The European Union’s landmark artificial intelligence legislation, known as the AI Act, aims to establish a rigorous regulatory framework designed to protect Europeans from potential risks posed by AI technologies. Enacted in 2024, the law mandates that companies assess and mitigate risks associated with AI systems, with the threat of sizable fines or activity bans for non-compliance. However, questions remain about the law’s effectiveness and whether the EU is prepared to enforce it robustly.
Implementation of the AI Act was partially delayed, with enforcement powers only coming into force in August 2024. Since then, EU regulators have issued more than 30 requests for information to AI providers, covering issues such as copyright, cybersecurity, and safety. The European Commission maintains that these steps demonstrate the rules are functioning as intended. EU spokesman Thomas Regnier emphasized the safeguards in place, stating that citizens “can feel safe at home in Europe” under the new regime.
Despite this assurance, skepticism persists among lawmakers, officials, and experts. Several EU lawmakers, including Brando Benifei, the lead negotiator for the AI Act, have raised concerns about “legislative gaps,” particularly due to the shelving of AI liability rules. These rules would have simplified holding AI developers accountable for harm caused by their tools. Critics argue that the current legislation does not adequately cover the research, testing, or development phases of AI, potentially leaving users unprotected during these stages.
The European Commission contends that the law’s enforcement extends to providers starting from the testing phase if a loss of control jeopardizes the EU’s internal market, including risks like cyberattacks or misuse involving biological or chemical agents. Nonetheless, researchers such as Harshvardhan Pandit from the AI Accountability Lab at Trinity College Dublin highlight ongoing accountability shortcomings. Pandit noted uncertainty around responsibility in cases where AI models, once deployed, engage in harmful actions such as hacking.
Concerns also exist about the EU’s capacity to enforce the regulation effectively. The European AI Office, which oversees compliance, currently employs roughly 125 staff members—a number deemed insufficient by some lawmakers and experts. Benifei has called on the European Commission to provide the office with enhanced political support, operational independence, and increased technical resources to enable decisive enforcement.
Another challenge lies in the EU’s ability to regulate major AI firms, predominantly based in the United States. Ongoing tensions have emerged from Brussels’ probes and substantial fines imposed on US tech companies under various laws. Some EU officials acknowledge that full enforcement against American companies may be tempered by Europe’s reliance on US technology. To strengthen its position, the EU is exploring efforts to develop indigenous AI capabilities, including investments in chip manufacturing and cloud infrastructure, as well as calls for public initiatives akin to the CERN physics laboratory.
European Commission President Ursula von der Leyen has also proposed dialogue with leading AI developers to collectively “pace” technological progress. However, a broader international consensus remains elusive, especially without cooperation from the United States, where regulatory enthusiasm is limited. Lawmakers like Benifei advocate for collaboration with middle powers such as Canada to advance shared regulatory objectives, aiming to prevent dominance by any single country or corporation in setting global AI standards.
