Why European Regulation Is More Predictable Than It Looks
By Rita Dienes, Esq., CIPP/E, AIGP
This summer Europe amended its flagship AI law, the EU AI Act, by passing the so-called EU Digital Omnibus package on AI. As we speak, the EU Digital Omnibus on AI is expected to enter into force any day during the second half of July, 2026 (depending on its official publication).
American companies tend to read this change as breathing room. But that reading may give a false sense of comfort and obscure the actual enforcement exposure. While the EU Digital Omnibus on AI pushed some of the EU AI Act’s hardest deadlines back by about sixteen months, the obligations that actually reach most companies – transparency and disclosure duties, that apply to nearly every AI product – will take effect on August 2, 2026.
EU-facing companies need to realize that the timing moved, but the exposure is there.
Yet the perception gap is in fact part of a bigger picture:
American companies tend to approach European regulation as an obstacle course (“Europe regulates, America innovates”) because European rules are perceived as practical red tape: dense and layered, with long timelines. “Brussels” is the notion that makes a business expansion plan pause. While that reading is understandable, it is inaccurate in a way that costs money.
The European approach is not obstruction. Instead, it is deliberation, and deliberation produces something American businesses say they want from a regulator: predictability.
The differentiator in the European approach is this: the European instinct is to assess a risk and set the rules before a technology scales, so that the ground under a business is settled by the time the business is standing on it. The alternative model is to let a market run and address the damage afterward, through enforcement and litigation, once harm has occurred and been proven. Both have a logic. But for a company trying to plan three years out, the first model is the one that lets you plan, because it tells you the rules in advance rather than discovering them in a courtroom.
This is the part that often gets obscured in the American reading of Europe. And a company or investor that takes the European regulatory and enforcement posture for mere obstruction may also fundamentally misjudge where European frameworks actually bind. It likely prepares for the wrong things when it treats the whole regime as friction to be minimized, while missing the specific places where the real, current exposure sits.
Where Enforcement Exposure Sits Right Now
All eyes now are on the EU Digital Omnibus on AI. It is making waves because it is the first change to the EU AI Act since the EU adopted it in 2024. And there is a real danger in misreading this very important piece of European legislation.
The EU AI Act is Europe’s first comprehensive law regulating artificial intelligence, sorting AI systems by how much risk they pose and piling the heaviest obligations, documentation, testing, human oversight, on the “high-risk” uses like hiring, credit scoring, and biometrics, with fines that top out higher than the GDPR’s.
The 2026 Digital Omnibus on AI pushed the EU AI Act’s hardest deadlines back:
- The obligations for standalone high-risk systems (AI tools whose main job is itself a sensitive decision, such as screening job applicants or scoring someone for credit, and where the AI system is regulated on its own, as distinct from AI built in as a safety component of a product already regulated under other EU law like medical devices or machinery) moved from August 2, 2026 to December 2, 2027.
- For product-embedded systems the date moved from August 2, 2027 to August 2, 2028.
- The EU Digital Omnibus package also trimmed lighter obligations: softening the AI literacy requirement (staff training) and extending small-company breaks to mid-sized firms.
As mentioned above, these changes many people read as relief, when they are really a change in timing, not in exposure. Businesses need to be stepping up their compliance efforts because significant regulatory exposure is untouched:
- The EU AI Act’s consequential transparency and disclosure obligations (users must be told when they interact with an AI system; AI-generated or AI-manipulated content must be labeled; deepfakes and AI-generated text published to inform the public must be disclosed if AI-generated) still apply from August 2, 2026, which is now weeks away.
- The GDPR remains the most actively enforced instrument in European technology law. It reaches any US company processing the data of people in the EU, and does so regardless of where the company sits.
There is also a mechanism inside the extension that cannot be overlooked: a high-risk system already on the market before the new dates keeps the benefit of the extension only until it is significantly changed. Retraining the model or altering what it is built to do can count as such a change (the EU AI Act’s trigger is a substantial modification, a defined term) and can remove that protection, so that once the new dates apply, a modified system loses the benefit and the full high-risk obligations attach. The extra time applies only as long as the system is untouched, which is not how product development works. A conditional deadline like this can cause a company struggling to comply to trip over more easily.
Where the Scrutiny Is Heading Next
The most useful question today is where enforcement is going, because that is what a company should be building toward. Two developments are worth considering.
The first is coordination: European supervisory authorities are increasingly cooperating rather than one EU Member State acting at a time. They coordinate joint enforcement actions on shared priorities, including transparency and disclosure obligations: duties nearly every AI product carries. Because of coordinated enforcement across the EU, an exposure found in one Member State is unlikely to stay there. And while coordinated data-protection enforcement is real and maturing, AI enforcement is building alongside it now. Consequently: when one Member State’s data-protection authority finds a problem with a company’s AI disclosure practices, the regulators are running a joint campaign on exactly that issue, so the authorities in other Member States are already looking at the same thing (a finding in France gets a company flagged to the regulators in Germany, Ireland, and elsewhere who are examining the identical question). This is how what would once have been a one-country problem becomes a multi-country problem, because the same deficiency in a product exists everywhere the company operates, and now multiple coordinating regulators are primed to investigate it.
The second is data provenance (where the training data came from and whether a company can prove it): in July the European Data Protection Board issued guidance, now open for consultation, on web scraping (automated bulk harvesting of data) to train AI, and on when data is genuinely anonymous. The European regulator sees this matter in an unambiguous way: scraping public data to train a model is regulated processing that needs a documented legal basis established before training begins, and a dataset may be considered anonymous only if a person truly cannot be singled out or re-identified. This points towards where scrutiny is moving. The question authorities are learning to ask is where the data came from and whether the company can prove it. The best practice is simply to build compliant records early, instead of trying to reconstruct them under real-time pressure.
How To Best Mitigate EU Enforcement Exposure
The European regulator offers useful notice that attentive companies can turn to their own advantage. The rules are knowable before they bind, and the enforcement priorities are visible before they are applied. The advantage goes to the company that reads the direction accurately and prepares for what is coming.
For companies with EU exposure, the practical takeaway is not to wait for the deferred deadlines. Start to map which obligations already apply and which are merely delayed, while it is still planning rather than response.
About the Author
Rita Dienes, Esq., CIPP/E, AIGP, is Counsel at Holon Law Partners.
This post is provided for informational and business development purposes only. It does not constitute legal advice or create an attorney-client relationship.
