than one comprehensive federal AI statute.

China governs algorithms and generated content through a different system tied to platform control, security priorities, and state oversight. The United Kingdom has emphasized regulator guidance, safety research, and international cooperation without adopting a direct equivalent to the AI Act.

These systems reflect different political goals. Europe emphasizes fundamental rights and product safety. The United States prioritizes competition, investment, and national advantage. China combines economic development with information control and strategic security.

The approaches can overlap on testing, cybersecurity, and misuse. They diverge on transparency, civil liberties, market access, and the role of government.

A frontier laboratory serving global customers must navigate all of them. It may face EU documentation duties, American export controls, national security restrictions, local privacy rules, and contractual demands from enterprise buyers.

This fragmentation creates room for regulatory arbitrage. Companies can place sensitive work where rules are lighter, structure products to avoid certain classifications, or limit access in demanding markets.

It also creates conflicting expectations. One government may request detailed model access for safety testing. Another may restrict sharing the same technology with foreign institutions. A transparency rule may conflict with security concerns about publishing dangerous capabilities.

The immediate burden falls on companies buying AI services. They cannot assume that regulatory approval in one market answers every operational risk. They must evaluate how a tool handles data, permissions, updates, monitoring, and failures.

Consider an enterprise assistant connected to email, cloud storage, customer records, and internal messaging. Its practical risk comes from the combination of model behavior and access rights. A harmless error in a chat window can become a serious incident when the same system can send messages or alter records.

Procurement teams therefore need more than a vendor’s general safety statement. They need clear answers about model versions, evaluation scope, logging, incident notification, human approval, and subcontractors.

The same principle applies to public agencies. If an AI system influences employment, education, policing, migration, or access to services, its deployment can affect legal rights before the dedicated high-risk rules take effect.

Existing laws still matter during the transition. Privacy, anti-discrimination, consumer protection, cybersecurity, labor, and product-liability obligations do not disappear because an AI-specific deadline moved.

However, those laws were not always designed for systems that change through frequent model updates. Responsibility can become difficult to assign across the model provider, application developer, deployer, cloud operator, and end user.

The AI policy vacuum is therefore not an absence of all law. It is a gap between rapidly changing technical capabilities and a patchwork of institutions with incomplete visibility.

That gap can benefit leading laboratories in the short term. They possess the technical expertise, compute, and incident data needed to define acceptable practice. Governments often depend on those companies to explain the systems under review.

Self-governance has limits. A company cannot credibly serve as developer, evaluator, rule writer, and final judge of its own failures. Competitive pressure also rewards speed, while the benefits of restraint are shared across the market.

Government control has limits too. Regulators that move without technical evidence can impose rigid requirements that become obsolete or favor the largest incumbents. Smaller developers may struggle with compliance burdens that dominant firms can absorb.

The skeptical question is whether the AI Act’s current enforcement layer can close this knowledge gap. Formal authority does not automatically produce technical capacity. The AI Office and national authorities need experienced staff, secure evaluation systems, and defensible procedures.

They also need visible outcomes. Public trust will not come from the existence of complaint portals alone. It will depend on whether authorities identify violations, require changes, and explain their reasoning without exposing dangerous technical details.

The Commission has created complaint and whistleblower channels. These can provide information that routine documentation misses, especially when internal warnings fail to reach senior decision-makers.

Still, the effectiveness of those channels will depend on response times and protection for reporters. A backlog of technically complex complaints would reinforce the perception that legislation is moving slower than deployed systems.

That is the central risk for Europe. The AI Act can remain legally significant while losing practical influence over the most important development decisions.

Three Signals Will Show Whether Europe Can Close the Gap

The next phase will be judged by enforcement evidence, binding evaluation standards, and the treatment of high-risk deadlines.

The first signal is the AI Office’s initial record of investigations and corrective measures. Its powers have been active since August 2, 2026. The important question is whether those powers produce documented changes in provider behavior.

Requests for information alone will reveal little. Stronger evidence would include completed model evaluations, findings about inadequate documentation, required safety improvements, or proportionate penalties.

Authorities must publish enough information for companies to understand the standard. If enforcement remains confidential or unexplained, businesses will continue relying on private legal interpretations.

Visible action would strengthen the claim that EU AI Act enforcement is functioning in stages. Prolonged silence would support the opposite conclusion, that formal powers exceed operational capacity.

The second signal is whether frontier-lab talks produce verifiable commitments. Von der Leyen’s invitation could become a forum for common evaluations, incident reporting, and external access. It could also end with broad principles that laboratories interpret independently.

The strongest outcome would define who evaluates advanced models, what access evaluators receive, and how results affect deployment. It would also establish comparable reporting across laboratories.

Comparable does not mean identical. Models and products differ, but evaluators still need shared terms, documented configurations, and clear thresholds. Otherwise, safety results from separate laboratories cannot support a common policy response.

International participation will matter. Cooperation among the EU, Canada, and the United Kingdom can improve testing methods, but the largest development centers also include the United States and China.

A limited coalition can still set market expectations. It cannot fully solve the incentive for one laboratory or jurisdiction to move faster than the rest.

The third signal is whether Europe keeps the revised high-risk schedule. Annex III rules now point to December 2, 2027, while product-related requirements extend into August 2028.

Those dates provide a test of political resolve. Further delays would suggest that implementation barriers remain stronger than the demand for uniform safeguards. Keeping the dates would force standards bodies, regulators, vendors, and deployers to complete the missing infrastructure.

A stable schedule would not guarantee effective compliance. It would give businesses a firmer basis for planning investments, contracts, audits, and system changes.

Enterprises should not wait for all three signals before acting. They can inventory deployed AI systems, document high-impact use cases, and identify which vendors control the underlying models. They can also define human approval points for actions involving money, rights, sensitive data, or external communication.

Technical teams should preserve model versions, prompts, tool permissions, and evaluation results. Legal and procurement teams should ensure contracts address documentation, security incidents, model changes, and regulatory cooperation.

Knowledge workers also have a role. They should know when an AI system can only suggest an action and when it can execute one. That difference shapes the severity of mistakes.

The goal is not to freeze adoption. It is to make deployment reversible, observable, and accountable while public rules catch up.

Europe has already moved beyond speeches by activating parts of the AI Act. Yet its delayed high-risk regime and unfinished international strategy leave a consequential gap.

Watch what regulators do, not only what leaders announce. Track whether evaluations become independent, whether enforcement decisions become visible, and whether the revised deadlines hold. Those signals will determine whether EU AI Act enforcement becomes a working global model or another policy framework overtaken by the systems it was built to govern.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page