Commentary. Europe has crossed an important line in artificial-intelligence policy: the EU AI Act is now enforceable, giving the bloc’s AI Office and national market-surveillance authorities powers to police prohibited, high-risk and transparency obligations. [1] That achievement deserves recognition. But our view at Archange Shadows is that the law should now be judged less by its ambition than by whether ordinary people can see a meaningful difference in how automated systems affect their lives.
The temptation is to declare victory. The Act is the world’s most prominent attempt to create a comprehensive framework for AI, and its transparency rules require certain systems to disclose or mark synthetic content. Yet the timetable remains staggered: some high-risk obligations will not apply until 2027 or 2028, while providers of some existing generative-AI systems have limited grace periods. [1] That delay may be legally sensible, but it creates a political risk. Citizens hear that regulation has arrived while many of the most consequential safeguards remain years away.
The case for restraint
There are good reasons not to demand instant enforcement of every provision. Companies, public agencies and smaller developers need time to understand technical standards and redesign products. A rulebook that changes faster than institutions can implement it may produce paperwork rather than safety. The EU’s July “AI Omnibus” was presented as a simplification measure, including streamlined requirements and expanded testing opportunities for smaller businesses. [1] Those adjustments acknowledge a real concern: compliance costs can fall hardest on organizations that lack the legal and engineering resources of major technology firms.
Nor should every error by an algorithm become proof that AI itself is unworkable. Automated tools can assist doctors, improve public services and help businesses operate more efficiently. Excessive caution could push investment and talent elsewhere, leaving European users dependent on systems designed under weaker rules. The technology sector is right to warn that vague duties, overlapping regulators and unpredictable penalties can discourage useful experimentation.
But flexibility cannot mean opacity
Those arguments explain why implementation should be proportionate. They do not justify making affected people carry the risks in silence. AI systems used in employment, housing, education, finance or essential services can influence access to opportunity even when no one affected understands how a decision was made. Recent US state legislative activity illustrates the breadth of the problem: lawmakers are addressing automated decisions, frontier-model risks, third-party auditing and public-sector use, while states continue to debate safeguards for chatbots and AI companions. [2]
The European framework therefore needs visible enforcement priorities. Regulators should begin with uses where mistakes can alter a person’s livelihood, liberty, safety or access to basic services. They should publish plain-language explanations of investigations and require meaningful routes to human review. A disclosure buried in terms of service is not transparency; it is legal decoration.
We also believe enforcement must reach beyond headline-grabbing bans. The Act’s rules on synthetic content matter, especially as fabricated images, voices and personas become easier to produce. But labels work only when platforms preserve them, users can understand them and authorities can act when manipulation causes harm. The question is not simply whether content was generated by AI. It is whether people were misled, targeted or denied a fair chance to respond.
A test of democratic confidence
The strongest counterargument is that regulators should avoid turning themselves into technology designers. That warning is fair. Governments are often slower than markets, and poorly drafted rules can entrench incumbents by making compliance too expensive for newcomers. The answer is not maximal regulation; it is disciplined regulation: narrow rules for high-impact uses, independent auditing, clear evidence standards and periodic review.
Europe now has the institutional opportunity to prove that model. Enforcement should be adequately funded, technically competent and insulated from both industry lobbying and political pressure. Companies that comply in good faith should receive predictable guidance, while those that conceal risks or evade accountability should face consequences proportionate to the harm.
Our position is straightforward: the AI Act should neither be celebrated as a finished solution nor dismissed as a bureaucratic obstacle. It is a democratic promise that automated power will remain answerable to the people affected by it. That promise will be kept only when enforcement is understandable, remedies are real and innovation is measured not merely by what machines can do, but by whether society can trust the institutions governing them.