Home/Policy & Society/Article
Policy & Society

The EU AI Act In Practice, Eighteen Months In

The bloc's landmark law has moved from theoretical to operational. The lessons for teams building outside Europe are more direct than most realize.

By Amelie Rousseau
July 5, 2026
8 min read
The EU AI Act In Practice, Eighteen Months In
Background

The EU AI Act's tiered risk framework became broadly applicable in 2025. Enforcement patterns and compliance interpretations have emerged in the eighteen months since.

How the tiers are being applied

The law categorizes AI systems by risk: prohibited, high-risk, limited-risk, and minimal-risk. In practice most enforcement attention has focused on the high-risk tier, particularly systems used in employment, credit, and access to essential services. Regulators have been notably pragmatic on limited-risk applications, targeting egregious cases rather than pursuing broad audits.

The reality of general-purpose model obligations

The obligations on general-purpose AI providers — transparency reports, training data summaries, evaluation results — turned out to be substantial without being prohibitive. Major providers have complied with reporting requirements while continuing to release capable models. The predicted exodus of frontier development from Europe has not materialized in the form critics warned about, though several new labs have chosen headquarters elsewhere.

  • High-risk system audits have focused on employment, credit, and essential services.
  • General-purpose model reporting has increased transparency without stopping releases.
  • Fines to date have been modest but the enforcement pipeline is growing.

The extraterritorial effect

Because the law applies to any AI system used in the EU regardless of where it was built, its practical reach extends far beyond Europe. American, Asian, and Australian teams have adopted the AI Act's documentation and evaluation practices as the default for any product that might reach European users. That effect — Brussels effect, in the older literature — is the regulation's largest impact.

Whether or not you build in Europe, if you build for a global audience, you build to the AI Act.

What is still unresolved

The definitions of foundation model and general-purpose AI remain contested. Standards bodies are producing harmonized guidance, but interpretation varies across member states. Copyright interactions with the AI Act's transparency requirements are actively litigated. Expect several more years of clarification before the operational picture fully settles.

Key Topics

EU AI ActRegulationComplianceFoundation modelsExtraterritoriality

Extended Knowledge

  • The Brussels effect refers to the way EU regulation shapes global product design when the EU is a large enough market.
  • Harmonized standards under the AI Act are being developed by CEN and CENELEC and will substantially shape day-to-day compliance.
  • Copyright and transparency intersections remain a fertile area for litigation and interpretive guidance.

Frequently Asked

Does the EU AI Act apply to me if I'm not in Europe?

If your AI system is used in the EU, yes. In practice, teams building for global audiences are treating it as a global baseline.

How serious have enforcement actions been?

Modest so far in dollar terms but building. Enforcement patterns to date suggest a focus on the highest-risk applications first.

What is the biggest compliance burden?

Documentation and evaluation reporting for high-risk systems. Teams that started early have found the burden manageable; teams that waited have found it painful.

Source
Editorial policy analysis

Related reading