All articles
Policy
May 8, 2026· 6 min read· Editorial Team

The EU AI Act One Year In: What's Actually Changed

Twelve months after the EU AI Act's main provisions took effect, here's what's working, what's not, and what builders need to know.

The European Union's AI Act has now had its main provisions in force for a year. The early predictions ranged from 'crippling burden that will drive AI out of Europe' to 'toothless theater that will change nothing.' Reality, as usual, has been more nuanced than either extreme. Here's where things stand.

The enforcement reality

Active enforcement has been more targeted and less aggressive than many feared. The first wave of regulatory attention has focused on prohibited practices — social scoring, real-time biometric identification in public spaces, and emotion recognition in workplaces and schools. Several high-profile actions against specific systems have established that the prohibitions are real and the penalties bite.

For most builders, however, the day-to-day impact has been about documentation and transparency, not bans. The largest practical effect has been the requirement to maintain detailed records of training data, evaluation results, and risk assessments for high-risk systems.

What 'high-risk' actually means

The high-risk category has settled into something more workable than the early drafts suggested. Most consumer AI products — chatbots, image generators, productivity tools — are not high-risk and face only modest transparency obligations. The high-risk category genuinely focuses on systems used in employment, education, critical infrastructure, law enforcement, and access to essential services. If you are building one of these systems, the compliance burden is real and you should be working with specialized legal counsel.

If you're not, the practical effect is more manageable: clear disclosure that users are interacting with an AI system, watermarking of synthetic media, and reasonable documentation of how your system works.

General-purpose models

The rules for general-purpose AI models — the foundation models that power most products — have been refined into a workable regime. Providers must publish summaries of training data, implement reasonable copyright safeguards, and meet additional obligations if their models exceed defined compute thresholds. All major providers have complied without significant disruption.

The threshold-based approach has held up reasonably well. The biggest models face the most obligations, which is roughly the right shape. The harder question — whether the threshold is set at the right level — remains a live debate.

The Brussels Effect

As with GDPR, the AI Act is shaping global practice well beyond Europe's borders. Many companies have chosen to adopt EU-compliant practices globally rather than maintain separate regimes. Other jurisdictions — the UK, Canada, several US states, and increasingly Asian regulators — have looked to the AI Act as a template, with local modifications.

Whether this is good or bad depends on your view of the substantive rules. What is undeniable is that the AI Act has become the global reference point, in the same way GDPR did for privacy.

What builders should do

If you are building AI products in 2026, regardless of whether you serve European users, the practical advice is: maintain documentation as if you might be audited, disclose AI usage clearly to users, watermark synthetic media where you can, and treat copyright and data sourcing as first-class concerns rather than afterthoughts.

None of these practices are uniquely European. They are increasingly the global baseline for responsible AI development. Build them in now, and the next wave of regulation — whatever shape it takes — will be much less disruptive.

Where the Act is falling short

The Act has been less effective than hoped at addressing the harms that motivated it: misinformation, algorithmic discrimination, and concentration of power among a few large providers. These are hard problems that no single regulation can solve, and the Act's blunt tools are not always well matched to the subtle ways these harms manifest.

Expect the next round of legislative attention to focus on these gaps, both in Europe and elsewhere. The AI Act is a foundation, not a finished structure.

Keep reading