Sunday, August 02, 2026

Europe Delayed Its AI Rules Because The Institutions Were Not Ready – OpEd

 
Image: Grok

August 2, 2026
By Burak Oktenli

Key Takeaways:

Governments are racing to pass AI laws while lagging in building the independent institutions needed to investigate failures, hear appeals, and enforce corrections.

Accountability requires more than rules or transparency: it needs named forums with authority to demand explanations, evaluate systems against standards, and impose real consequences.

Deployment of high-impact AI should be matched to institutional capacity—name the oversight body, design the technical interface for evidence, and limit or delay systems where no competent forum yet exists.


Governments are writing AI laws faster than they are building the bodies that can investigate failures, hear appeals and order corrections.

The European Union has just given the clearest possible demonstration of what is missing from artificial intelligence governance, and it did so by accident. Under the Digital Omnibus signed in July, the bloc deferred the core obligations of its AI Act for high-risk systems from Aug. 2, 2026, to Dec. 2, 2027, with systems embedded in regulated products pushed to 2028. The reason was not a change of heart about the rules. Member states had been slow to designate the national authorities that would enforce them, and the harmonized standards and conformity assessment tools that high-risk compliance depends on were unfinished. Regulators found themselves demanding conformity against benchmarks that did not yet exist.

The rules were ready. The institutions were not. What does take effect on Aug. 2 is the transparency regime under Article 50: disclosure when a person is interacting with an AI system, marking of synthetic content, labeling of deepfakes. Those duties matter. But notice which part survived and which part slipped. The obligations that require someone to inspect, evaluate and judge a system are the ones that moved.

We speak about accountability as though it were a property that can be added to a model through better documentation or a compliance checklist, when it is in fact a relationship. Someone must be required to explain a consequential decision to a body that can question the explanation, judge it against a standard and attach consequences. Without that body, a decision can be transparent, tested and formally compliant while remaining practically unaccountable. The person denied a loan, screened out of a job, flagged at a border or harmed by a clinical recommendation may know that AI was involved and still have nowhere competent to challenge the result.

What happens when there is no forum


Australia has already run this experiment. Between 2016 and 2019 the government operated an automated welfare debt recovery scheme, known as Robodebt, that used income averaging to calculate debts and shifted the burden of disproving them onto recipients. It recovered roughly 1.76 billion Australian dollars in debts later found to be unlawfully raised. The rules were in place throughout, ministers had legal advice, and complaints came continuously from recipients, caseworkers, community legal centers and journalists.

What did not exist was a body able to compel the evidence, evaluate the method against a standard and order the scheme stopped. The ordinary machinery of oversight, including the ombudsman and the administrative appeals system, did not arrest it. Undoing it took a Federal Court case, a class action and finally a royal commission, whose 2023 report described the scheme as neither fair nor legal. Repayment and compensation has since passed 2.4 billion Australian dollars, and the human cost was far heavier than the financial one. That is what it costs to discover, four years late, that nobody had the standing to ask the right question.

Rules do not create accountability

Europe is at least building the machinery. The AI Office, national competent authorities and an AI Act Service Desk are early components of a real enforcement system. But the deferral shows how far that construction still must go. The Act will be judged less by the number of articles in the statute than by whether those bodies have the expertise, independence, resources and access to evidence to act before harm becomes routine.

The same test applies in the United States, where the policy emphasis is different. The federal approach set out in America’s AI Action Plan prioritizes adoption, competition, infrastructure and leadership. Office of Management and Budget memoranda M-25-21 and M-25-22 revised federal AI use and procurement policy and gave agency chief AI officers a central role in promoting adoption while managing higher-impact uses. Those are governance arrangements, not merely rules. But an officer expected to accelerate deployment, manage risk, advise on spending and investigate failure faces conflicting mandates unless independent review and appeal sit with someone else.

The Pentagon offers a useful partial model. The Department of Defense moved past broad principles by standing up the Chief Digital and Artificial Intelligence Office, publishing a responsible AI toolkit and tying autonomous weapons policy to testing, human judgment and lifecycle governance. Directive 3000.09 matters not because it contains a perfect rule but because it links policy to organizations, engineering practice, review processes and named accountable operators. Principles become governance only when an institution can perform them.

Build the forum, not just the framework

Every high-impact AI deployment should be matched, before deployment, with a named institutional forum. That forum may be a regulator, a court, an inspector general, a certification body, a professional board or a specialized internal review authority. Its form will vary by sector. Its functions should not.

It must be able to demand an explanation, which takes more than a vendor statement that a model is proprietary. That means lawful access to system documentation, data provenance, evaluation results, incident records, model versions and the human decisions surrounding the system. It must be able to evaluate the decision against an articulated standard, which takes technical competence and independence, because no general-purpose compliance office can meaningfully review a diagnostic model, an autonomous targeting function and a hiring system with the same undifferentiated checklist. And it must be able to impose a consequence: pause a system, require a rollback, order revalidation, notify affected people, provide recourse and escalate repeated failures. An accountability process that ends in a report is not enough.

These functions have to be supported by the technology itself: audit trails, version control, provenance records, preserved evaluation evidence, appeal pathways and reliable correction mechanisms. Designing that interface between an AI system and the institutions expected to govern it is an engineering task, and it is currently nobody’s job.

Three tests for institutional readiness


Policymakers can turn this into a deployment test with three questions.

Name the forum. Before a high-impact system goes live, identify the body that will receive complaints, compel evidence, evaluate failures and order remediation. The vendor, the agency and the market are not sufficient answers.

Design the interface. Require the system to produce the evidence that forum needs. If a deployment cannot preserve an audit trail, distinguish model versions, reconstruct a consequential decision or support correction, it is not ready for accountable use.

Match deployment speed to institutional capacity. Where no competent forum exists, deployment should be limited, staged or delayed. No institution, no deployment should be the default for uses that affect liberty, livelihood, health or access to essential services.

Critics will call this a brake on innovation, but the opposite is more likely. Ungovernable systems create hidden liabilities, public distrust, emergency bans and political backlash, and Europe has just spent sixteen months of regulatory runway learning that lesson. Institutions that can investigate failure and correct it are infrastructure for durable adoption, in the same way that certification and incident investigation are infrastructure for aviation, medicine and nuclear power.

Europe’s rights-based regime, America’s innovation-led strategy and the Pentagon’s mission-driven approach differ in philosophy and purpose. All three face the same practical question: when an AI system causes a consequential error, who has the knowledge, authority and technical access to make it answerable? The next phase of AI governance should be judged by that answer. We do not lack principles, frameworks or policy announcements. We lack institutions capable of turning them into explanation, judgment, recourse and correction. AI accountability will not emerge from better models or longer statutes. It has to be built.




About Burak Oktenli

Burak Oktenli holds an MBA and a Master of Professional Studies in Applied Intelligence from Georgetown University. His research addresses the governance of authority in autonomous and AI-enabled systems, and his writing has appeared at the Modern War Institute at West Point, RUSI, RealClearDefense, RealClearMarkets, and Geopolitical Monitor. He is the author of Authority Architectures for Autonomous Systems, a ten-volume series on how authority in autonomous systems is delegated, monitored and recovered, at authority-architecture.me.
View all posts by Burak Oktenli →


EU rules on AI models become enforceable. What's going to change?

The ChatGPT app is displayed on an iPhone in New York, May 18, 2023.
Copyright AP Photo/Richard Drew
By Luca Bertuzzi
Published on

EU AI Act rules on AI models become enforceable today, making Brussels the world's top AI regulator. Euronews breaks down what this all means for Europe and beyond.

As of today, the EU's rules on AI models become enforceable, cementing the European Commission's role as the world's most prominent regulator of this disruptive technology. Euronews takes a deep dive into what the rules mean for Europe and beyond.

The AI Act is the first comprehensive law regulating artificial intelligence. Passed in 2024, some of its most significant provisions — notably those regulating large language models — become applicable this August.

As the law introduces first-of-its-kind rules, enforcing them presents a unique set of challenges, not least because new generations of AI technology emerge every few months. Brussels' experience is likely to resonate well beyond Europe's borders.

What are the rules about?

Initially, the AI Act was only meant to regulate AI applications. But when the public launch of ChatGPT took the world by storm in 2022, EU policymakers decided also to cover the underlying technology: large language models.

The rulebook sets out rules for all models that lack a specific purpose but can be adapted to a variety of use cases, requiring transparency on how a model was built, disclosure of any copyright-protected content used for training, and enough information for downstream users to understand the model's capabilities.

Additional requirements fall on companies developing the most powerful "frontier" models — those pushing the boundaries of the technology — compelling AI firms to identify and mitigate risks to society at large.

Last year, the Commission endorsed a voluntary code of practice drafted by world-leading experts, including Yoshua Bengio, detailing how developers should comply with the rules. Most leading Western AI labs, with the notable exception of Meta, signed the code.

"We've collaborated closely with the European Commission and the wider ecosystem on implementing the AI Act, including its Codes of Practice, and will continue working together to help Europe realise the benefits of the Intelligence Age," Tom Duff Gordon, OpenAI's Vice President and Head of EMEA Policy, told Euronews.

What challenges lie ahead?

The Commission set up the European AI Office to drive enforcement of the AI Act's rules on AI models. The task is enormous, taking on one of the most complex technologies of our time and some of the richest companies in the world.

The EU's resources are knowingly limited, and AI talent is in high demand, with public authorities competing with the private sector. The Commission is therefore seeking to tap into external expertise, namely a panel of scientists and a pool of highly specialised AI safety firms.

Still, AI in general, and frontier models in particular, remain a moving target: officials will have to keep pace with fast-moving technological developments without much prior experience or scientific consensus on how to prevent harm at scale.

At the same time, any decisive action from Brussels in this area is bound to draw the attention, if not the ire, of Washington, with the Trump administration particularly assertive in attacking the EU's digital rules when they affect American companies.

"The danger is that the current US administration treats this as an attack on US commercial interests, as it did when the Commission sought to implement its digital markets' rules in December 2025 and more recently this month when it sought to fine Google under the EU's Digital Markets Act," MEP Michael McNamara (Ireland/Renew) told Euronews.

What does it mean for Europeans?

The AI Act's core purpose is to make technology safer for European citizens, ensuring it does not harm their safety and fundamental rights. As such, it also applies to foreign companies that commercialise their AI technologies in the EU.

The industry has repeatedly attacked the law, arguing that it will slow innovation by placing an unnecessary burden on tech companies, forcing them to divert money from hiring engineers to hiring lawyers to handle the paperwork.

In practice, for European consumers and businesses, that might mean some of the most advanced AI models launch in the EU a few weeks later than in other markets, as firms ensure they have done their compliance homework.

Still, it will also mean that, at least in theory, Europeans can trust that if an AI model is available in the EU, it is safe to use. Given how embedded AI is becoming in everyday products and services, that time lag might be worth it.

MEP Axel Voss (Germany/EPP) called on the Commission to enforce the AI Act in close alignment with other digital issues, since AI technologies are increasingly embedded in connected products and online services.

"Taking the AI Office's lack of capacities into account, I very much hope that they do not waste their energy on niche concerns but instead align strongly with the priorities of their platform regulation colleagues," Voss told Euronews.

Is the EU setting the benchmark?

As the Commission has become the world's most prominent AI regulator, it will inevitably set the benchmark for how public authorities approach the technology, especially since other jurisdictions have taken a more wait-and-see approach.

That is why the enforcement priorities the AI Office sets for itself are bound to have an impact well beyond Europe's borders — not to mention the so-called "Brussels effect," the EU's capacity to set compliance standards for global companies.

There are two main schools of thought on the main risks AI regulation should address. The AI ethics tradition focuses on fundamental rights violations, such as discrimination and privacy, and the need to ensure human oversight.

Effective altruism, by contrast, emphasises so-called existential risks: the possibility that AI could cause catastrophic harm by helping build nuclear or biological weapons, enabling massive cyberattacks, or escaping human control altogether.

Recent episodes — Anthropic's Mythos-based model being pulled under US export control restrictions over concerns about its cyber capabilities, and an OpenAI AI agent hacking into an AI firm during testing — might push the Commission to focus its scarce resources solely on existential risk scenarios.

"The Commission must resist the temptation to devote its enforcement resources solely to cyber-offence and loss-of-control systemic risks," Laura Lazaro Cabrera, a director at the Center for Democracy & Technology, told Euronews.

"Enforcement should not be headline-driven, but should address the full spectrum of risks and ask whether fundamental rights and societal risks have been adequately considered," she said.



AI-generated label becomes mandatory in the EU for companies

Professionally AI-generated content must be labelled as such starting Sunday following EU guideline implementation.
Copyright Copyright Business Wire 2026.

By Gael Camba
Published on

Companies creating or using AI-generated content have to label it clearly for users to know, as part of an EU guideline implemented on Sunday.

Deepfakes and other AI-generated content must be labelled from Sunday, as the European Union's sweeping artificial intelligence transparency rules kick in.

The goal? To make sure Europeans immediately know whether the online content they see is real or fake.

The EU's comprehensive AI law enters into force in stages. From Sunday, companies must ensure their AI systems like chatbots make it clear to users they are AI, or when an image or text has been created using AI, there must be a label saying so.

This can be done by integrating watermarks and other markers to allow the easy detection of AI-generated content. Firms face large fines if they don't comply.

The guideline also states that deployers of AI systems must inform individuals when they are exposed to:

  • Emotion recognition and biometric categorisation tools
  • Deepfakes
  • Text publications on matters of public interest without human review or editorial control

Deepfakes in focus

"Generative AI enables disinformation to be created at unprecedented scale, tailored to specific audiences, and disseminated with remarkable speed," an EU official said.

Since AI is "making it increasingly difficult for all of us to distinguish what is real from what is synthetic", the official said, the EU's rules seek to "preserve citizens' ability to trust what they see, hear, and read".

Of particular concern for the EU are deepfakes, text, images, videos and sounds that appear to be real but are generated or manipulated by AI.

The rules affect content made for professional reasons, and the EU insists individuals using AI in a purely personal capacity will not be affected.

Text that aims to inform the public on general interest issues will also have to be labelled if they are created using AI without human editorial oversight.

Existing AI systems have until 2 December 2026 to adapt to the new rules, and there are exemptions for "artistic, creative, satirical, fictional" work.

EU pressures firms

The EU has come under fire for placing more demands on businesses, and rules that will ultimately force all content to be labelled given the rapidly growing widespread use of AI across Europe.

"We have heard that it is going to be very, very difficult to implement. But I think we often hear this with compliance requirements. And yet, the world turns and we figure these things out," said Ashley Casovan of International Association of Privacy Professionals.

The world's tech giants have already begun slapping their own labels in anticipation of the rules.

For example, TikTok has required content creators to label AI-generated images, audio and video for several years, and says over three billion content items already have labels thanks to tools and detection technology.

Likewise, Meta has deployed an "AI Info" label on Instagram and Facebook for posts using the technology.

Google has signed the EU code of conduct on AI transparency, and says it is working with others like Nvidia, OpenAI and Apple on digital tagging tools.

But Google's Karen Massin warns of "regulatory complexity" that could prove counterproductive, and "risks confusing the people these rules are meant to help".

"If online content is flooded with overlapping AI labels and legal disclosures, it becomes harder for people to get the clear context they need," Massin added.



No comments: