The Deceptive Simplicity of a Staggered Timeline

When the European Union’s AI Act entered into force in August 2024, it appeared to follow a straightforward governance template: prohibitions on the riskiest applications first, followed by obligations on high-risk systems, then transparency requirements, and finally voluntary codes of conduct. Six months later, in February 2025, the prohibitions on genuinely dangerous AI systems officially became enforceable across all twenty-seven member states. On paper, this looks like orderly regulatory implementation. In practice, the staggered timeline has exposed fractures that run deep enough to reshape how member states interpret and enforce Brussels’ signature technology law.

EU AI Act Phase-In Creates Regulatory Friction: Why Europe's Governance Model Is Fracturing Along Economic Fault Lines
EU AI Act Phase-In Creates Regulatory Friction: Why Europe’s Governance Model Is Fracturing Along Economic Fault Lines

The gap between formal legal entry and actual enforcement creates what economists call a “compliance arbitrage window” where firms can continue practices that are technically illegal while enforcement capacity remains under construction. For Brussels, this would be manageable under normal circumstances. But we are not in normal circumstances. The European AI market is fragmenting precisely as the regulation meant to unify it. What appeared to be a technical detail about implementation schedules has become a political pressure point that reveals fundamental disagreements about what European AI governance should actually accomplish.

The Strategic Autonomy Lobby and the Competitive Anxiety Underneath

Start with France and Germany. In late 2024, as the prohibition phase approached, both countries jointly pressed the European Commission for “strategic autonomy” carve-outs that would allow their foundation model developers more operational flexibility than the regulation technically permitted. Their argument was economically straightforward: European AI companies were already lagging behind American and Chinese competitors, and regulatory strictness would widen that gap further. The pressure was not framed as rule-breaking; it was framed as a survival question.

This matters because it reflects a collision between two legitimate policy objectives that the EU AI Act tried to simultaneously pursue. The regulation aims to be both protective (preventing harms) and competitive (enabling European firms to innovate). For much of 2024, EU policymakers spoke about these goals as compatible. But as enforcement deadlines approached, they proved to be in tension. When the Stanford HAI 2025 AI Index Report documented that the EU produced only seven percent of the world’s notable AI models in 2024 compared to sixty-one percent from the United States and fifteen percent from China, those numbers landed in member state capitals with real political weight. Germany’s automotive sector, France’s growing AI startups, and smaller member states dependent on attracting AI investment all faced the same uncomfortable choice: embrace strict enforcement or quietly signal flexibility.

The lobby campaign ultimately failed to secure formal carve-outs. But its very occurrence signaled something important: the assumption that member states would uniformly implement the AI Act was always optimistic. Different economies have different stakes in the global AI race, and those different stakes now translate into different enforcement priorities.

The Enforcement Gap Between Law and Capacity

Consider the practical dimension. The European Commission’s AI Office, the bureaucratic unit responsible for overseeing and coordinating compliance, received a staffing budget of approximately 9.7 million euros for 2025. Critics from the European Parliament’s Internal Market Committee called this figure inadequate for the task at hand. They were not wrong. The AI Act applies to firms operating across the entire EU market, but the Commission’s AI Office cannot possibly conduct real-time monitoring of millions of AI systems across thousands of companies in twenty-seven countries on that budget.

Enforcement, therefore, falls primarily to national data protection authorities and national regulators. This is where the fractures become visible. Italy’s data protection authority, the Garante, launched formal compliance investigation notices in early 2025 targeting three generative AI service providers operating in the Italian market. These were among the first enforcement actions taken anywhere in the EU under the prohibition phase. But other member states with smaller regulatory staff or different political priorities took a more measured approach. The result is not uniform enforcement of European law across the bloc. It’s fragmented enforcement shaped by each member state’s regulatory capacity, political economy, and appetite for confrontation with tech companies.

Where Regulatory Fractures Become Competitive Advantage

Here is where the analysis becomes uncomfortable for EU policymakers. When a technology regulation is enforced unevenly across a single market, companies respond by locating their riskier operations in the jurisdictions with lighter enforcement. This is not hypothetical. We have watched it happen with data protection enforcement under the General Data Protection Regulation, where enforcement intensity varies wildly across member states despite a unified legal framework. The AI Act, with its more technically complex obligations and its dependence on national enforcement capacity, will experience the same pattern.

A foundation model developer facing genuine constraints from aggressive Italian or German regulators can consider establishing subsidiary operations in member states with stretched compliance resources and lighter enforcement priorities. A high-risk AI system that faces serious scrutiny in one country might find a friendlier operational home three hundred kilometers away. This is not illegal, exactly. But it is the opposite of what the regulation intended. The EU AI Act was designed to create a unified digital market with consistent baseline protections. The enforcement fractures created by uneven capacity and political will are instead creating an archipelago of different regulatory zones within what is supposed to be a single bloc.

The Deeper Structural Problem: Ambition Without Alignment

The fundamental issue is this: the EU attempted to build a comprehensive AI governance system that assumed member states possessed roughly equivalent regulatory capacity and were aligned on enforcement priorities. Neither assumption held. Some member states are building sophisticated AI compliance infrastructures. Others are not. Some governments see strict AI regulation as essential to protect workers and citizens. Others see it primarily as a competitive burden. The staggered timeline of the AI Act, rather than smoothing the transition, has simply exposed these differences at the exact moment when compliance becomes mandatory.

This does not mean the AI Act will fail. It will likely succeed in its core objective: preventing the most dangerous AI applications from operating openly in Europe. But it will probably succeed unevenly, which means it will create the regulatory fragmentation that Brussels hoped to prevent. The EU AI Act’s official text and timeline can be revised through formal amendment procedures, but the political dynamics driving member states toward different enforcement postures will persist regardless of how the legal text reads.

What we are watching in 2025 and 2026 is the collision between two competing visions of what European AI governance should accomplish: one that prioritizes consistent protection across the bloc, and another that prioritizes competitive positioning within the global AI economy. Until EU member states reach genuine political agreement about how to weight those competing objectives, the phase-in schedule will keep generating friction rather than coherent implementation. The question for observers is not whether the AI Act will work as written. The question is whether Brussels can recalibrate its approach before the fractures become permanent features of the European digital market.

Author