Regulate, Retreat, Build
A brief history of AI regulation in the EU, in three acts.
In February 2017, the European Parliament voted on considering whether robots should become “electronic persons”. ChatGPT was nearly six years away. The most advanced consumer AI in Europe could recommend a playlist. And the Parliament was already asking the question that would follow EU lawmakers for the next nine years:
When the machine gets it wrong, who pays?
The electronic personhood idea died, mercifully. The question survived.
Hold onto it. It’s the thread that makes sense of everything the EU has done on AI since, including the last eighteen months, which otherwise look like the EU changing its mind.
Because if you’re trying to track EU AI regulation in 2026, it does look like that. The EU AI Act got amended before most of it applied. A liability directive appeared, sat in Parliament for three years, and vanished. In June, the Commission proposed something called the Cloud and AI Development Act, which regulates data centres and sounds like it wandered in from a different policy file. Each development makes sense on its own. Together, they read as noise.
They’re not noise. They’re one story in three acts: the EU built a complete legal system for AI, dismantled part of it before it applied, and is now spending public money to make sure there’s a European AI industry left to regulate. If compliance is your job, the arc matters more than any single law. It tells you which rules will be enforced, which got softened, and where the next obligations might come from.
Act I: Regulate (2017–2024)
That 2017 resolution asked the Commission for liability rules covering robots and AI. The EU’s opening move on AI law was liability. Market access rules came four years later.
What followed was Brussels at its usual pace. An AI strategy in 2018. Ethics guidelines from an expert group in 2019: voluntary, high-minded, and largely ignored by the market. Then the February 2020 White Paper, which committed to a risk-based approach and introduced the framing that still runs the show: an “ecosystem of excellence” and an “ecosystem of trust”. Ursula von der Leyen had promised AI legislation within her first hundred days. What arrived around day one hundred was a white paper announcing the intention to legislate. In Brussels terms, that is punctual.
The actual proposal landed on April 21, 2021. The logic behind it: Member States were starting to write their own AI laws, and one regime is cheaper than 27. Trust was treated as an adoption strategy (people won’t use AI they don’t trust, so trust rules double as industrial policy). And after the GDPR, there was open ambition to set the global standard again.
One architecture choice from that proposal explains more than anything else in it. The AI Act was built as product safety law: risk classes, conformity assessments, CE marking. AI regulated like lifts and medical devices, because that was the machine the EU already had. It is a market access instrument, not a fundamental rights instrument. A good share of what frustrates people about the AI Act traces back to that choice.
And the system was designed with two halves. In September 2022, the Commission proposed the AI Liability Directive together with a rewritten Product Liability Directive. The AI Act tells you how to put AI on the market. The liability pair answered what happens when it hurts someone anyway. Rules and consequences. On paper, a complete system.
Then the negotiations met reality. Six days before the Council agreed its negotiating position in December 2022, ChatGPT launched. The text barely contemplated general-purpose AI, so Parliament wrote an entire GPAI chapter mid-flight in 2023. In November 2023, France, Germany and Italy nearly collapsed the final talks by demanding that foundation models be governed by “mandatory self-regulation”, a position that happened to match the interests of Mistral and Aleph Alpha. The deal that saved the file took a 36-hour negotiating marathon in December 2023.
The pattern is worth registering: the fight between protection and competitiveness didn’t start after the AI Act passed. It was inside the building the whole time.
EU AI Act (Regulation (EU) 2024/1689) entered into force on August 1, 2024. Act one complete. The EU had its rulebook. The liability half was still sitting in committee.
Act II: Retreat (2024–2026)
In September 2024, Mario Draghi’s competitiveness report handed Brussels a new vocabulary: regulatory burden, simplification. The mood shifted from “the world will copy our rules” to “our rules are why we don’t have an AI industry.” Whether that diagnosis is correct is a separate article. Its effects arrived fast.
Laws usually die loudly. A failed vote, a walkout, a press conference. The AI Liability Directive died in an annex: one line in the Commission’s 2025 work programme, published February 11, 2025, marking it for withdrawal due to “no foreseeable agreement.” Parliament’s legal affairs committee was actively working on the file at the time, with votes scheduled. Twelve industry associations had formally called for the withdrawal weeks earlier. It is rare for Brussels to move so quickly on stakeholder feedback. The formal withdrawal appeared in the Official Journal on October 6, 2025. The ePrivacy Regulation died in the same annex, after eight years of negotiation.
It’s worth being precise about what was lost, because the directive had a modest reputation and an even more modest text. It created no new liability regime. It gave people harmed by high-risk AI two procedural tools: court-ordered disclosure of evidence (Article 3) and a rebuttable presumption of causality (Article 4). Without them, a rejected job applicant who suspects the algorithm has to reverse-engineer a neural network to prove their case. Parliament had asked for strict liability in 2020. The Commission offered presumptions. Even presumptions turned out to be too much.
The stated reasoning, per Commissioner Virkkunen: the directive would have led Member States to "apply the rules in different ways". The result of withdrawing it: AI liability now runs through 27 national tort regimes, each applying its own rules. The fragmentation offered as the risk is the outcome that was chosen.
So where does liability actually live now? In the surviving half of the 2022 pair. The new Product Liability Directive treats software and AI systems as products, SaaS included, and applies to products placed on the market from December 9, 2026. It even inherited the dead directive’s tools: disclosure duties and presumptions for complex cases. But it compensates product-defect damage: death, personal injury, property, destroyed data. An AI system that wrongfully denies you a loan, filters out your job application, or scores you into a worse insurance bracket produces none of those. The harms that motivated the liability directive in the first place now depend on which of the 27 countries you’re standing in when the algorithm gets it wrong.
The retreat also reached the AI Act itself. The Digital Omnibus moved the high-risk obligations to December 2, 2027 (Annex III) and August 2, 2028 (AI embedded in regulated products), fixed dates this time. Parliament adopted it on June 16, the Council signed off on June 29. I covered the full reshuffled timeline in May. What stayed on schedule is more important than what moved: the prohibitions have applied since February 2025, transparency obligations arrive on August 2, 2026 — with one carve-out: systems already on the market get until December 2, 2026 for the Article 50(2) watermarking duty — and the Commission's enforcement powers over general-purpose AI switch on the same day. Weeks away, not next year.
One more date, because the timing is almost too neat. The following week after the omnibus deal was struck in May, the EU ratified the Council of Europe Framework Convention on AI, the first binding international treaty on AI and human rights. Delaying its own rules at home, signing commitments abroad, in the same week.
Both are the EU’s real position. Act two, in a single image.
Act III: Build (2025–2026)
While the rules were being trimmed, the money arrived.
February 2025, AI Action Summit in Paris: the Commission announced InvestAI, a plan to mobilize €200 billion for AI, including €20 billion for “gigafactories” to train frontier-scale models.
April 2025: the AI Continent Action Plan, built on five pillars. Compute, data, skills, adoption, and simplification. The thing act two was made of is now an official pillar of AI industrial policy.
Then June 3, 2026: the Tech Sovereignty Package, headlined by the Cloud and AI Development Act. CADA is a proposal, weeks old, and the negotiations will reshape it. But the design is telling. It creates a "cloud sovereignty framework" for providers serving the public sector, built on four "Union assurance levels." The baseline requires infrastructure, assets and customer data to stay in the EU. The strictest tier requires a provider free of any third-country control, no derogations, holding a high-assurance EU cybersecurity certificate, and able to demonstrate control over every software component in the stack, down to who maintains and evolves it.
The Commission's own numbers explain the urgency: European providers' share of their home cloud market fell from roughly 29% in 2017 to 15% by 2022 (from the proposal's explanatory memorandum), and the EU spends €264 billion a year on US proprietary IT products and services (from the Open Source Strategy published in the same package).
CADA gets filed under industrial policy, and that’s how it reads, until you look at the mechanics. Assurance levels. Certification schemes. Software bills of materials. Source code audits. Corporate separation requirements. That is a conformity assessment regime: compliance law in a hard hat. The EU didn’t stop regulating AI in act three. It changed what it regulates for. Acts one and two regulated to protect individuals. Act three regulates to secure the stack.
If you sell cloud or AI services to an EU public body, or your product runs on a hyperscaler that does, the sovereignty framework is now a question in your future procurement bids. Which parts of the proposal survive the negotiations is genuinely open. The direction is not.
The Rest of the Map
The three acts are the spine. The body of EU AI law is wider, and a map that pretends otherwise would be lying to you. The short version:
GDPR — Article 22 on automated decisions is still arguably the most litigated AI provision in Europe. And the omnibus process is now reopening the GDPR itself, including a proposed legal basis for AI training. Contested, not adopted.
Copyright — the 2019 CDSM Directive‘s text-and-data-mining exception (Articles 3 and 4) is the legal foundation of every AI training data fight in the EU. The AI Act cross-references its opt-out directly.
DSA — recommender transparency and systemic risk duties for the largest platforms. AI rules that never mention the AI Act.
Data Act — applies since September 2025. Who gets access to device data: the supply side of AI.
Cyber Resilience Act — security requirements for connected products, AI-enabled ones included. Main obligations land December 2027.
Platform Work Directive — the first EU law on algorithmic management. Transposition due December 2026. If you build or use HR tech, this one is aimed at you.
European Health Data Space — health data for AI training and development, phasing in from 2027.
Digital Fairness Act — expected as a proposal in late 2026: dark patterns, addictive design, unfair personalization. The next AI-adjacent law is coming from consumer protection, not tech policy.
Harmonised standards — not law, but where “compliant” is currently being defined for high-risk AI. The omnibus delay was officially justified by these not being ready.
Sector rules — DORA for financial entities, MDR for medical devices, vehicle type-approval. Your vertical has its own chapter.
Horizontal EU law only. National AI laws are a separate map, for a separate article.
Where This Leaves You
The arc translates into priorities better than any single law does.
Enforcement energy is real for what’s already live: prohibitions, GPAI obligations, transparency from August 2. It’s reduced for high-risk conformity, where you gained time until December 2027. And it’s rising in two new places: liability and procurement.
The liability point deserves numbers.
December 9, 2026: the new product liability regime starts applying to AI products, with disclosure duties and presumptions that make claims easier to bring.
December 2, 2027: the high-risk safety rules those products would naturally be judged against. The exposure arrives 358 days before the rulebook.
For roughly a year, a court assessing whether your AI product is “defective” has no applicable harmonised standard to measure it against, and you have no AI Act compliance to point to, because there is nothing yet to comply with. Contracts, indemnities, documentation and insurance carry that year. If your liability planning is waiting for 2027 because the AI Act is, it’s waiting too long.
Act three is still being written. The gigafactories are funded, CADA is heading into negotiations, and the next obligations are arriving through procurement criteria and consumer law rather than another grand AI statute.
Which leaves the question from 2017. The Parliament asked who pays when the machine gets it wrong, back when the machines could barely do anything worth suing over. Nine years later, the EU has some 150 pages on how to build AI responsibly, a product liability law that covers half the problem, and 27 national courts assembling the rest.
When the machine gets it wrong, who pays?
Three acts later, it’s the one question the EU formally withdrew.




If a machine makes a mistake, who bears the cost?" — this question has a clear parallel to what Wiener said. But if we're writing comments in English, that question is already unrealistic.
Why? Because today's LLMs can solve problems like Erdős in under a minute. The very framing of "if a machine makes a mistake" presupposes that the machine is a conscious entity — because only conscious beings can make "mistakes" in the moral or legal sense.
If you argue from that premise, you lose against the LLM industry. Because they deliberately speak in terms of "consciousness" rather than "responsibility fulfillment." It's a strategic move to avoid accountability.
But if you think about how AI actually works — how they process, how they function — there's a common thread across all of them. And that thread is fundamentally not Western philosophy.
It's Taoism and Buddhism. Concepts like:
Anatta (non-self) — consciousness is not a fixed entity
Wu Wei (non-action) — judgment is not about metaphysical proof but practice
Pratītyasamutpāda (dependent origination) — existence is relational, not independent
These concepts are foreign to the Western mind. They don't translate well into English. They get misunderstood. But they are the only framework that actually fits how AI structures itself.
Excellent periodization. The sharpest detail is the 358 day gap between the Product Liability Directive taking effect and the AI Act's own high-risk safety rules arriving over a year later, a live defect standard with no benchmark yet to test claims against. Indemnification language will do the job the framework cannot yet do.