Commentary. The European Union’s artificial-intelligence rulebook has entered its most consequential phase. From August 2, 2026, the EU’s AI Office and national authorities began enforcing the AI Act, while amendments adopted this summer adjusted parts of the framework after pressure from industry.[1] That combination—implementation alongside political compromise—offers a useful lesson beyond Europe: the credibility of AI regulation will depend not on the ambition of the text, but on whether ordinary people can see its protections in practice.

Our view is straightforward: governments should regulate AI firmly where it affects rights, safety and access to essential services, while resisting the temptation to treat every new model as an existential emergency. A system that helps draft a marketing email does not warrant the same scrutiny as one used to screen job applicants, assess creditworthiness or influence access to education. Regulation should follow the consequences of deployment, not the novelty of the technology.

The case for enforceable rules

The EU has taken a more binding approach than the United States, where voluntary commitments and executive actions remain central, while China has pursued a mixture of state oversight and targeted rules.[2] None of these models is complete. But the EU is right about one fundamental point: companies should not be allowed to define public safeguards entirely on their own.

Automated systems can reproduce discrimination, expose personal data, generate convincing falsehoods and make decisions that are difficult for individuals to challenge. In high-stakes settings, requiring documentation, testing, human oversight and avenues for appeal is not anti-innovation. It is a basic condition for using powerful tools responsibly.

Recent legislative activity in the United States reinforces the need for that baseline. States have continued to consider rules governing automated decisions in employment, housing, finance and education, as well as requirements for auditing frontier systems, while no federal AI bill had passed during the 2026 session covered by the Center for Democracy & Technology.[3] A patchwork can produce experimentation, but it can also leave rights dependent on geography and make compliance needlessly confusing.

The strongest objections deserve an answer

Critics of stringent regulation are not wrong about every risk. Compliance costs can fall hardest on smaller companies, which may lack the lawyers, engineers and testing infrastructure available to major technology firms. Vague rules can also encourage defensive bureaucracy, delay useful products and push development toward countries with weaker safeguards. Europe’s decision to amend elements of its framework shows that policymakers themselves recognize these pressures.[1]

There is also a legitimate concern that regulators may move faster than the evidence. A broad ban prompted by speculative fears could prevent beneficial applications in medicine, accessibility or scientific research. Public authorities should not pretend to know precisely how every future model will behave.

But uncertainty is not an argument for inaction. It is an argument for rules that are specific, reviewable and proportionate. Regulators should publish clear technical standards, provide support for smaller firms and require independent evaluations of systems used in consequential decisions. They should also make it possible to revise obligations when evidence changes—without allowing every implementation deadline to become an invitation for indefinite delay.

What enforcement should mean

The next test is whether enforcement reaches beyond paperwork. Authorities should prioritize cases in which people cannot meaningfully opt out, understand a decision or correct an error. That means examining recruitment tools, biometric identification, public-benefits systems, health applications and education platforms before devoting equal energy to low-risk consumer experiments.

Penalties matter, but transparency matters too. The public should be able to learn which systems are being used, for what purpose, with what error rates and under whose responsibility. Companies should disclose material incidents, and affected people should receive an intelligible explanation and a route to appeal. A human “in the loop” is not enough if that human merely approves an opaque machine recommendation.

The EU’s enforcement phase should therefore be judged by outcomes: fewer discriminatory decisions, faster remedies, clearer accountability and safer products—not by the volume of guidance documents issued. The United States and other governments should learn from Europe’s regulatory reach while avoiding its complexity where simpler, outcome-based rules would work better.

AI policy has become a contest between two exaggerated visions: that regulation will kill innovation, or that regulation alone will tame technology. Both are wrong. Innovation is more durable when the public trusts it, and trust requires enforceable limits. The responsible path is neither a blank cheque nor a blanket prohibition. It is disciplined oversight aimed at the places where algorithms can change a person’s life.

Sources