Brussels: Almost a year after the Artificial Intelligence Act entered into force, the law has stopped being an abstraction and started being a deadline. The first prohibitions, on practices such as social scoring and untargeted facial-recognition scraping, took effect in February 2025. The rules for general-purpose models, the engines behind today’s chatbots and image generators, followed that summer. The next, larger wave, covering most high-risk systems used in hiring, credit, education and critical infrastructure, lands in 2026. Each step pulls the regulation closer to the messy reality of enforcement.
At the centre of that effort sits the AI Office, a unit housed inside the Commission’s digital department and tasked with supervising the most capable systems directly. Its remit is unusual. National authorities will police most uses of AI within their borders, but the Office alone oversees the handful of foundation models judged powerful enough to pose systemic risk, those trained with computing power above a threshold the law fixes in raw arithmetic. For the first time, a European regulator is being asked to look inside the models themselves rather than only at how companies deploy them.
The instrument it leans on is the General-Purpose AI Code of Practice, a voluntary rulebook drafted with industry, academics and civil society. Signing up is meant to be the path of least resistance: firms that follow the code gain a presumption of compliance and a degree of legal certainty, while those that refuse must demonstrate conformity by other, harder means. The approach is pragmatic, but it leaves an obvious question hanging. A code negotiated with the very companies it governs risks codifying what they were already willing to do, rather than what oversight demands.
Industry has pushed back on the pace as much as the substance. Several large developers argue that obligations on transparency, copyright and systemic-risk testing arrived before the technical standards needed to meet them, leaving compliance teams to guess at moving targets. European firms, meanwhile, complain that the heaviest burdens fall on those least able to absorb them, and warn that the continent is writing rules for a technology it does not yet build at scale. That tension, between governing AI and growing it, runs through every Brussels debate on the file.
The Commission has signalled some sympathy. Talk of a broader simplification package, trimming overlapping digital reporting duties, has fuelled speculation that parts of the AI timetable could be softened or clarified. Supporters frame this as sensible housekeeping that removes duplication without touching core safeguards. Critics see the early sign of a retreat, a worry that the bloc will blink the moment its flagship law starts to bite. Both readings will be tested over the coming year.
What is no longer in doubt is that the AI Office must move from drafting to doing. It is hiring technical staff capable of auditing systems most regulators have never examined, building channels to receive incident reports, and preparing to wield fines that can reach a substantial share of global turnover. Whether it can match the resources and speed of the firms it supervises remains the open question. Europe has written the world’s most detailed rulebook for artificial intelligence. The harder task, proving it can be enforced, is only beginning, and the credibility of the entire experiment rests on getting that part right.




