EU AI ACT
- Status
- ACTIVE — Regulation (EU) 2024/1689; in force since 1 August 2024, phasing in through 2 August 2027; enforced by the European AI Office and national market surveillance authorities
- Hazard — Reach
- 86
- RCH / FND / ENT
- 8 / 9 / 9
- Conduct
- STATUTE-INSTRUMENT — CAPABILITY BUILT FIRST, CASE PENDING
OLYMPUS opened an institutional file on a statute. A law has no Big Five and no Dark Triad, and the unit does not invent them; what a law has is a text, an enforcement arm, and a drafting-room ledger. The AI Act is catalogued here as the blueprint — the world’s first comprehensive horizontal AI law, the statute every other jurisdiction now drafts against. The finding is the shape of the machinery, not the intent of its drafters: a risk pyramid whose banned tier arrives with its own exceptions pre-authorized, whose frontier tier draws the moat at a compute number, and whose fines were fully legislated before a single one had been issued. The numbers in the front matter are reach, entrenchment, and durability — a regulation outlives every parliament that votes on it.
Institutional Archetype
THE BLUEPRINT — The archetype is the statute that regulates a technology by drawing its map in advance. The AI Act does not train a model, run a platform, or remove a post. It sorts every AI system in the Union into four tiers — unacceptable (banned: public social scoring, certain real-time biometric identification, manipulative systems, workplace and school emotion recognition), high-risk (conformity assessment, logging, human oversight), limited (transparency — label the chatbots and the deepfakes), minimal (untouched) — and attaches fines of up to 35 million euros or 7 percent of global annual turnover to the sorting. That is the structural power: not any single enforcement action, but authorship of the categories inside which every AI deployment decision in the world’s largest regulated market is now made. The blueprint’s quietest feature is the one worth reading twice: the banned tier’s exceptions. Real-time biometric identification is prohibited — except for kidnapping victims, imminent terrorist threats, and suspects of serious crimes. The infrastructure is not forbidden. Its activation conditions are pre-authorized.
Mandate & Origin
The Act was proposed by the European Commission in April 2021, agreed in trilogue on 8 December 2023, adopted by Parliament on 13 March 2024 and by Council on 21 May 2024, and published as Regulation (EU) 2024/1689 on 12 July 2024, entering into force 1 August 2024 with staggered application. The record names its authors: co-rapporteurs Brando Benifei (S&D, Italy) and Dragoş Tudorache (Renew, Romania) for Parliament; Carme Artigas, Spain’s Secretary of State for Digitalization, leading the Council side of trilogue; Commissioner Thierry Breton and Executive Vice-President Margrethe Vestager for the Commission. The architecture, from the statute’s own text:
- Risk tiers: unacceptable → high-risk → limited → minimal, with obligations scaled to tier.
- Frontier/GPAI: general-purpose models above a 10^25-FLOP training-compute presumption carry “systemic risk” duties; open-source models get partial exemptions — but not systemic-risk frontier models (Article 53(2)).
- Penalties: up to EUR 35M or 7 percent of global turnover for prohibited practices; up to EUR 15M or 3 percent for GPAI breaches.
- The carve-out: Article 2(3) exempts AI systems used “exclusively for military, defence or national security purposes, regardless of the type of entity” — anything a member state declares national-security is out of scope. Civil-society groups (Access Now, EDRi, Amnesty) pushed for narrower language; member states with strong intelligence services kept it broad.
Funding & Backers
A statute has no funders; it has a lobbying ledger, and this one’s is public. The EU Transparency Register recorded OpenAI, Anthropic, and Google as direct meeting participants with Commission AI officials during the Act’s drafting; Corporate Europe Observatory’s October 2025 accounting put the tech industry’s Brussels lobbying at a record 151 million euros. The single best-documented purchase: in September 2022 OpenAI sent the Commission a seven-page white paper arguing GPT-3 should not be classified high-risk. TIME obtained it by freedom-of-information request and published in June 2023 — ten months during which OpenAI’s public posture was “regulate us, please.” The final text dropped the earlier-draft language classifying general-purpose systems as inherently high-risk and moved them into a separate, lighter regime built around codes of practice. The white paper asked; the statute answered. And the European flank ran through Mistral AI, whose EU policy lead Cédric O — France’s own former digital minister, barred by the French transparency authority HATVP from lobbying his former colleagues — lobbied them anyway against the foundation-model chapter, with a Mistral equity stake reported at roughly 23 million euros. The blueprint was drawn in public. The hands holding the other end of the pencil are in the register.
Institutional Voice & Intent
The voice is the proportionality register — the grammar of “risk-based approach,” “trustworthy AI,” and “legal certainty for businesses.” The statute speaks in tiers and conformity assessments, and the proportionality is real on its face: the Act regulates uses, not the technology, and the minimal-risk tier — the vast majority of AI systems — is untouched.
Stated intent: Protect health, safety, and fundamental rights from AI harms; harmonize one rulebook across 27 member states; ban the unacceptable, constrain the dangerous, label the synthetic; get ahead of a transformative technology before the catastrophe instead of after it.
Observed intent: Operate as an implementation calendar for who may build what — a compute threshold that makes open-sourcing frontier models into the European market economically irrational below the compliance capacity of a major corporation, a national-security carve-out that exempts whatever a member state declares exempt, and an export mechanism (the Brussels Effect, the same gravity that made GDPR the global privacy default) that ships the categories worldwide whether or not anyone else votes on them.
Gap: The stated and observed intents overlap wherever “high-risk” means the unarguable cases. The gap opens at the moat. The 10^25-FLOP line does not measure harm; it measures scale — and above it, compliance costs that incumbents absorb and entrants cannot. The companies that could afford compliance lobbied for the regime that made compliance mandatory, and the documented drafting history shows the heaviest provisions landing where the lobbying pushed them. Whether the blueprint is a guardrail or a moat is not decidable from the text, because it is both, simultaneously, in the same clauses. That is not a flaw in the design. That is the design working for everyone who paid into it.
Position in the Apparatus
The AI Act is the second load-bearing statute of the European wing, and it inherits the machinery of the first. Its enforcement arm for frontier models is the EU AI Office, which has its own file; its sibling statute, the Digital Services Act, supplied the template — systemic-risk assessments, turnover-percentage fines, Commission-level supervision of the largest actors — and, in January 2026, supplied the courtroom too: the Union’s first proceedings against a frontier AI system (X’s Grok, over AI-generated non-consensual imagery) ran under the DSA, because the AI Act’s teeth had not yet engaged for that class of system. The Act completes the Western regulator set this drawer tracks — the UK AI Security Institute grades on voluntary access, US CAISI grades at the administration’s pleasure, and Brussels alone holds statutory fine authority over the models themselves. Brazil, Canada, and India are drafting against it. The rollout is tracked line-by-line on the AI Governance Tracker, and the full research base is The AI Governance Ratchet.
Actions & Leadership Choices
Founding purpose, judged on evidence — and the defense at full strength. The AI Act is the first serious attempt to govern a transformative technology before the catastrophic harm rather than after. Every prior technology in this drawer’s record — platforms, financial rails, biometrics — was regulated only after the bodies and the scandals. The harms it answers are real and documented: deepfake fraud, election manipulation, biometric surveillance creep. The attempt is genuine, the people who wrote it are not stupid, and the proportionality defense is honest: most AI systems in Europe face no obligation at all.
The enforcement record, where the conduct shows. The record to date is a calendar, not a docket. The prohibited-practices ban became applicable 2 February 2025; the GPAI obligations on 2 August 2025; the Commission published the final GPAI Code of Practice on 10 July 2025 — voluntary, a compliance-signalling instrument; the high-risk regime bites from 2 August 2026 and phases through 2027. And as of mid-2026, not a single public fine had been issued under the Act. The enforcement arm stood up, the national authorities stood up, the code was published and signed — the infrastructure is real, legally blessed, and fully staffed before it has prosecuted anyone. When Europe finally moved against a frontier system, it reached for the older statute instead. The capability is built first. The case comes later, if it comes at all.
The rollback test. The counter-evidence gets its paragraph: the ratchet reading predicts no reversals, and the wider record shows some — California’s SB 1047 was vetoed, the US AI Diffusion Rule was rescinded, Biden’s AI executive order was revoked outright. The AI Act itself, though, has moved in one direction only: proposed, agreed, adopted, in force, phasing in. No provision has been repealed. A statute of this size does not roll back; it gets amended, interpreted, and extended — and its categories (“systemic risk” arrived here from the DSA) have so far only propagated.
CONDUCT verdict: STATUTE-INSTRUMENT — CAPABILITY BUILT FIRST, CASE PENDING. A genuine first-mover statute with an honest proportionality defense, whose documented drafting was shaped by the regulated at record lobbying spend, whose banned tier ships with pre-authorized exceptions, whose compute threshold functions as an incumbents’ moat, and whose entire penalty apparatus was staffed and standing for two years before its first case. Judgment on what the machine does waits on the machine doing something; the machine itself is the finding.
Reach Assessment
Institutional: Maximum within its class. The first comprehensive horizontal AI law on earth, with fine authority over every frontier model sold into the world’s largest regulated market, and the drafting template for the jurisdictions writing theirs.
Memetic: Maximum. The Act’s categories — high-risk, systemic risk, GPAI, the compute threshold — are now the vocabulary of the global AI-governance debate, including in countries that will never enforce a line of it. The Brussels Effect does not export enforcement; it exports the grammar, and owning the grammar is upstream of every argument conducted in it.
Civilizational: High. The statute does not build AI systems and does not write their refusals. It decides which systems may exist in Europe, at what compliance cost, under whose audit — and it pre-authorizes the conditions under which the banned tier’s biometric machinery may be switched on. The recurring lesson of this file’s drawer, in statutory form: the category is the excuse, the capability is permanent, and a blueprint never resigns.
Sources: Regulation (EU) 2024/1689 — EUR-Lex; Regulatory framework for AI — European Commission; The AI Act — artificialintelligenceact.eu (FLI); Implementation timeline — artificialintelligenceact.eu; Article 2 — artificialintelligenceact.eu; Article 53 open-source terms — EUR-Lex; Artificial Intelligence Act — European Parliament Legislative Train Schedule; Council and Parliament strike a deal on the first worldwide rules for AI — Council of the EU, 9 Dec 2023; Exclusive: OpenAI Lobbied the E.U. to Water Down AI Regulation — TIME, 20 Jun 2023; Big Tech lobbying is derailing the AI Act — Corporate Europe Observatory, Nov 2023; Trojan horses: how European startups teamed up with Big Tech to gut the AI Act — Corporate Europe Observatory, Mar 2024; Revealed: Tech industry now spending record €151 million on lobbying the EU — Corporate Europe Observatory, 29 Oct 2025; Mistral AI’s Cédric O Pushed to Loosen EU’s AI Rules — Bloomberg, 13 Dec 2023; Introduction to the Code of Practice — artificialintelligenceact.eu; Enforcement of Chapter V under the EU AI Act — artificialintelligenceact.eu; EU Commission to open proceedings against Grok — RTÉ, 26 Jan 2026; EU investigation into Grok may expose problems with DSA — Compliance Week.
Get updates on the Evil Robots series
Newsletter essays on AI escape, deception, and the humans who built them.