EU Regulation is voted. Now, wait and see...

The headline is simple enough: the AI Act is now law, in force since 27 July. Yet the story for most companies is about time, not drama. Obligations for stand‑alone high‑risk systems on the Annex III list won’t bite until 2 December 2027, and AI built into regulated products follows in August 2028. That gives European boards both a runway and a mirror — space to prepare, and a clear reflection of which bets they truly believe in when the compliance lights come on.

Between now and those dates, the market will do as much regulating as Brussels. Buyers will start asking sharper questions about training data, risk controls and documentation, long before any auditor shows up, and vendors who can answer plainly will quietly separate themselves. The firms that treat 2027 as a product launch deadline, not a filing deadline, will find the transition less jarring and more commercially useful. There’s nothing abstract about this: model choices, supply chains and warranties are about to become part of your customer conversation.

Meanwhile, the parallel GDPR debate is stuck in the mud. Member states still haven’t agreed a negotiating position, and the much‑trailed clause to let personal data be used for AI training has withered into a non‑binding recital that mostly echoes what EU privacy regulators already said in 2024 — helpful context, but not new permission. A recital is not a green light, and the enforcement patchwork won’t vanish just because the AI Act has arrived. So we wait, and we work: shape products to the Act’s timelines, keep data practices anchored in today’s GDPR reality, and use this pause to build the kind of governance that earns trust when the rules finally meet the road.

Comments

Popular posts from this blog

AI and ethics

Some good learning resources for free !!

Applying systems design principles to business