EU AI Act Enters Its Hard Phase as GPAI Rules and a Funding Gap Collide
The EU AI Act's obligations for general-purpose AI models are due to land on 2 August, according to the European Commission's AI Office, but the bloc's bid to set the global standard for AI rules is running into a funding gap and a shortage of scaleups.

The EU AI Act entered into force on 1 August 2024. In a compliance overview published on 22 June 2026, GDPR Local calls it the first comprehensive legal framework for artificial intelligence anywhere in the world. The regulation sorts AI systems into four risk tiers. Obligations scale with the potential harm a system poses to fundamental rights, competition and public safety.
General-purpose AI models sit at the top of that stack. Their key rules were expected on 2 August, and the AI Office has said it plans to finalise them in July, before the European Parliament adopts its position on the standards. "This is a big, sophisticated technology, and we want to get it right," Eoghan O'Neill, senior policy officer at the AI Office, told the TNW Conference in Amsterdam on 20 June. "We need specific obligations to capture some of the most impactful or potentially harmful models under the AI Act."
O'Neill said a broad code of practice group drafted the guidelines. Its members included major model providers, civic society organisations, NGOs, academics, AI safety experts, SMEs and European industrial giants. "It is a big tent with all of those voices from the stakeholder community," he said.
The delay has turned into a political fight. Swedish Prime Minister Ulf Kristersson, Bosch CEO Stefan Hartung and the tech lobbying group CCIA Europe, whose members include Alphabet, Meta and Apple, have intensified calls to postpone the roll-out, The Next Web reported on 2 July 2025.
Rules, capital and the scaleup problem
Tech leaders argue the problem is not only the text of the AI Act. Fabrizio Del Maffeo, CEO of the Netherlands-based chip company Axelera AI, said Europe's many languages, markets and layers of regulation create borders that make expansion harder. His company signed a petition for EU Inc, a proposal for a standardised legal entity for startups that would operate across member states under the bloc's 28th regime. Commission President Ursula von der Leyen said at Davos in January that the rules would combine corporate law, insolvency, labour law and taxation into one framework. Del Maffeo stressed that regulation is not the only obstacle. Europe, he said, focuses on launching startups, and that focus needs to be balanced with scaling them. Scaling takes capital more than policy.
The numbers point the same way. Europe accounts for just 8% of the world's scaleups, against 60% in North America, and no EU-founded startup in the past 50 years has surpassed a €100bn valuation, according to The Next Web. European startups raised about $52bn (€44bn) in venture capital last year. Their US counterparts attracted $209bn (€177bn).
Peter van der Putten, director of the AI Lab and lead scientist at software firm Pegasystems, said the EU needs to become more attractive for both domestic and international investment. "Regulations could be adjusted to make it easier and more attractive for funding that's leaving the US to flow into Europe," he said. Del Maffeo's reading of Europe's industrial base was similarly mixed: leading in machine building, strong but losing traction in automotive and robotics.
Not everyone frames the answer as deregulation. Elise de Reus, co-founder of Cradle, pointed to European engineers returning from Big Tech jobs in the US, drawn by purpose-driven work and better quality of life. "We're also maybe a little bit too modest. We should measure happiness, not GDP, which is not a sustainable metric. I don't think we should copy and paste the American system," she said.
Enforcement spreads across 27 capitals
The AI Act does not stand alone. The GDPR, the Digital Services Act, the Digital Markets Act, the NIS2 Directive, the Data Act and the Cyber Resilience Act each impose distinct but overlapping duties, per GDPR Local. A model that processes personal data must satisfy both the AI Act and the GDPR. If it sits inside critical infrastructure, NIS2 cybersecurity obligations also apply. Fines reach up to 7% of global turnover under the framework as a whole. GDPR violations alone can cost up to €20 million or 4% of global annual turnover in the most serious cases.
Enforcement is layered. The European Commission provides direct oversight for the largest platforms, for gatekeeper designations under the DMA and for general-purpose AI models under the AI Act. The EU AI Office, established inside the Commission, coordinates AI Act enforcement with the AI Board, a Scientific Panel and an Advisory Forum. National regulators handle smaller entities: Digital Services Coordinators for the DSA, data protection authorities for the GDPR, national cybersecurity authorities for NIS2.
Coordination bodies including the European Data Protection Board and the NIS2 Cooperation Group are meant to keep application consistent across 27 member states. GDPR Local notes that enforcement inconsistency remains a real challenge, particularly where member states differ in transposition speed and enforcement capacity. By June 2026, all major EU digital regulations were either fully in force or in active phased implementation.
Sources
2- 01EU Tech Regulations: Compliance Deadlines and Obligations for 2026EN
- 02'Europe is not the US': Tech insiders call for smarter AI rulesEN
All figures and quotations in this text come from the sources listed below.
Content prepared by the editorial team with AI assistance.
Comments
0- No comments yet — be the first.