Europe’s regulatory double bind
Marco Perugini is an independent researcher and founder of Centrifuga Lab
2 August 2026 was supposed to mark the full activation of the European Union’s AI Act – the most ambitious regulatory framework for artificial intelligence anywhere in the world. Instead, it crystallised something different: a structural double bind in which Europe loses regulatory sovereignty whether it enforces its own rules or retreats from them.
The retreat
The AI Act’s high-risk regime – covering biometric identification, recruitment systems, credit scoring, law enforcement, and border control – was originally scheduled to apply from 2 August 2026. It will not. The Digital Omnibus on AI (Regulation 2026/1744), approved by the European Parliament on 16 June and entering into force on 27 July, deferred standalone high-risk obligations by sixteen months to December 2027, and product-embedded systems by twenty-four months to August 2028.
The stated rationale was implementation readiness. That rationale has documented basis: the Commission’s own standardisation request to the European Committee for Standardization (CEN) and the European Committee for Electrotechnical Standardization (CENELEC), originally due in April 2025, was amended in June 2025 and remains undelivered; as of June 2026, none of the harmonised standards produced by JTC 21 had been cited in the Official Journal (European Commission 2026a). Conformity assessment bodies remain largely undesignated, and certification timelines stretch nine to twenty-four months (European Parliament 2025).
The temporal sequence and documented statements suggest, however, that implementation readiness was not the sole driver of the deferral. Reuters reported in November 2025 that the Commission proposed the delay after Big Tech pushback. In April 2026, US Under Secretary of State for Economic Affairs Jacob Helberg publicly identified the Digital Markets Act as the source of “90 percent of issues” in US–EU cooperation on AI leadership and competitiveness. Commerce Secretary Howard Lutnick linked tariff relief to digital regulatory reform (Euronews 2025, CEPA 2025).
The pressure was not exclusively external – it found institutional allies within member states and the Commission itself, as the Center for European Policy Analysis analysis of the fading ‘Brussels effect’ documents. The causal weight of external pressure relative to genuine implementation constraints cannot be determined from public sources alone. But the result was the same: the most structurally consequential provisions of Europe’s AI framework were postponed.
What remained
What did take effect on 2 August was Article 50 – the AI Act’s transparency layer. Providers must now inform individuals when they interact with an AI system. Synthetic audio, images, video, and text must carry machine-readable markers. Deployers must label deepfakes and disclose emotion recognition and biometric categorisation systems.
These are real obligations with real enforcement dates. But the infrastructure required to assess compliance with them is not yet operational. The Commission mandated CEN and CENELEC to develop harmonised standards in May 2023; the work is still ongoing, and the mandate was amended in June 2025 to align with the final text of the AI Act (European Commission 2026b).
Conformity assessment bodies remain largely undesignated for AI Act purposes (European Parliament 2025). The EU is enforcing transparency requirements on AI systems it does not produce, using assessment capacity it does not yet possess.
In the absence of domestic assessment capacity, compliance evaluation will likely default to methodologies developed in the systems’ jurisdictions of origin – primarily the United States – where benchmark standards and testing thresholds are not subject to European institutional oversight.
The gap between legal activation and operational capacity is not unusual in EU regulatory history. What makes August 2026 distinctive is that this gap opened in the same two-week window as a second, more consequential development.
The trajectory leads to a regulatory model in which Europe writes rules for systems built elsewhere, assessed elsewhere, and contested by governments with the leverage to make enforcement more expensive than forbearance
The punishment
On 23 July 2026, the European Commission fined Google €890 million under the Digital Markets Act – €460 million for self-preferencing its own services in Search, €430 million for anti-steering restrictions on Google Play. This was the Commission exercising a law that had been adopted through standard legislative procedure, enforced through established institutional channels, and reinforced by the Court of Justice just weeks earlier when it upheld the €4.1 billion Android fine on 2 July.
The response was immediate. On 24 July, President Trump declared on Truth Social that the United States would “immediately launch a Section 301 investigation” into the EU’s practice of, in his words, “robbing” American companies. The US Trade Representative warned that EU actions “pose a real risk to the continuation of transatlantic stability with respect to trade.” Trump characterised the conduct as “illegal and highly discriminatory” and stated that the EU would “pay a very big price.”
Section 301 of the Trade Act of 1974 is the statutory mechanism the United States used to impose tariffs on Chinese goods in 2018. Its deployment against the EU’s competition enforcement carries a specific signal: the application of European law to American technology companies is now treated not as a jurisdictional matter to be contested in courts, but as a trade grievance to be answered with tariffs.
The bind
These two dynamics – the retreat from high-risk AI regulation and the punishment for competition enforcement – are not separate policy stories. They are not causally linked: the Omnibus was in preparation since late 2025, well before the Google fine. But they form a single structural condition, because they demonstrate that the same jurisdiction faces sovereignty costs on both sides of the same decision: whether to enforce or to defer.
When the EU retreats from its own regulatory ambitions, it cedes the capacity to shape the terms on which AI systems operate within its borders. The sixteen-month deferral of the high-risk regime means that biometric systems, recruitment algorithms, and law enforcement tools will operate in the European Single Market without the conformity assessment, risk management, and human oversight requirements that the AI Act was designed to impose.
When the EU enforces its own competition rules, it faces trade retaliation calibrated to make enforcement economically costly. The Section 301 investigation is not an abstract threat. It is a statutory process with a defined timeline that typically concludes within twelve months and whose prescribed remedy is unilateral tariffs.
The result is a double bind on regulatory sovereignty. Europe does not lose autonomy through a single dramatic act of external imposition. It loses autonomy incrementally: by deferring the rules it wrote, and by absorbing costs when it applies the rules it kept. The mechanism operates through internal institutional choices – the Omnibus vote, the implementation calendar – shaped by external pressure that need never take the form of a direct command.
What this means for 2050
If this pattern holds, the long-term trajectory is clear. It has held before. Europe’s energy dependence on Russian gas consolidated through the same mechanism: repeated deferral of diversification under cost and convenience pressure, combined with political costs each time member states attempted to enforce their own energy security commitments.
The result was a structural vulnerability that became visible only when the 2022 crisis made forbearance impossible. The regulatory double bind in digital markets operates through the same logic, with one difference: there is no equivalent external shock forcing the correction.
Europe retains formal legislative authority over digital markets and artificial intelligence. It continues to produce regulations, directives, and frameworks. But the operational content of that authority – the capacity to shape what systems do, how they are assessed, and on what terms they enter European markets – migrates elsewhere.
The deferral of the high-risk regime means that every AI system classified under Annex III – biometric identification, recruitment, credit scoring, law enforcement – operates in the European Single Market until December 2027 without conformity assessment, risk management documentation, or mandatory human oversight. These are not future systems. They are deployed now.
By 2050, the question will not be whether Europe has rules. It will be whether Europe’s rules determine outcomes. A regulatory framework that is routinely deferred under external pressure and punished when enforced does not govern; it documents. The ‘Brussels effect’ (Anu Bradford 2020) assumed that market size would sustain regulatory export. The events of July-August 2026 suggest a different equilibrium: market size attracts regulatory arbitrage from producers and trade retaliation from their governments simultaneously.
Breaking the double bind requires something the current institutional architecture is not designed to deliver: the capacity to enforce without dependence on external assessment infrastructure, and the fiscal willingness to absorb enforcement costs without deferral. This is not primarily a legal problem. It is an industrial and budgetary one.
Europe will regulate AI credibly only when it produces AI systems at a scale sufficient to sustain independent conformity assessment – and when it funds that infrastructure as a standing capability rather than a deferred aspiration. The Draghi Report (2024) identified Europe’s competitiveness gap in frontier technologies; the events of July-August 2026 reveal the regulatory corollary of that gap.
Without that shift, the trajectory leads to a regulatory model in which Europe writes rules for systems built elsewhere, assessed elsewhere, and contested by governments with the leverage to make enforcement more expensive than forbearance. A jurisdiction that can legislate but not implement, and that pays a price each time it enforces, retains the form of regulatory sovereignty without its operative content.
References
Bradford, A (2020), The Brussels Effect: How the European Union Rules the World, Oxford University Press.
Broadband Breakfast (2026), “U.S. Official to Europe: Align With U.S. on AI or Fall Behind”, 2 April.
CEPA (2025), “Is the Brussels Effect Fading?”, Center for European Policy Analysis, December.
Draghi, M (2024), The Future of European Competitiveness, Report to the European Commission.
Euronews (2025), “Lutnick: tariff relief contingent on digital regulatory reform”, 24 November.
European Commission (2026a), “Navigating the AI Act”, FAQ, digital-strategy.ec.europa.eu.
European Commission (2026b), “Transparency obligations under Article 50 of the AI Act”, FAQ, digital-strategy.ec.europa.eu.
European Commission (2026c), “Commission fines Google €890 million for breaches of the Digital Markets Act”, 23 July.
European Parliament (2025), “AI Act implementation timeline”, EPRS At a Glance, PE 772.906.
Perugini, M (2026), “Europe’s Ungoverned Space: Military AI and the Autonomy That Cannot Be Bought”, VoxEU.org, 22 June.
Reuters (2025), “EU to delay ‘high risk’ AI rules until 2027 after Big Tech pushback”, 19 November.
Reuters (2026), “Trump says US to launch EU probe over ‘illegal’ Google fine”, 24 July.
USTR (2026), Statement by Ambassador Jamieson Greer on EU enforcement actions against US technology companies, 23 July.
This article was originally published on VoxEU.org.
