The easiest way to dismiss the EU AI Act is to call it European bureaucracy.

More notices. More documentation. More lawyers asking questions before a product can launch.

Originally published on Substack.

That reading misses the actual problem the regulation is trying to solve.

Companies are handing more and more work to systems that can read customer records, generate campaigns, answer prospects, recommend candidates, assess applications, publish content and trigger actions on their own. Ask most of these companies a basic operational question, though, and the answer gets vague fast:

  • Who owns the system?
  • What information does it use?
  • What decisions can it influence?
  • Who checks its work?
  • Can someone override or stop it?
  • What happens when it is wrong?
  • Can the company reconstruct what happened?

The AI Act matters because it forces those questions into the open.

For European companies, this is a direct regulatory issue. For American, British, Asian or other companies going to market in Europe, it is a market access and deployment issue, whether they planned for it or not.

The goal here is not to put a human in front of every automated task. That would be slower, not safer. The goal is to know which decisions can be automated without a second look, which need monitoring, and which have to stay under a person's control.

1. The mistake: treating governance as paperwork

Most companies start an AI governance project by writing a policy.

The document says AI must be used responsibly, personal information must be protected, and important outputs must be reviewed by a human. Then it gets filed somewhere, and the actual workflows carry on exactly as before.

That is governance on paper. It changes nothing about how the system behaves on a Tuesday afternoon.

Real governance lives inside the operating process itself:

  • The chatbot identifies itself.
  • The publishing agent cannot release sensitive content without approval.
  • The human reviewer has enough information to challenge the model, not just rubber stamp it.
  • The company knows which version of the system produced the output.
  • A named person has the authority to stop the automation.
  • Errors and complaints go back to the people maintaining the system, not into a void.

This is why treating the AI Act purely as a compliance cost misses the point. Its stated purpose is to protect safety and fundamental rights while also giving companies enough legal certainty to actually adopt AI with confidence.

Poorly governed automation is not just a legal risk. It is an operational one. It can publish something false, contact the wrong customer, leak confidential information, discriminate against a candidate, or quietly run on an outdated policy for months before anyone notices.

Governance is what makes the failure visible while it is still cheap to fix.

2. What actually changes on 2 August 2026

For most ordinary businesses, the immediate change is not the full high risk AI regime. It is transparency.

Article 50 starts applying to covered systems on 2 August 2026. Depending on the use case, it requires people to be told when they are talking directly to an AI, requires machine readable marking of certain synthetic content, and requires disclosure of deepfakes and certain AI generated content touching public interest topics.

That can touch:

  • Website and WhatsApp chatbots.
  • AI customer service agents.
  • Synthetic presenters and influencers.
  • Generated or manipulated images.
  • Voice clones.
  • AI generated video testimonials.
  • Political, medical, financial or institutional content.
  • Automated systems publishing information to the public.

The Commission's Code of Practice on AI generated content is voluntary. The underlying Article 50 obligations are not. Non compliance can carry fines up to fifteen million euros or three percent of global annual turnover, whichever is greater, enforced by national market surveillance authorities.

At the same time, Brussels just moved the goalposts on the harder part. On 29 June 2026, the Council gave final approval to a Digital Omnibus that pushes back the high risk AI obligations: stand alone systems under Annex III (recruitment, credit scoring, law enforcement, education, border control) now have until 2 December 2027, and AI embedded in regulated products under Annex I, think medical devices, machinery, vehicles, until 2 August 2028.

That distinction matters and it is easy to miss if you only skim the headlines.

Not every marketing automation becomes a regulated high risk system this August. But customer facing transparency, AI literacy, the prohibited practices list, and the basic requirement to know where AI is operating in your business cannot be pushed to next year. Those apply now.

3. Europe and the United States are solving different problems

Europe chose a horizontal, risk based law. It asks companies to classify what they are doing, assign responsibility, and have evidence ready in advance, particularly anywhere AI touches safety, fundamental rights, or a decision that matters to someone's life.

The US federal picture looks nothing like that, at least not yet.

As of mid 2026, there is still no single comprehensive federal AI statute in the US that plays the same role as the AI Act. On 20 March 2026, the White House published its National Policy Framework for Artificial Intelligence, a set of legislative recommendations, not a binding law. It asks Congress to avoid creating a new federal AI regulator and instead lean on existing sector agencies and industry led standards. It also pushes for federal preemption of state AI laws seen as excessively burdensome, while carving out room for states to keep enforcing general consumer and child protection laws.

None of that means AI is unregulated in America. It means the regulation is scattered across existing law rather than gathered into one framework.

  • The FTC can and does pursue deceptive AI claims, unfair practices, and misleading marketing. Its enforcement docket already includes cases over AI chatbot claims, inflated business opportunity promises, and companies overselling what their AI can replace.
  • Federal employment discrimination law still applies when an AI system disadvantages applicants or workers.
  • Creditors using complex models still have to give specific, accurate reasons for an adverse credit decision.
  • Fair housing obligations still apply when algorithms are used for tenant screening or housing ads.

Boiled down, the US model tends to ask: did the system break an existing sectoral or consumer protection law? The European model tends to ask a question earlier in the process: before you used the system, did you classify the risk, assign responsibility, prepare oversight, and preserve evidence?

That earlier question is the one American companies usually have not had to answer at home. Building it, a governance layer that actually connects product, operations, legal, sales and deployment, is the real work of entering Europe. Not the paperwork. The wiring.

4. Why human oversight exists in the first place

"Human in the loop" gets used as a comfort phrase. A company says a human reviews the decision, so the risk is handled. Case closed.

Except a human presence does nothing if the reviewer does not understand the system, cannot see the evidence behind the output, has ten seconds to approve two hundred items, assumes the model is more accurate than it actually is, has no authority to overturn anything, is measured purely on speed, cannot stop the workflow, and, realistically, just clicks approve.

Article 14 of the AI Act asks for more than a ceremonial approval button. For high risk systems, the people overseeing them need to actually understand the system's capabilities and limits, notice when something looks wrong, resist the pull to just trust the machine, read the outputs critically, and be able to reverse or halt the system safely.

Those high risk duties themselves just got pushed back on the calendar, as covered above. The underlying logic is still worth using now, because it is really a checklist for whether oversight means anything at all.

Meaningful human control needs four things in place at once. The person needs the information to actually see the input, the output, and the uncertainty behind it. They need the competence to understand what the system does and where it breaks. They need the authority to reject, correct, reverse or stop the action, not just flag it upward. And they need the time to think, because a ten second review window is not oversight, it is theatre with a signature.

Miss any one of those four and "human in the loop" is decoration.

5. Human in the loop is not the goal everywhere

Maximum human intervention is not the target. Proportionate control is.

3 operating modes cover most of it.

Diagram comparing three levels of human control in AI workflows: human in the loop, human on the loop, and human out of the loop, with consequence, reversibility, and typical use cases for each.

Human in the loop

The AI drafts a recommendation. A person has to sign off before anything happens. This fits situations that are consequential, hard to undo, or heavily dependent on context that only a human can weigh.

Think: rejecting a job candidate, denying credit or housing or insurance, terminating an employee or a customer account, publishing anything political or health related or tied to a crisis, sending a legally binding offer, using a cloned voice or a realistic synthetic identity, making a public accusation, or acting on an uncertain identity match.

The human is not there to redo the model's math. They are there to bring context the model never had.

Human on the loop

The system runs on its own, but a person watches performance, reviews exceptions, and can step in or shut it down. This works for customer service agents handling common questions, lead qualification, ad optimisation, product recommendations, content scheduling, fraud alerts, CRM enrichment, translation, and large scale document classification.

The system moves faster than a person could. That speed only stays safe with thresholds, alerts, sampling, and a real rollback plan sitting underneath it.

Human out of the loop

The system just runs. This is fine for low consequence, reversible, well understood tasks: formatting internal documents, deduplicating records, tagging files that carry no sensitive information, transcribing meetings, drafting internal first passes, resizing images, sorting support tickets without resolving them, or producing internal summaries that carry no formal weight.

Even here, somebody still owns it, tests it occasionally, and checks in on it. Low risk is not the same as no maintenance.

NIST's voluntary AI Risk Management Framework lands on a similar conclusion through its Govern function: define responsibilities for how humans and AI work together, keep an inventory, document risks, monitor systems, and keep accountability traceable across the whole lifecycle, from onboarding a system to eventually retiring it.

6. The AI Act reaches well past "AI companies"

The AI Act is horizontal legislation. What matters is not the label on the company. What matters is the purpose and consequence of the specific system.

A hospital can run a low risk grammar assistant. A marketing agency can run a high consequence biometric system. A bank can use AI purely to sort emails. A retailer can deploy a synthetic spokesperson that customers genuinely believe is human.

Meaningful exposure shows up across marketing and advertising, SaaS, ecommerce and retail, media and creator platforms, recruitment and HR, financial services and fintech, insurance, healthcare, education, housing and real estate, travel and hospitality, government services, political communication, and biometric security.

The questions that matter differ by industry. A marketing agency is mostly looking at chatbots, synthetic images, voice cloning, automated publishing, and how customer data feeds personalisation. An HR platform needs to know whether its system materially influences employment decisions. A fintech needs to know whether a customer can actually understand and contest an adverse decision. A healthcare company needs to know whether a clinician can spot the system's limits and override a bad recommendation.

The wrong question is "does our company use AI." Nearly everyone will answer yes. The useful question is where AI actually touches a person, a decision, a communication, or someone's access to an opportunity.

7. Why companies outside Europe get pulled in

The AI Act does not stop at companies incorporated in the EU. It covers providers and deployers based in third countries whenever the output of their system is used inside the European Union.

A US company can end up with European obligations even with headquarters in the States, a model hosted outside Europe, no European engineering team, and a system built originally for the American market. One European customer using the output is often enough to create the connection.

That changes how go to market planning has to work. A startup cannot treat European compliance as something to sort out after signing its first European enterprise customer. By then, product claims, data architecture, logging, model provider contracts, and automated permissions are often already locked in and expensive to unwind.

The sales process itself will surface the gap. A serious European prospect is likely to ask which AI systems are involved, which party is the provider and which is the deployer, where the customer's data actually goes, whether the customer can turn the AI feature off, whether outputs are logged, who reviews important decisions, how synthetic content gets labelled, how model changes get communicated, how incidents get investigated, and how an affected person can contest an outcome.

A company that cannot answer those questions does not just carry legal risk. It can fail procurement before the contract stage even opens.

8. Governance has to live inside the workflow

The first useful step is not a long policy document. It is a workflow audit.

For every AI enabled workflow that matters, write down the job (what work has actually been delegated), the owner (which named person answers for its performance), the inputs (what data, documents, prompts and outside sources it draws on), the output (what it produces or recommends), the permissions (can it read, draft, send, publish, modify, delete or decide), the consequence (what happens when it is wrong), the control mode (in the loop, on the loop, or out of the loop), the evidence (what logs, approvals, versions and corrections get kept), and the failure response (who can stop, reverse, investigate and repair it).

Every agent worth running should have a visible owner, a defined job, known sources, known permissions, a review cadence, and known failure modes. Skip that, and it becomes a shadow process doing real work that nobody can actually explain if asked.

AI literacy sits underneath all of this. Article 4 asks providers and deployers to make sure the people operating or using these systems have an appropriate level of AI literacy, scaled to their role, training, and the people the system actually affects.

That rules out a generic one hour slide deck for everyone. The person approving a synthetic ad campaign needs different knowledge than the person monitoring a hiring system, who needs different knowledge again than whoever is configuring the customer service agent.

9. The real opportunity here is deployment quality, not compliance theatre

Treat the AI Act bureaucratically and it will generate bureaucracy right back. Companies that collect documents, copy templates, and stand up committees without touching how their systems actually run will get exactly that: more paperwork, no safer.

Used properly, the same requirements sharpen the deployment itself. A well governed system has a clear purpose, an accountable owner, controlled permissions, human intervention where it counts, logs that hold up, a real path for complaints and corrections, evidence of what happened, and a way to actually learn when something breaks.

Those are not legal checkboxes. They are what lets a system survive contact with the real world instead of quietly rotting in production.

European companies now have an explicit obligation to make this discipline visible. American and other international companies are looking at an operating model they may not be legally required to build at home yet, but will need anyway if they want to sell into Europe and be trusted there.

Strip away the paperwork framing and the real insight underneath the AI Act is simple: automation hands out decision making power faster than most organisations are writing the rules for using it. The Act just forces the question early: what did you delegate to the machine, what responsibility did you keep, and what evidence proves the difference?

Companies that cannot answer that will feel the AI Act as friction. Companies that can will find it works more like a competitive advantage than a compliance burden.

A magnifying glass on a blue surface, by Markus Winkler.
Photo by Markus Winkler

Sources

  1. Article 50: Transparency obligations for providers and deployers of certain AI systems — European Commission AI Act Service Desk
  2. Artificial Intelligence: Council gives final green light to simplify and streamline rules — Council of the EU, 29 June 2026, confirming the Digital Omnibus delay to 2 December 2027 and 2 August 2028
  3. National Policy Framework for Artificial Intelligence: Legislative Recommendations — The White House, 20 March 2026
  4. Artificial Intelligence — Federal Trade Commission, AI enforcement docket
  5. Govern function, AI Risk Management Framework — NIST AI Resource Center