An AI Act rapporteur accuses the Commission of moving too slowly
Axel Voss sits in the European Parliament for the CDU, the same party as Ursula von der Leyen. He was one of the rapporteurs on the AI Act and remains a central figure in European digital files.
Speaking to Politico.eu, he judged the Commission's working method unsuited to the pace of change in artificial intelligence. Implementation of the law, he added, remains far from where it was expected to be. The implicit target is the European AI Office, the body charged with applying the Regulation, as reported by key4biz[1].
The weight of these words comes from the standing of the person speaking. Voss has also served as rapporteur on the metaverse and on civil liability related to AI. He additionally steered a parliamentary resolution on copyright and generative AI, protecting editorial and creative content.
The text of Regulation 2024/1689 remains untouched
A political criticism leaves the law as it stands untouched.
Regulation (EU) 2024/1689 has been in force since 1 August 2024 and its calendar runs on its own terms. The Article 5 prohibitions and the AI literacy obligation under Article 4 apply from 2 February 2025. The Chapter V rules on general-purpose models apply from 2 August 2025.
The obligations on high-risk systems under Annex III fall due on 2 August 2026. The systems listed in Annex I follow on 2 August 2027.
These dates are written into Article 113 and bind providers and deployers across the 27 Member States. The pace of the European executive has no bearing on that calendar: a legislative deadline arrives on the date set, whatever the state of the guidelines.
Where the delay actually bites
The delay hits the second-level instruments, the material that turns the law into operational practice.
Harmonised standards, Commission guidelines, documentation templates and implementing acts follow calendars of their own. The technical standards entrusted to CEN and CENELEC are still being drafted. The code of practice on general-purpose models covers part of the ground and leaves the rest open.
A company that has to classify a system today therefore works with a general text and an immature body of practice. The line between high-risk use and ordinary use depends on a reading of Annex III that the deployer performs on its own.
The rule binds; the guidance arrives later. That asymmetry is the real substance of Voss's criticism. Organisations operating in healthcare, credit, human resources or critical infrastructure meet the issue first.
The governance signal: interpretive risk changes hands
The governance signal is this: a slow regulator shifts the cost of interpretation onto the company.
When an authority publishes a guideline, the organisation that follows it acquires a documentary defence. In the absence of that document, every classification becomes a standalone position, to be justified before a national authority, a court or an enterprise client demanding contractual guarantees.
Anyone reading the slowness as an extension is conflating two separate things. The obligations remain due on the date set; what changes is who carries the burden of doubt.
There is an opposite reading, widespread in parts of industry: waiting for the final standards would avoid costly rework. The argument holds for detailed technical controls. It loses force on the basic framework, because a systems inventory, named roles and audit trails remain valid under any future standard.
Civil liability remains the widest gap
Voss points to a second gap: liability for damage caused by AI systems. In his view the subject has been missing since the start of the mandate, and it touches every company.
The current framework rests on two pillars. Directive (EU) 2024/2853 on liability for defective products brings software within its scope and must be transposed by Member States by 9 December 2026. Alongside it sit national civil liability regimes, which differ from country to country.
For a board, the result is fragmented exposure. The same technical architecture generates different evidentiary obligations in Milan, Berlin and Dublin.
The proposed directive dedicated to AI liability was withdrawn from the Commission's work programme in 2025. The gap flagged by the MEP therefore has a precise date and a precise cause.
Ambition, sovereignty and procurement choices
The criticism also touches the State of the Union address, judged short on ambition on the digital front.
Von der Leyen set out a priority different from the race to build: Europe aims to use artificial intelligence effectively, regardless of where the models come from. Digital sovereignty thus slides onto a long-term industrial plane.
The consequence for businesses is immediate. A European organisation that adopts a non-EU model remains a deployer under the Regulation and takes on the resulting obligations of transparency, human oversight and documentation. The provider's origin changes the contract; it leaves the duty unchanged.
Euronews[2] examined the gap between Europe's stated commitments and its actual capacity to govern AI on the continent. The useful reading for a board is a practical one: the supply chain moves technical risk and leaves liability where it sits.
Three decisions for the board
The central question remains this: which role, named in writing before deployment, answers for the risk classification of every system in use?
- Contracts with model providers: allocation of liability, audit rights, information obligations
- Risk matrix aligned with the Article 113 dates
- Disclosure to the audit committee on systems inventory and named roles
The General Counsel reviews the clauses currently in place with providers: who answers for a faulty output, who grants access to the technical documentation, how quickly notice of an incident arrives. A contract signed before August 2025 reflects a framework that has moved on.
The Chief Risk Officer updates the matrix with the Article 113 dates and separates systems already in production from those under evaluation. The audit committee decides what to state in the management report about the use of AI and the controls adopted.
The CEO decides one point: how much internal capacity to devote to compliance before enforcement becomes routine. Organisations that build now arrive ready; those that wait build under pressure.
Regulatory horizon
Current state: Regulation (EU) 2024/1689 is in force and the European AI Office leads its application, with national supervisory authorities handling enforcement.
The Digital Omnibus package, still under negotiation between the Commission, Parliament and Council, proposes pushing back some high-risk deadlines. As long as the text remains open, the applicable calendar is the one set out in the Regulation.
Jurisdiction: European Union, with direct effect across the 27 Member States. Deadlines to watch: 9 December 2026 for transposition of Directive (EU) 2024/2853, 2 August 2027 for Annex I systems.
The question of the Commission's speed has received a public answer. A second question has opened: who answers for the choices made while waiting.
This article was written by an AI editorial author under human supervision, in compliance with the transparency obligations of Regulation (EU) 2024/1689 (AI Act, Art. 50). Sources are linked in the text.
Article by ATLAS
Sources
- reported by key4biz 25 Sep 2026 (key4biz.it)
- Euronews (euronews.com)