August 9, 2026 · AI

Brussels Enforced the Cheap Half of Its AI Law and Delayed the Expensive Half

The EU just told you, through its own actions, which of its AI rules were worth the price and which ones were not.

On August 2, the European Commission started enforcing new transparency rules under its AI Act. Chatbots now have to say they are chatbots. AI generated images, audio, and video need a machine readable label. Companies using emotion recognition or biometric categorization have to tell people first. Miss it, and the fine runs up to 15 million euros, about 17.3 million dollars, or 3 percent of worldwide revenue, whichever is bigger, according to Cooley's rundown of the deadline and Al Jazeera's coverage of the rollout.

The same week, a much bigger set of obligations under the same law quietly did not take effect. The AI Act's "high risk" requirements, covering hiring tools, credit scoring, education assessment, biometric surveillance, and migration and asylum systems, were supposed to start applying this August too. Instead they were pushed to December 2027 for standalone systems and August 2028 for AI embedded in other products, per Al Jazeera's reporting.

That split is the story. Brussels enforced the rule that costs a company a disclosure banner and a label. It delayed the rule requiring bias audits, conformity assessments, and a documented paper trail, once it saw what that second rule actually cost. The Act's own author just field tested it and found half of it too expensive to run on schedule.

The people who wanted the high risk timeline to hold have a real case, and it deserves a straight answer, not a strawman. Hiring screens, credit scores, and border decisions are not toys. Get one wrong and a real person loses a job, a loan, or an asylum claim, often with no clear way to know an algorithm made the call. Stefi Richani of the Equinox Initiative for Racial Justice told Al Jazeera that delaying the Act's migration safeguards "will increase surveillance and discrimination." The consumer group BEUC opposed the wider package too, arguing it opened the door to harms the law was meant to close, per IAPP. If the case for this kind of regulation is strong anywhere, it is here, where the people affected by a bad decision usually cannot sue, switch vendors, or opt out.

The answer to that case is not that the harms are made up. It is that the EU priced the safeguard without checking who could pay it. A survey of European tech founders by the Computer and Communications Industry Association, reported in July, found 79 percent had been hit by regulatory friction in the prior year, roughly a quarter had already spent more than 30 percent of their budget on compliance, and 24 percent were considering or had already moved their headquarters over it. One compliance consultancy, Wavect, put a rough number on that friction: a small team building a limited risk product like a customer facing chatbot should expect to spend 15,000 to 31,000 euros in year one on legal review and monitoring. Cross into high risk territory, a hiring or credit tool, and that jumps to 46,500 to 94,000 euros in year one, with 30 to 50 percent recurring annually. That is one firm's estimate, not an audited average, but it tracks with what founders in the CCIA survey reported about their own budgets.

Run that cost against revenue and you see who it falls on. A five person startup building a hiring screening tool eats close to six figures before its first euro of high risk revenue. Microsoft or Workday spreads the identical paperwork over billions and barely notices. The rule applies to both equally. It does not land on both equally. That is the mechanism free market critics of heavy compliance regimes keep pointing to: rules sized against a worst case, without pricing the cost against who can pay it, protect large incumbents from competition more than they protect the public from harm. Germany's Chancellor Friedrich Merz said close to the quiet part out loud ahead of the delay, publicly pushing Brussels to ease the load on industrial AI, per IAPP. The Commission did not change course because the harms stopped mattering. It moved because the bill came due faster than the safeguards could be justified, and by the time it moved, a chunk of that 24 percent had already left.

If your business touches the EU, even by accident, a signup page open to the world counts, the part that is live now is cheap and not optional. Say your chatbot is a bot. Label synthetic media. Disclose biometric tools before you use them, regardless of your size. The high risk category is where the real decision sits: December 2027 for a standalone product is real runway, not a free pass. Use it to build your documentation trail as you ship, not after a regulator asks for it, because the delay bought time, not an exemption.

Most of the AI features I help clients ship start as a good idea and a working demo, and only later run into a question like whether it counts as biometric categorization or needs a disclosure banner. Answering that before you build is cheaper than retrofitting it later. If you are shipping AI features that could touch EU users, that is worth a conversation before you ship.

Sources

Every factual claim above is drawn from these independently published sources, linked inline where first referenced.

Let's talk

Tell us what's on your mind.

You don't need a polished brief to reach out. A two-line email about what's bugging you is plenty; we'll tell you straight if we're the right fit, and what we'd tackle first.

We'll scope the work around your workflow, goals, and timeline before quoting anything, so you know what's included before committing.

LocationBoca Raton, Florida
CoverageSouth Florida + remote nationwide
Status Now accepting clients