Global Edition
The Doom Ledger
Est. 2026
AI is not a new church, and people don’t need a new pope.

The EU AI Act and the People Who Will Have to Enforce It

Writing a technology law is the easy part. Staffing it is where the ambition meets reality.

A European Union institutional building — photo by Diliff, licensed under CC BY-SA 3.0 via Wikimedia Commons.

The European Union’s approach to artificial intelligence is the most comprehensive regulatory framework any major jurisdiction has attempted. It classifies systems by risk, imposes obligations on providers according to that classification, and creates supervisory structures to enforce them.

The difficult part begins after the text is final. A rule that requires a company to document its training data, conduct conformity assessments and report serious incidents is only meaningful if someone checks.

Assessors have to be hired first

  • National supervisory authorities must be designated, funded and staffed with technical expertise.
  • Assessors need enough machine learning knowledge to evaluate claims they are given.
  • Smaller member states have limited pools of qualified people and competing priorities.

A model is not a medical device

Assessing a general-purpose model is not like inspecting a medical device. The behaviour depends on deployment context, changes with fine-tuning, and is difficult to bound in advance. Regulators have responded by leaning on documentation and process requirements — what the provider did, what it tested, what it concluded — rather than on independent testing of the system itself.

Advertisementin-article · responsiveAfter the opening section of a long article. Never between a heading and its own body.

That approach is workable but it has a known weakness: it verifies that a process was followed, not that a system is safe.

The single market as a lever

Industry objections have focused on compliance cost and on the risk that European firms face obligations their American and Chinese competitors do not. European policymakers have generally responded that a large single market can set terms for anyone who wants access to it, which has historically worked in other regulated sectors.

Whether it works here depends on something less tractable: whether businesses and consumers insist on AI features badly enough to accept the friction. So far the evidence suggests they do.

Is a hiring model high risk, or only its deployment?

Any risk-based regime depends on classifying systems correctly, and the boundaries are contested. Is a model that could be used for hiring a high-risk system, or only its deployment in a hiring workflow? Does a general-purpose model that can write legal analysis fall into a regulated category?

Advertisementin-article-2 · responsiveRoughly two thirds down a long article.

The answers determine who bears compliance cost, and the industry has an obvious incentive to argue for narrow definitions. Regulators have an incentive to be broad and lack the technical capacity to adjudicate fine distinctions, which pushes the decision toward documentation requirements that apply regardless of classification.

The burden falls on firms with no legal department

The compliance burden falls hardest on organisations without legal departments. Large providers can absorb it and, in some cases, benefit from it, because a demanding regime raises the cost of competing with them.

That dynamic has been noted in every regulated technology sector, and the standard mitigation is proportionality: lighter requirements for smaller providers. In practice proportionality is difficult to define without creating an obvious route around the rules.

Image credit and licence details for every photograph on this site are listed on the credits page. This article is editorial content; it carries no sponsored material.

Related

Advertisementfooter-banner · 970x90End of page, above the site footer. Never inside the footer itself.