EU AI Act: where the rules bite, and why Europe's tech sector is uneasy
The EU AI Act entered into force on 1 August 2024 as the first comprehensive legal framework for artificial intelligence anywhere. By mid-2026, its general-purpose AI obligations are the next big deadline. Fines under the bloc's digital rulebook run as high as 7% of global turnover.

The European Union has built what GDPR Local, in a June 2026 compliance guide, calls the world's most extensive digital regulatory framework. The AI Act is one layer of it. It sits alongside the GDPR, the Digital Services Act, the Digital Markets Act, the NIS2 Directive, the Data Act and the Cyber Resilience Act. Each comes with its own obligations and its own enforcement body. That matters for anyone selling into Europe.
The AI Act entered into force on 1 August 2024, making it the first comprehensive legal framework for artificial intelligence globally, according to GDPR Local's guide. Its text sorts systems into four tiers, from minimal risk to unacceptable risk, and scales obligations accordingly. A minimal-risk chatbot faces lighter transparency duties than a high-risk system used in employment screening.
What the Act actually requires
The structure is risk-based, the same logic that runs through the rest of the EU's digital rulebook. GDPR Local describes three principles cutting across the regulations. Obligations scale with company size, user reach and potential impact. Fundamental rights such as privacy, non-discrimination and transparency are protected everywhere. Market fairness provisions stop dominant platforms from shutting out competitors.
The AI Act adds its own layer. High-risk systems trigger requirements including fundamental rights impact assessments. General-purpose AI models, the category covering large foundation models, get their own set of obligations. Those GPAI rules were the next deadline on the calendar. The Next Web reported on 2 July 2025 that the European Commission was preparing to finalise its GPAI rules in July of that year, with the European Parliament then adopting its position on the standards.
Eoghan O'Neill, a senior policy officer at the Commission's AI Office, spoke at the TNW Conference in Amsterdam on 20 June 2025. "This is a big, sophisticated technology, and we want to get it right," he said, according to The Next Web. "We need specific obligations to capture some of the most impactful or potentially harmful models under the AI Act." O'Neill said the draft guidelines came from a broad code of practice group that included model providers, civil society organisations, NGOs, academics, AI safety experts, SMEs and European industrial giants.
Overlap is the point, and the problem
None of these laws operates in isolation. GDPR Local's guide gives a worked example. An AI system that processes personal data must satisfy both the AI Act and the GDPR. If it forms part of critical infrastructure, NIS2 cybersecurity obligations apply as well. For platforms, the DSA and DMA can both bite if the company meets gatekeeper thresholds.
Enforcement is split across levels. The European Commission oversees the largest platforms, DMA gatekeeper designations and general-purpose AI models under the AI Act. The EU AI Office, set up inside the Commission, coordinates AI Act enforcement and works with an AI Board, a Scientific Panel and an Advisory Forum. National regulators handle smaller entities: Digital Services Coordinators for the DSA, data protection authorities for the GDPR, national cybersecurity authorities for NIS2.
GDPR Local notes that enforcement inconsistency remains a real challenge, especially where member states differ in how fast they transpose rules and how much capacity they have to enforce them. The same guide puts the maximum GDPR fine at €20 million or 4% of global annual turnover for the most serious violations. Penalties across the framework, it says, can reach up to 7% of global turnover.
Non-EU companies face an extra step. Article 27 of the GDPR requires an EU-based representative if a company offers goods or services to EU data subjects or monitors their behaviour. Failing to appoint one carries penalties of up to €10 million or 2% of global turnover. The representative must sit in a member state where the relevant data subjects are located.
The pushback from European tech
Calls to slow the roll-out have come from some notable quarters. The Next Web reported that Swedish Prime Minister Ulf Kristersson, Bosch CEO Stefan Hartung and the lobbying group CCIA Europe, whose members include Alphabet, Meta and Apple, all pushed to postpone parts of the schedule.
Fabrizio Del Maffeo, CEO of the Netherlands-based chip company Axelera AI, framed the problem as structural rather than purely regulatory. "Europe is not the United States," he said at TNW. "We have many languages, many markets, and many regulations, both European and local. And these are stifling growth because they create borders, making it difficult for companies to expand." Del Maffeo said Axelera had signed the petition for EU Inc, a proposal for a standardised legal entity that would let startups operate across member states more easily.
Europe accounts for just 8% of the world's scaleups, compared with 60% in North America, and no EU-founded startup in the past 50 years has surpassed a €100bn valuation.
Funding is the other half of the argument. European startups raised about $52bn (€44bn) in venture capital last year, against $209bn (€177bn) for their US counterparts, according to figures cited by The Next Web. Peter van der Putten, director of the AI Lab at software firm Pegasystems, argued that regulation could be adjusted to make it more attractive for capital leaving the US to flow into Europe.
Not everyone wants a US-style approach. Elise de Reus, co-founder of Cradle, told the conference she sees European engineers returning from Big Tech jobs in the US, drawn by purpose-driven work. "We're also maybe a little bit too modest," she said. "We should measure happiness, not GDP, which is not a sustainable metric. I don't think we should copy and paste the American system."
A parallel fight over AI talent
While Brussels argues over deadlines, the companies the rules target are competing for something else: executives who can sell AI in Asian markets. Rest of World reported on 11 September 2026 that OpenAI and Anthropic are recruiting from Google, Microsoft, Amazon and Meta to build teams in countries including India and Singapore, and to strengthen engagement with policymakers.
Sandhya Devanathan, Meta's India and Southeast Asia vice president, left the company after a decade to join OpenAI as vice president for Southeast Asia and Australia, according to Rest of World. That was at least the ninth hire by a US AI giant from an American Big Tech firm in Asia in the past year. OpenAI and Anthropic did not respond to the outlet's requests for interviews with their recent hires or for comment on their Asia-Pacific hiring strategy.
The skills in demand differ from those sought in the US. "Once a company decides [a region] is a strategic growth market, you start looking for executives who can essentially operate as mini-CEOs," Deepali Vyas, global head of data and AI executive search at ZRG Partners, told Rest of World. Arjun Jaggi, an applied AI researcher and executive adviser, put the size of that pool at maybe a few hundred people across all of Big Tech India.
For European regulators, the talent question is a reminder that the rules are only one variable. GDPR Local's guide calls on companies to build compliance into technology development from the earliest stages rather than treating it as an afterthought. The Next Web's reporting suggests that for many European founders, the more urgent complaint is not the rules themselves but the capital and market fragmentation sitting behind them.
Sources
3- 01EU Tech Regulations: Compliance Deadlines and Obligations for 2026EN
- 02'Europe is not the US': Tech insiders call for smarter AI rulesEN
- 03The AI talent war is coming for Big Tech's Asia executivesEN
All figures and quotations in this text come from the sources listed below.
Content prepared by the editorial team with AI assistance.
Comments
0- No comments yet — be the first.