Commentary. The world is entering a consequential phase of artificial-intelligence regulation. The European Union’s AI Act enforcement powers became operational on 2 August 2026, while its transparency obligations are scheduled to cover AI-generated audio, images, video and text from 2 November.[1][2] In the United States, lawmakers continue to debate federal oversight, including proposals for incident reporting and risk controls.[1][2] Our view is straightforward: governments should stop treating the passage of rules as proof of safety. The real test is whether people can understand, challenge and escape harmful automated decisions.

The case for regulation is strong. AI systems increasingly mediate access to jobs, education, financial services, healthcare and public information. When such systems produce false content, expose personal data or reproduce discriminatory patterns, the consequences are not merely technical. They can be difficult to detect and even harder for an individual to contest. The EU’s framework gives its AI Office powers to investigate general-purpose-model providers, demand documentation, conduct evaluations and impose significant fines.[3] Those powers are a necessary acknowledgment that voluntary promises cannot substitute for accountability.

Yet regulation can fail in another way: by becoming a compliance industry detached from ordinary users. The EU’s staggered timetable—high-risk rules for some systems applying in December 2027 and for others in August 2028—reflects the complexity of bringing broad legislation into force.[2] Businesses, particularly smaller firms, argue that uncertainty and overlapping obligations may delay useful products or entrench the largest technology companies, which can afford lawyers and testing laboratories. Those concerns deserve more than ceremonial consultation. A rule that only the biggest firms can navigate may reduce competition without reliably reducing risk.

The danger of symbolic safeguards

Transparency is valuable, but a label alone does not make an AI system trustworthy. Telling a user that an image or passage was generated by AI may help in some contexts; it does little when a benefits application is rejected, a worker is screened out or a medical recommendation is wrong. Regulators should therefore prioritize remedies: clear explanations, human review, accessible appeals and records that allow independent investigators to reconstruct what happened.

There is also a legitimate argument for restraint. Overly prescriptive rules can freeze assumptions about a fast-changing technology. The United States’ fragmented approach, though confusing, may allow experimentation and faster adaptation. Japan’s non-binding principles for generative-AI developers show the appeal of guidance that encourages innovation while addressing intellectual-property concerns.[3] Industry leaders likewise argue that self-regulation can move more quickly than legislation.[4] That argument should not be dismissed outright; companies often possess the technical knowledge regulators lack.

But expertise is not independence. A company deciding whether its own system is safe faces incentives that a public authority does not. Self-regulation can supplement enforceable standards, especially for technical testing and best practices, but it cannot be the final safeguard where rights, livelihoods or public safety are at stake. Nor should innovation be defined as the freedom to externalize costs onto people who have no meaningful way to object.

What responsible enforcement looks like

Our newsroom’s position is not that every AI deployment requires a bureaucratic maze. It is that obligations should track impact. Low-risk tools should face light-touch requirements. Systems used in employment, credit, education, healthcare, policing or essential services should meet a higher bar before deployment, with ongoing monitoring rather than one-time certification.

Europe’s enforcement moment is therefore more than a legal milestone. It is an opportunity to demonstrate whether democratic oversight can keep pace with private power. The answer will not be found in the number of pages in a regulation or the confidence of an executive statement. It will be found in whether a person harmed by an automated system can get an explanation, a correction and a remedy.

Sources