Simplifying the European Union AI Act: A Strategic Retreat or Smarter Regulation?
- Author
- Published on
Summary
The EU’s Digital Omnibus on AI postpones key high-risk obligations while strengthening the European AI Office and adding new safeguards. The reform responds to incomplete standards and growing competitiveness pressures, but delay is defensible only if it produces workable guidance, adequately resource enforcement and lower unnecessary burdens without weakening fundamental-rights protection. Its implementation will determine whether simplification becomes regulatory pragmatism or strategic retreat.
The European Union’s Artificial Intelligence Act was designed to prove that technological innovation and fundamental-rights protection need not be competing goals. Adopted in 2024, it created the world’s first comprehensive horizontal legal framework for AI and imposed its strictest obligations on systems used in sensitive areas such as employment, education, essential services, law enforcement and biometric identification.
Yet before many of those high-risk obligations became applicable, the EU changed course. On 29 June 2026, the Council gave final approval to the Digital Omnibus on AI. The revised timetable moves the application of requirements for stand-alone high-risk systems to 2 December 2027 and for high-risk systems embedded in regulated products to 2 August 2028.
This is a major postponement, but it is not a suspension of the AI Act. Rules on prohibited practices and AI literacy have already taken effect, as have governance provisions and obligations for general-purpose AI models. The Omnibus also introduces new prohibitions on AI-generated non-consensual intimate material and child sexual abuse material. It therefore combines delay and simplification with additional safeguards.
The package also strengthens the European AI Office. Within its jurisdiction, the Office gains market-surveillance powers, including the ability to request information, investigate providers, conduct inspections, require corrective action and impose fines. The reform therefore changes the sequencing and institutional organisation of regulation more than it dismantles the Act’s risk-based structure.
The case for this regulatory reset begins with a practical problem: implementation readiness. The original timetable assumed that harmonised standards, commission guidance and conformity-assessment procedures would be available before the high-risk obligations applied. That assumption proved too optimistic. Without common technical specifications, firms would have faced uncertainty over how to translate broad duties on risk management, data governance, human oversight, accuracy and cybersecurity into concrete compliance procedures.
Postponement therefore has a defensible regulatory logic. Applying technically demanding rules before regulators and regulated firms possess common interpretive tools can produce fragmented national practices, defensive paperwork and legal uncertainty rather than meaningful risk reduction.
But the Omnibus is not merely a technical correction. It reflects a wider political shift towards competitiveness. Mario Draghi’s report on the future of European competitiveness showed the scale of the challenge: EU companies invested about EUR 270 billion less in research and innovation than their US counterparts in 2021, around 70 per cent of foundational AI models developed since 2017 originated in the United States, and EU firms received only about 6 per cent of global AI start-up funding.
These figures do not show that the AI Act caused Europe’s technological weakness. Most of the gap predates the legislation and reflects deeper problems, including fragmented capital markets, weak research commercialisation, high energy costs and limited scale-up finance. Yet the report helped establish a political narrative in which regulatory complexity became one part of Europe’s competitiveness problem.
That narrative was reinforced by political mobilisation. France and Germany supported a more competitiveness-oriented implementation agenda, while industry groups called for a “stop the clock” on major obligations. Consumer organisations, by contrast, warned that simplification must not weaken transparency, accountability or fundamental-rights safeguards. The large parliamentary majority for postponement showed that concern about implementation had extended well beyond the technology industry.
Against this background, the central question is not whether Europe is regulating less, but whether it is regulating better. Simplification becomes regulatory pragmatism when it removes unnecessary procedural burdens without weakening substantive protections, enforcement capacity or public accountability. On that standard, the additional time is justified only if it produces completed standards, usable guidance, predictable conformity assessments and stronger supervisory capacity.
The expanded mandate of the AI Office is therefore central. Centralisation may reduce inconsistent national enforcement and give the commission greater leverage over AI systems deployed across several member states. But broader powers will matter only if the Office receives sufficient staff, technical expertise and financial resources. Otherwise, the reform could replace fragmented national enforcement with a bottleneck at the European level.
The same applies to support for smaller firms. Extending selected proportionality and innovation measures to small and mid-cap companies may prevent fixed compliance costs from favouring only the largest technology companies. But proportionality cannot become a blanket exemption from safeguards, especially where AI systems affect employment, education, credit or access to public services.
The success of the Omnibus should therefore be judged through observable outcomes. Are harmonised standards completed on time? Do conformity assessments become faster and more predictable? Does the AI Office conduct credible investigations and enforcement actions? Do companies face less duplicative documentation without abandoning substantive risk controls? And do individuals retain meaningful routes to explanation, complaint and redress? If the answer is yes, postponement may strengthen the AI Act by making it more implementable. If obligations are repeatedly delayed while standards remain unfinished and enforcement remains under-resourced, simplification will become strategic retreat.
The answer will also shape Europe’s influence beyond its borders. The AI Act applies in specified circumstances to providers and deployers outside the EU when their systems or outputs are used within the Union. Access to the single market can therefore encourage multinational companies to incorporate European requirements into products and governance systems used elsewhere.
This is the logic of the Brussels Effect: firms may adopt EU rules more broadly when maintaining separate production, documentation or compliance systems is too costly. But the global diffusion of the AI Act should not be confused automatically with the diffusion of European values. Companies can reproduce documentation and conformity procedures without delivering equivalent protections for democracy, the rule of law or fundamental rights.
A stronger form of European influence would depend less on other governments copying the full text of the AI Act and more on whether European governance tools prove workable. Credible technical standards, consistent enforcement, interoperable testing methods and practical risk-management templates may travel more easily than an entire legislative architecture.
Conclusion
Whether those governance tools travel will depend first on whether they work at home. The Omnibus is therefore a high-stakes test. If the EU uses the delay to build effective institutions and usable standards, it may create a more durable model of regulatory influence. If implementation remains uneven, Europe risks exporting compliance paperwork rather than credible governance.
The future of AI governance will not be determined by which jurisdiction writes the longest or strictest law. It will be determined by which can build a system that is legitimate, enforceable, adaptable and capable of supporting innovation without transferring its risks to society.
Disclaimer: Views expressed are of the author(s) and do not necessarily reflect the views of The Statecraft Institute.

