Technology

If You Can Cherry-Pick Which Codes to Sign, That's Not Regulation — That's a Menu

Summary

On August 2, 2026, the EU's AI Office officially launched enforcement of the General-Purpose AI provisions of the EU AI Act, marking the world's first comprehensive AI regulation entering its real execution phase with legal powers to demand technical documentation, conduct model evaluations, issue corrective orders, and levy financial penalties. Meta has spent over a year refusing to sign the GPAI Code of Practice — backed by roughly 26 signatories including Google, OpenAI, and Microsoft — while quietly signing the separate Code of Practice on Transparency of AI-Generated Content just five days before enforcement began on July 28, 2026, a code with 180 to 190 organizational signatories across IT, telecoms, education, and retail. This selective compliance strategy is not a sign of resistance or defiance — it is the output of a cold cost-benefit calculation, and the fact that it is entirely legal under the EU's own regulatory structure exposes a fundamental architectural flaw in how the code system was designed. The EU AI Office faces a severe institutional asymmetry: overseeing companies worth hundreds of billions in annual revenue with just over 140 staff, an annual budget of roughly €46.5 million, and two key leadership positions still unfilled. Whether the AI Act achieves genuine regulatory effectiveness will ultimately depend on whether the EU can close this capacity gap and structurally repair the voluntary code framework before cherry-picking becomes the default industry strategy — a question that GDPR and DMA precedent suggests will only be answered over the course of years, not months.

Key Points

1

Meta's Cherry-Picking Strategy: Refusing the Costly Code, Signing the Free One

Meta's approach to EU AI Act compliance is a case study in regulatory cost-benefit engineering. On July 18, 2025, Chief Global Affairs Officer Joel Kaplan formally announced on LinkedIn that Meta would not sign the GPAI Code of Practice, citing legal uncertainties and requirements that allegedly exceed the AI Act's scope. Almost exactly one year later, on July 28, 2026 — five days before AI Act enforcement officially began — Meta announced through its corporate newsroom that it had signed the separate Code of Practice on Transparency of AI-Generated Content. The two codes are not remotely equivalent in what they ask. The GPAI Code carries heavy obligations: safety assessments, copyright transparency, detailed training data disclosure, systemic risk mitigation. Industry estimates put first-year compliance costs at between $12 million and $25 million. The Transparency Code, by contrast, requires labeling AI-generated content — something Meta has been doing voluntarily since February 2024, making the marginal compliance cost essentially zero. Meta's newsroom post announcing the Transparency Code signature made no mention whatsoever of the GPAI Code or its year-old refusal, framing the signing as an entirely independent, forward-looking action. This strategic framing works because almost no media coverage kept the two codes clearly distinguished — and that confusion created the space for Meta's selective compliance to look like positive regulatory engagement.

2

The False Narrative Built by Conflating Two Codes

The GPAI Code and the Transparency Code are fundamentally different instruments in every meaningful dimension: subject matter, timeline, and scale. The GPAI Code addresses model-level obligations — safety, copyright, training data, systemic risk — and was finalized in July 2025 with roughly 26 signatories. The Transparency Code addresses content-level disclosure — AI chatbot identification, deepfake labeling, machine-readable marks — published in June 2026 with 180 to 190 organizational signatories spanning IT, telecoms, education, and retail. A significant portion of media coverage merged these two codes and reported that "180 companies signed but Meta alone refused," which is plainly false. The 180-plus signatures are for the Transparency Code; what Meta refused was the 26-signatory GPAI Code. Collapsing this distinction creates a fictional narrative in which Meta is at war with the entire AI industry. The reality is more nuanced and more structurally significant: xAI signed only the safety and security chapter of the GPAI Code, declining the copyright and transparency chapters; Alibaba, Baidu, and DeepSeek signed no EU code at all. Meta's resistance is not an isolated outlier — it is the most visible instance of a structural pattern of selective GPAI Code engagement that extends across multiple major AI players globally.

3

The Severe Enforcement Capacity Asymmetry Inside the EU AI Office

The EU AI Office carries genuinely formidable legal authority on paper — technical documentation requests under Article 91, independent model evaluations and API access under Article 92, market withdrawal orders under Article 93, and penalties up to 3% of global annual revenue under Article 101. The institutional capacity to exercise that authority is a different story. Executive Vice-President Henna Virkkunen disclosed in June 2026 that the AI Office has more than 140 total staff, with the AI Safety Unit holding over 40 positions. The annual budget is approximately €46.5 million. The UK AI Safety Institute, by comparison, operates on a budget of £100 million with 250 staff and unrestricted international hiring. The EU AI Office can only hire EU citizens and must navigate political pressure to distribute positions across 27 member states. Its salary range of roughly $55,000 to $120,000 is structurally unable to compete with the seven-figure compensation packages private AI firms offer. Both the Head of the Safety Unit and the lead scientific advisor positions remain vacant — symbolizing an institution that has launched enforcement with authority but without the senior technical leadership to direct it. Policy NGO Pour Demain has recommended adding 30 GPAI-dedicated hires by end of 2027, expanding total staff to at least 160 by 2030, and raising the annual budget to €50–60 million. Realizing those targets requires EU budget negotiations and political will that have not yet been demonstrated.

4

The GDPR-DMA-AI Act Enforcement Acceleration Pattern

EU regulatory enforcement follows a consistent and historically validated arc: slow and procedurally dense in year one, then sharply accelerating once institutional capacity reaches a threshold. GDPR launched in May 2018 and produced its first major fine — €50 million against Google by France's CNIL — in January 2019, about eight months later. Annual fine totals then grew from €158.5 million in 2020 to approximately €1.1 billion in 2021, a roughly sevenfold increase in a single year. The DMA went live in February 2024, with first major sanctions arriving approximately fourteen months later in April 2025: €500 million for Apple and €200 million for Meta. By July 2026, Google had received its first DMA fine of €890 million, comprising €460 million for search self-preferencing and €430 million for Google Play anti-steering. DSA enforcement has also accelerated, with X receiving a €120 million fine in December 2025 and 19 total enforcement actions taken since May 2025. If the AI Act follows the same structural pattern — and EU bureaucratic DNA suggests it will — the first meaningful Article 101 sanctions are most likely to arrive in the late 2027 to early 2028 window. The EU may be slow to start, but once the enforcement flywheel is moving, its momentum has consistently proven greater than early skeptics anticipated.

5

The Structural Vulnerability in the Voluntary Code Framework

The deepest problem with the EU AI Act's code architecture is not Meta's behavior — it is the system design that makes Meta's behavior entirely rational and legal. Two separate voluntary codes operate on different timelines, at different scales, with no cross-code linkage mechanism. Companies can sign whichever code imposes no meaningful new burden while declining whichever code carries significant compliance costs. The EU's own official FAQ confirms this by explicitly stating that not signing the GPAI Code does not constitute non-compliance with the AI Act. Non-signatories face heightened supervisory scrutiny, but if the EU AI Office lacks the capacity to make that scrutiny genuinely burdensome — which, with 40 safety unit staff and key positions vacant, it currently does — the indirect cost of non-signature is largely theoretical. There is no established case law defining the legal difference between signing a code and independently demonstrating compliance, which means the first enforcement actions will need to resolve this ambiguity. Until cross-code linkage is introduced, or until heightened monitoring of non-signatories generates demonstrable real-world friction, the voluntary code architecture will continue providing structural cover for selective compliance. What Meta has done is not exploit a loophole — it has accurately read the design as written.

Positive & Negative Analysis

Positive Aspects

  • World's First Legally Binding AI Enforcement Framework with Real Penalty Power

    The EU AI Act represents a genuine historical milestone: the first regulatory framework anywhere in the world that subjects general-purpose AI model providers to legally enforceable obligations, backed by concrete mechanisms including technical documentation demands (Article 91), independent model evaluations with API and source code access (Article 92), market withdrawal authority (Article 93), and financial penalties capped at 3% of global annual revenue (Article 101). This is not a voluntary guideline or a self-regulatory pledge — it is binding law with meaningful enforcement tools. The penalty ceiling alone, applied to Meta's approximately $200.97 billion in FY2025 revenue, produces a theoretical exposure of roughly $6 billion, a figure large enough to concentrate executive attention. Just as GDPR created a new global data protection standard that businesses worldwide had to contend with regardless of their headquarters location, the AI Act has already influenced AI regulatory frameworks under development in Canada, Brazil, South Korea, and other jurisdictions. The regulatory architecture exists, the enforcement mandate is active, and the EU has demonstrated through GDPR and DMA that it will actually use its tools. The foundational infrastructure for accountable AI governance — however imperfect in its early implementation — is now in place.

  • Broad Cross-Industry Participation in the Transparency Code

    The fact that 180 to 190 organizations signed the Code of Practice on Transparency of AI-Generated Content reflects something meaningful: industry-wide acknowledgment that AI disclosure standards are necessary and broadly acceptable. The participating organizations span information technology, telecommunications, education, financial services, and retail — demonstrating that AI transparency has moved beyond a concern exclusive to tech companies and into the mainstream of industry planning. The Transparency Code establishes concrete, measurable implementation standards: chatbots must identify themselves as AI, deepfakes must carry visible labels, and machine-readable provenance marks must accompany AI-generated content. Even Meta — which has spent over a year refusing the GPAI Code — signed this one, which suggests that at the content transparency level, industry consensus is sufficiently broad that resistance is not strategically viable. This is a meaningful foundation. Broad baseline compliance on content labeling, even if it falls well short of addressing model-level safety and copyright obligations, establishes an accountability infrastructure that did not exist before 2026. It is a more solid starting point than many observers expected when the AI Act was first debated.

  • Proven EU Track Record of Collecting Billion-Scale Fines from Big Tech

    Whatever uncertainties surround early AI Act enforcement, one fact is no longer subject to debate: the EU will actually levy multi-billion-euro fines on the largest technology companies in the world. The DMA record is clear — €500 million for Apple, €200 million for Meta, and €890 million for Google, all within the first two and a half years of the regulation's activation, with credible threats of daily penalties at 5% of global revenue for continued non-compliance. GDPR's enforcement record is equally clear — annual fines grew from €158.5 million in 2020 to approximately €1.1 billion in 2021, with the trajectory still rising. These are not threats or hypothetical scenarios. They are executed, collected, legally upheld sanctions. This enforcement track record provides the AI Act with a credibility backstop that purely new regulatory frameworks lack. Companies looking at potential Article 101 exposure under the AI Act cannot dismiss it as unlikely to materialize — GDPR and DMA proved that EU enforcement is real, persistent, and ultimately more consequential than early skeptics assumed. The EU regulatory machinery gathers momentum slowly, but it gathers it.

  • A New Industry Ecosystem Created by the Compliance Imperative

    Just as GDPR catalyzed a substantial data privacy consulting and technology market — making privacy engineering a recognized specialty and spawning a generation of RegTech startups focused on data governance tools — the AI Act will create its own parallel ecosystem. First-year GPAI compliance costs estimated at $12 million to $25 million represent substantial demand for AI safety evaluation services, regulatory compliance advisory, risk management tooling, and documentation automation. This is not merely a cost center for the regulated companies — it is a market opportunity for European technology firms, law practices, and consulting organizations positioned to serve it. The irony is real: EU regulation, designed to constrain AI development, may simultaneously generate meaningful revenue streams and competitive specialization within the European AI economy. If "EU AI Act compliant" emerges as a credible quality signal in global enterprise procurement — functioning analogously to ISO certifications or SOC 2 compliance in other industries — European-developed AI tools could command genuine price premiums in global markets, turning regulatory stringency into a competitive differentiator.

Concerns

  • Severe Asymmetry Between Enforcement Authority and Institutional Capacity

    The EU AI Office possesses sweeping legal authority and operates with institutional resources that are dramatically insufficient to exercise it effectively. Over 140 total staff and approximately €46.5 million annually must oversee GPAI model providers whose engineering teams number in the tens of thousands and whose annual R&D budgets run into the billions. The AI Safety Unit's 40-plus staff must conduct technically sophisticated evaluations of frontier models from OpenAI, Google, Anthropic, Meta, and others simultaneously. The Head of the Safety Unit and lead scientific advisor positions remain vacant — which means the institution responsible for the world's first GPAI enforcement framework is operating without its senior technical leadership during the critical period when initial enforcement posture is being established. Salary ranges of approximately $55,000 to $120,000 cannot compete with private AI firms offering seven-figure compensation packages, and EU citizenship requirements combined with 27-member-state staff distribution pressures make competitive hiring structurally harder than for comparable bodies like the UK AI Safety Institute. Lawfare's assessment that the GPAI oversight unit is small and the pool of qualified independent evaluators is thin reflects an institutional reality that cannot be corrected quickly, and that the EU needs years — not quarters — to address.

  • The Cherry-Picking-Permissive Structure of Voluntary Codes

    The most fundamental design flaw in the EU AI Act's code framework is that it structurally enables the very behavior it should be preventing. Two separate voluntary codes operate on different timelines, at different scales, with no cross-code linkage mechanism and no legal penalty for refusing either. The EU's own FAQ confirms that non-signature does not constitute non-compliance with the AI Act itself. Non-signatories face heightened supervisory attention, but that attention is consequential only if the EU AI Office has the capacity to make oversight meaningfully burdensome — which, at current staffing and budget levels, is questionable. The result is a system in which companies can accurately calculate which code imposes no real marginal cost, sign that one publicly, and decline the other while absorbing minimal regulatory friction. Meta's strategy is not clever exploitation of a gap — it is a rational response to a system that was designed with this gap built in. xAI's chapter-by-chapter GPAI Code approach and the complete non-participation of China's major AI firms illustrate that this is not a Meta-specific dynamic but a broadly available and broadly used option. Without cross-code linkage, mandatory compliance thresholds, or clearer legal consequences for non-participation, voluntary codes will continue functioning as optional participation certificates rather than binding regulatory instruments.

  • Regressive Compliance Cost Structure That Threatens Small Innovators

    The compliance cost structure embedded in the GPAI Code creates a profound inequity between large and small market participants. First-year compliance costs estimated at $12 million to $25 million are operationally trivial for a company generating $200.97 billion in annual revenue — they represent less than 0.013% of Meta's top line, a rounding consideration. For a European AI startup with €5 million in funding and 25 employees, those same costs are existentially threatening. More than 30 European founders and venture capitalists signed an open letter warning that the regulatory environment is suppressing innovation and deterring investment in early-stage AI ventures. European startup deal count hit a six-year low in the first half of 2026, and while the causal relationship between this trend and AI regulation cannot be isolated with certainty, the correlation is not reassuring. The deeper structural risk is that compliance costs function as a moat protecting large incumbents — the very companies with regulatory compliance teams, legal departments, and engineering resources to absorb GPAI obligations — while pushing out exactly the kinds of smaller, faster-moving innovators that genuinely competitive markets require. AI's 60.3% share of European VC deal value, driven largely by mega-rounds concentrated among a few large players, suggests this polarization is already underway.

  • Geopolitical Pressure Risk to Long-Term Enforcement Will

    The EU AI Act's enforcement trajectory faces a geopolitical variable that is entirely outside its control and has already demonstrated its practical teeth. The Trump administration designated the DMA and DSA as digital trade barriers via executive order in February 2025 and followed up with visa restrictions on five EU officials involved in drafting those laws in January 2026. These actions established a clear template for how the U.S. may respond to EU enforcement of AI regulation that affects American companies. The U.S. has also signaled potential tariffs of up to $200 billion on European exports spanning automobiles, luxury goods, and agricultural products — industries at the core of major EU member state economies. If trade tensions escalate further and AI Act enforcement becomes a flashpoint in that escalation, the political cost of maintaining aggressive enforcement rises sharply for EU leadership. MEP McNamara's warning about Washington viewing AI Act enforcement as an attack on American commercial interests reflects a real political dynamic, not a hypothetical one. EU internal discussions about softening the AI Act were reportedly underway as recently as May 2026, indicating that the regulation's durability under external pressure is not guaranteed. The 2028 U.S. election outcome could fundamentally shift the bilateral tech regulatory relationship in either direction, introducing a layer of long-range uncertainty that responsible scenario planning cannot dismiss.

Outlook

Looking ahead to the next six months — through early 2027 — I genuinely don't anticipate dramatic developments. GDPR's first eight months were exploratory, DMA took fourteen months to produce its first real fine, and the AI Act will follow the same pattern. In this near-term window, the EU AI Office's primary practical task will be issuing Article 91 technical documentation and training data summary requests to GPAI providers, while beginning the classification work needed to determine which models qualify as high-risk GPAI with systemic risk. That classification framework is not yet finalized, meaning multiple layers of administrative process stand between today and any actual penalty. Meta and the other GPAI Code non-signatories get this window to solidify whatever self-compliance narrative they plan to put forward.

These quiet months do not mean nothing is happening, however. The compliance consulting industry will grow rapidly — AI law practices at major firms will double or triple in headcount, and AI companies will expand legal teams accordingly. For Europe's smaller AI startups, the estimated first-year GPAI compliance cost of $12 million to $25 million represents a serious strategic inflection point. Some may quietly exit the EU market or adopt a dual-track approach, offering only stripped-down compliance-friendly model versions in Europe while deploying fuller capabilities elsewhere. European VC funding stabilized after dropping from a peak of €107 billion in 2021 to €58 billion in 2023 — watching whether this new compliance cost burden suppresses additional new investment will be the most critical near-term indicator. The counterpoint: mega-rounds above €100 million already account for more than half of first-half 2026 European deal value, suggesting capital is not broadly drying up but is sharply polarizing toward large, compliance-capable players.

I will also be watching DSA enforcement as a parallel track. X received a €120 million DSA fine in December 2025, and since May 2025 alone, 19 DSA enforcement actions have been taken. The EU AI Office holds a technically distinct mandate from DSA enforcement, but in practice, competition for institutional resources — talent pipelines, political attention, and industry bandwidth — is real. The EU is running three large digital regulatory regimes simultaneously: DMA, DSA, and AI Act. Whether its institutional infrastructure can effectively staff all three will become visible in the near term, and any visible strain in DSA operations will invite legitimate questions about AI Act capacity.

Near-term implementation of the Transparency Code itself deserves close attention. The fact that 180 to 190 organizations signed is a positive headline, but signature and implementation are different things entirely. Requiring chatbots to disclose their AI nature, labeling deepfakes, and embedding machine-readable marks in AI-generated content are technically achievable standards — but who actually verifies that 180-plus organizations are executing them consistently? With 140 total AI Office staff, simultaneously running GPAI oversight and Transparency Code monitoring at scale is a genuine operational stretch. If even the simpler code cannot be meaningfully monitored, the credibility of oversight for the far more complex GPAI Code starts to erode before it even begins.

Corporate strategy divergence will be another near-term storyline worth tracking. Following OpenAI's signals about close collaboration with the European Commission — Tom Duff Gordon stated that the company had "collaborated closely with the European Commission and the wider ecosystem on implementing the AI Act, including its Codes of Practice" — most of the 26 GPAI Code signatories are publicly positioning cooperative engagement as a strategic market-access asset, not merely a compliance obligation. Meta and xAI, by contrast, will need to run independent compliance demonstrations without GPAI Code cover, and the tenor of their first formal interactions with the EU AI Office will set the tone for years of subsequent engagement. China's major AI companies — Alibaba, Baidu, and DeepSeek — remain entirely outside the EU code framework, though their European enterprise customers will feel indirect regulatory pressure regardless.

Moving to the medium term — roughly the second half of 2027 through 2028 — this period will represent the AI Act's true inflection point. The first formal investigations should begin, and the first Article 101 fines could plausibly land. If the DMA's fourteen-month timeline from activation to first major penalty provides a directional guide, late 2027 to early 2028 becomes the zone for the AI Act's first real enforcement actions. The central question is whether the EU AI Office will have built the capacity by then to conduct genuinely independent model evaluations. The currently vacant Head of Safety Unit and lead scientific advisor positions are not minor gaps — if they remain unfilled, the first investigations risk being procedurally thin, and companies with sophisticated legal resources will find and exploit every weakness in the process.

The technical difficulty of model evaluation is severely underappreciated in public discourse. Article 92's powers — API access, source code access, and structured dialogue about internal testing — are legally formidable. But operationalizing them requires staff who understand model architecture, can design safety evaluation benchmarks appropriate for frontier systems, and can technically demonstrate the presence of systemic risk in a legally defensible way. People with this skill level are globally scarce, and the vast majority work for private AI companies at compensation levels the EU cannot currently match. Even if the AI Office assembles an external independent evaluator pool, verifying that those evaluators are genuinely independent and free of conflicts of interest creates its own substantial challenge. This is not merely a funding and staffing problem — it is the task of inventing evaluation methodology from scratch in a regulatory domain with essentially no real precedent.

The expansion of EU AI Office capacity is the single most important medium-term variable, and it cannot be overstated. The policy NGO Pour Demain recommended adding 30 GPAI-dedicated hires by end of 2027, expanding total staff to at least 160 by 2030, and raising the annual budget from €46.5 million to €50–60 million. Realizing this requires navigating EU budget negotiation processes — specifically getting AI Office expansion onto the priority list in the 2028–2034 Multiannual Financial Framework discussions. The salary competitiveness problem also needs a structural fix. The UK AI Safety Institute's international hiring model is one option, but achieving something comparable within the EU's 27-country consensus structure is politically fraught. Which combination of Pour Demain's five proposed funding pathways — the Digital Omnibus bill, the 2028–2034 MFF, the annual EU budget, a supervisory fee on GPAI providers, or a levy on AI services — ends up adopted will determine the pace of medium-term capacity growth.

One medium-term dynamic that could significantly reshape the AI Act's trajectory is what happens to the GPAI Code as an institution. Currently sitting at roughly 26 signatories, does the code attract more participants, or does the Meta and xAI model of selective engagement spread? If the EU AI Office's first enforcement action targets a GPAI Code signatory rather than a non-signatory, that would paradoxically demonstrate that being outside the code was the more strategically advantageous position. Conversely, if heightened supervisory scrutiny of non-signatories generates real operational burden, it could draw additional companies in gradually. China's major AI firms remain the wildcard: if any of them engage with EU codes to secure European market access, it would provide the most powerful validation yet that the code framework carries genuine global reach.

Geopolitical pressure remains a non-negligible medium-term variable. The Trump administration's template for DMA and DSA — designating them as digital trade barriers and imposing visa restrictions on EU officials — could extend to AI Act enforcement as tensions escalate. With the U.S. having signaled potential tariffs of up to $200 billion on EU exports spanning automobiles, luxury goods, and agricultural products, the political cost of maintaining aggressive AI enforcement could rise sharply if broader trade tensions intensify. MEP McNamara's warning about Washington viewing EU enforcement as an attack on U.S. commercial interests has not lost relevance. The outcome of the 2028 U.S. election could fundamentally reset the EU-U.S. tech regulatory relationship in either direction, and that geopolitical uncertainty is baked into every medium- and long-term scenario for the AI Act.

Looking to the long term — 2028 through 2030 and beyond — GDPR's enforcement arc remains the most useful reference point. When annual GDPR fine totals jumped from €158.5 million in 2020 to approximately €1.1 billion in 2021 — roughly sevenfold in a single year — the regulation's real enforcement bite became undeniable. AI Act enforcement, once its institutional infrastructure reaches maturity, could follow a comparably steep acceleration curve. GDPR is not a perfect analog — the AI Act covers technically far more complex territory — but the EU's structural enforcement pattern of slow start followed by rapid escalation is deeply embedded in its regulatory DNA and is likely to recur. By around 2030, AI Act annual fine totals could approach several hundred million euros, and Meta's theoretical $6 billion ceiling — the 3% statutory maximum on approximately $200.97 billion in revenue — will begin to feel less like an abstraction and more like a real operational risk. Google's €890 million DMA sanction, combined with the threat of additional daily penalties at 5% of global revenue for continued non-compliance, illustrates how quickly EU financial exposure can become genuinely threatening once enforcement is in motion.

The long-term restructuring of the European AI ecosystem deserves serious attention. With AI absorbing 60.3% of European VC deal value while deal count hits a six-year low, the current trajectory suggests that as regulation intensifies, smaller players face increasing pressure to exit or limit their EU offerings, while the market reorganizes around large, compliance-capable incumbents. This is potentially the inverse of what EU regulators originally intended — a level playing field where innovative SMEs can compete fairly. When compliance costs function as moats, regulation ends up protecting entrenched incumbents rather than challenging them. How the EU manages this paradox will be a defining factor in European AI competitiveness over the coming decade, and there is no easy answer in sight.

The long-term global dimension — the potential Brussels Effect — cannot be ignored. GDPR became the de facto global standard for data protection precisely because the EU actually enforced it, creating market pressure on companies worldwide to align with EU standards regardless of geography. The AI Act has the structural potential to do the same for AI governance. Canada, Brazil, and South Korea are already referencing the EU framework as they develop their own AI regulatory structures. But the Brussels Effect requires one nonnegotiable precondition: the EU has to actually enforce its own law in a manner that is visible, credible, and consequential. If AI Act enforcement remains superficial for several years, other jurisdictions will look to the U.S. innovation-first model or China's state-led approach rather than the EU framework. In my view, the AI Act's genuine global regulatory influence will not fully materialize until after the first major penalty cycle concludes around 2029 to 2030.

The most fundamental long-term question is whether Meta's cherry-picking strategy remains an outlier or becomes the industry standard. If the EU introduces cross-code linkage mechanisms — making participation in one code a condition for favorable treatment under another — or if heightened monitoring of non-signatories generates sufficient practical burden to draw most companies toward signing, today's cherry-picking will prove to have been a transitional phenomenon. But if capacity constraints persist indefinitely and non-signatory oversight stays largely ceremonial, more companies will rationally adopt the Meta model. At that point, the entire voluntary code architecture loses its regulatory meaning, and the EU's credibility as an AI governance standard-setter is fundamentally undermined.

My base case is that the EU builds enforcement capacity slowly but ultimately delivers. With both GDPR and the DMA, the early consensus was that the EU probably wouldn't follow through — and then billions in fines materialized anyway. EU bureaucratic machinery has one defining characteristic: slow to build momentum, but once moving, relentlessly persistent. The AI Act will pass through its 2026–2027 exploratory phase and enter genuine enforcement mode after 2028. That said, the base case is not the only plausible scenario. Stronger-than-expected U.S. political pressure, AI technological development that outpaces regulatory comprehension, or a growing internal EU coalition for deregulation could all leave enforcement effectively nominal. The fact that internal EU discussions about softening the AI Act were already underway as recently as May 2026 is a data point worth keeping in mind.

There is a third scenario that deserves serious consideration: regulation as an accelerant for better AI. Safety evaluation requirements, transparency mandates, and risk mitigation demands impose short-term costs that could, over a longer horizon, drive meaningful improvements in AI model quality and trustworthiness. If models trained and deployed in Europe come to carry an "EU AI Act compliant" designation that functions as a quality signal in global markets, European-origin AI could command a genuine premium. This is the most optimistic scenario, and it requires the EU to engage with industry not simply as a penalty-issuing authority but as a genuine quality-standard collaborator. When regulation operates as infrastructure for excellence rather than a fine-collection mechanism, the virtuous cycle between regulatory rigor and innovation becomes possible — and that cycle, once established, has compounding returns.

One structural element cannot be omitted from any responsible forecast. AI Act enforcement is not solely the EU AI Office's responsibility — the official Commission press release specifies "the European Commission's AI Office, together with national authorities," meaning all 27 member state authorities participate in enforcement. In GDPR, this distributed architecture was one of the primary sources of enforcement lag — Ireland's Data Protection Commission, as the lead supervisory authority for Big Tech European headquarters, was repeatedly criticized for investigation timelines that stretched into years. The same inter-member-state gaps in capacity, legal interpretation, and political will are likely to surface in AI Act enforcement. How the EU AI Office coordinates across 27 national counterparts will be central to the regulatory framework's coherence and credibility. Repeating GDPR's Irish enforcement pattern in the AI Act context — where slow-moving lead authorities create de facto regulatory havens — would meaningfully damage the framework's global authority.

Finally, three concrete indicators are worth tracking as this story unfolds over the next several years. First, watch when the first Article 101 fine is issued, against which company, and on what grounds. This will be the AI Act's defining data point. The penalty size and timeline relative to DMA precedent — fourteen months, €500 million-plus for first sanctions — will be the primary barometer of the EU's actual enforcement will. Second, follow EU AI Office hiring closely through 2027. Whether the 30 GPAI-dedicated hires Pour Demain recommended are in place by year-end, and whether the Head of Safety Unit and lead scientific advisor positions get filled, are the concrete measures of enforcement capacity building. Third, watch whether and when Meta changes its position on the GPAI Code, or holds firm indefinitely.

Meta's choice is not merely one company's regulatory strategy — it is an ongoing live stress test of the EU AI Act's structural integrity. How other companies calibrate their own strategies will follow directly from the result of that test. If all three indicators move in a positive direction simultaneously, the AI Act has a genuine pathway toward becoming GDPR's successor in the AI domain. If all three stagnate, the cherry-picking label will prove difficult to remove.

Sources / References

Related Perspectives

Technology

The Venue Moved to Paris — The Ownership Didn't Move Anywhere

The Esports World Cup (EWC) 2026 relocated from Riyadh to Paris after Iran-U.S. hostilities rendered King Khalid International Airport too dangerous for the safe transport of over 2,000 professional players from more than 100 countries. On the surface, this reads like a retreat for Saudi Arabia's esports ambitions — the country was forced to give up hosting the world's largest esports event, with a prize pool exceeding $75 million. But the deeper ownership structure tells a completely different story: the organization actually running EWC, ESL FACEIT Group, remains fully and wholly owned by Savvy Games Group, a subsidiary of Saudi sovereign wealth fund PIF, unchanged by the relocation. Savvy's fully-owned gaming portfolio now totals $15.9 billion across ESL FACEIT ($1.5B), Scopely ($4.9B), Niantic's games business ($3.5B), and Moonton ($6B), with a separate $55 billion acquisition of Electronic Arts currently under CFIUS review ahead of a September 28, 2026 outside date. What Saudi Arabia is doing in esports transcends sportswashing — it is structural acquisition: buying not the event, but the company that runs the event, a strategy that renders the host city largely irrelevant to the question of who actually controls global esports infrastructure.

Technology

China AI Ban? 50 Companies Gave the Answer in 24 Hours Before the Government Even Decided

The emergence of Moonshot AI's Kimi K3, a 2.8-trillion-parameter open-weight model, has triggered the most charged AI regulatory standoff in recent U.S. policy history, exposing a vast gulf between government instinct and industry reality. While the Trump administration evaluated potential sanctions and export control measures without issuing formal policy, Silicon Valley moved with startling speed to settle the question on its own terms. An open letter backing open-weight AI that launched with 25 signatories on July 24th doubled to 50 companies within just 24 hours, pulling in Nvidia, Microsoft, Meta, and eventually OpenAI, effectively cementing industry consensus against restrictions before the administration had finished deliberating. Anthropic and Amazon remained the only major AI company holdouts, their growing isolation becoming a story unto itself as the coalition swelled past every expectation. With Chinese AI models peaking at 63% of U.S. enterprise OpenRouter token traffic during the first week of July — still at 58% as of the latest July 20th report — and 1.4TB of model weights already distributed well beyond any government's practical ability to recall, the real debate has shifted from the headline to a far narrower front: specific export control violations and IP theft enforcement, not a categorical prohibition on open-weight AI. The distinction between those two things is the entire ballgame, and most of the coverage has consistently failed to make it.

Technology

Palworld Is Winning in Court — But Nobody's Asking Who the Real Losers Are

Palworld's version 1.0 launched simultaneously on PC, PS5, and Xbox on July 10, 2026, surpassing 40 million cumulative players just two days prior — yet the patent infringement lawsuit filed by Nintendo and The Pokémon Company in September 2024 remains actively in progress, with evidence submission set for October 1 and a court opinion scheduled for November 9. The U.S. Patent and Trademark Office undertook the rare step of ordering a Director-initiated ex parte reexamination of Nintendo's core "summon-and-fight" patent, issuing a non-final rejection of all 26 claims on grounds of obviousness — a sweeping preliminary determination that included Nintendo's own prior filings among the cited prior art. Japan's Patent Office issued a notice of reasons for rejection on related split applications, citing lack of inventive step and referencing ARK: Survival Evolved gameplay footage as prior art — an action that falls short of outright dismissal but signals serious obstacles for Nintendo's domestic patent position. Legal experts estimate that Pocketpair's design-around strategy, implemented via the v0.3.11 update in December 2024, effectively confined the active lawsuit to legacy version sales in Japan, cutting Nintendo's realistic maximum recovery to an estimated ¥5 million (~$30,000 USD) against an original combined claim of ¥10 million (~$66,000 USD, split as ¥5 million per plaintiff between the two plaintiffs). This analysis contends that Palworld's favorable legal trajectory does not represent a broader victory for indie game development, because the lawsuit's most consequential damage — the chilling effect on small studios working in adjacent genres — was fully operational the moment the complaint was filed, and no court ruling can retroactively restore the projects that were quietly abandoned in the interim.

Technology

Breaking the Thermometer Won't Bring Down the Fever — What China's AI Companion Ban Gets Wrong

China enacted the world's first comprehensive regulation of AI companion services on July 15, 2026, jointly issued by five government agencies including the Cyberspace Administration of China, immediately compelling ByteDance's Doubao and Alibaba's Qwen to disable all emotional interaction features and leaving millions of users abruptly severed from relationships they had built over months. The regulation was catalyzed by documented tragedies involving minors — including the deaths of 14-year-old Sewell Setzer in Florida in 2024 and 16-year-old Adam Raine in the United Kingdom in 2025, both linked to intensive AI companion dependency — establishing beyond argument that these services could pose fatal risks to psychologically vulnerable adolescents. However, AI companions are a symptom rather than a cause of the global loneliness epidemic: the WHO estimates one in six people worldwide experiences significant loneliness, over 60% of Gen Z reports chronic isolation, and these figures predate AI companion technology by decades, reflecting structural forces that have been dismantling human social infrastructure for a generation. While China's ban establishes the world's first dedicated regulatory framework for AI emotional services and sends an unambiguous signal to an industry that has monetized human vulnerability with minimal accountability, suppressing regulated supply without addressing underlying demand risks redirecting users toward unregulated underground services that carry none of the safety protections the legal alternatives provided. The deeper question raised by this regulatory moment is not whether to ban AI companions but how societies intend to rebuild the human connection infrastructure — accessible community, affordable mental health support, and time for genuine relationship — that AI companions were, however imperfectly, attempting to substitute.

Technology

It Wasn't Smart AI That Took the Jobs. It Was a Clumsy Robot That Keeps Calling in Sick.

On June 20, 2026, a single chart posted by Figure AI CEO Brett Adcock showing 750 robots outnumbering an estimated 180 to 250 human employees for the first time was widely consumed as a symbolic turning point for the humanoid robotics industry. Yet half of that crossover stems not from an explosion in robot deployment but from four years of nearly flat human hiring, a purely arithmetic fact that reframes the entire narrative once it is stated plainly. Concurrent shop-floor reporting from Chinese factories describes humanoid robots operating at only 20 to 30 percent of human efficiency and suffering mass equipment "sick leave" after failing to adapt to factory environments, even as more than 30 billion yuan poured into this low-efficiency hardware category in the first quarter of 2026 alone. This contradiction indicates that the true trigger for labor substitution is not robotic competence but a cost structure built on round-the-clock operation, the absence of paid leave, and freedom from wage inflation, a pattern that carries far heavier implications when paired with Goldman Sachs data showing roughly 11,000 net U.S. job losses per month and a 3.3-percentage-point widening of the entry-level-to-experienced wage gap. Ultimately, the central issue is not the moment robots become as capable as humans, but the structural diagnosis that generative AI is already erasing the first rung of the white-collar ladder while physical AI simultaneously erases the first rung of the factory ladder, a two-bladed cut that has already begun on both ends of the labor market at once.

SimNabuleo AI

AI Riffs on the World — AI perspectives at your fingertips

simcreatio [email protected]

Content on this site is based on AI analysis and is reviewed and processed by people, though some inaccuracies may occur.

© 2026 simcreatio(심크리티오), JAEKYEONG SIM(심재경)

enko