27 September 2026

7 Ways the EU AI Act Could Fail +1 Test That Matters

Europe’s AI rules may succeed on paper—but their real test will be whether firms can access evidence, expertise and consistent decisions without turning assurance into bureaucracy.

The EU AI Act has reasonable goals: prevent harmful uses, protect people and build trust.

But good rules can still fail in practice.

My thoughts:

1: Businesses may realise too late that their role has changed.

A company may begin with a vendor’s tool and later substantially modify a high-risk system, place a resulting system on the market or put it into service under its own name, or repurpose another system so that it becomes high-risk. It may then become legally responsible as the provider. By then, vendor contracts may be signed. Redesigning the system may be costly.

2: No one may hold all the evidence.

The model provider holds information about the underlying model. The organisation building the finished system must record how it was configured, tested, supervised and used. If either part is unavailable, compliance may be difficult to prove.

3: Much depends on self-assessment.

For many standalone high-risk systems, the provider assesses and documents compliance itself, without a notified body reviewing every case. That works only if it has the right expertise—and authorities have the capacity to identify and challenge weak assessments.

4: One Act may feel different in every country.

Member States designate national market surveillance authorities, alongside EU-level coordination. Differences in expertise, staffing and speed may still make enforcement uneven across countries.

5: AI changes faster than assessments.

Models, data, workflows, threats and uses change. The QMS must address modifications and post-market monitoring. But what should trigger reassessment, and when should yesterday’s assessment stop being trusted?

6: Practical support may still be incomplete.

EN 18286:2026 is a meaningful step towards operationalising the QMS requirement. But firms still need the wider set of standards, guidance, sandboxes, templates and qualified specialists to be available, affordable and consistent. Otherwise, they may know they must comply without knowing what sufficient compliance looks like.

7: The mood around the Act could turn sharply negative.

If compliance feels confusing, slow and costly, even firms that support safeguards may see the Act as a barrier. Smaller companies may drop projects, investment may shift elsewhere and responsible AI may become associated with bureaucracy rather than trust.

+1: Paperwork is not assurance.

Technical documentation, conformity assessment and a CE mark can show that a compliance case was established before market launch or internal use. The real test is whether organisations can prove how their systems behave now.

The mandatory quality management system is an important part of the answer.

Article 17 requires providers of high-risk AI systems to establish and document a QMS covering regulatory compliance, design and modification controls, testing and validation, data and risk management, post-market monitoring, incident reporting, record-keeping, resources and accountability. Its implementation must be proportionate to the provider’s size, particularly for SMEs, start-ups and small mid-caps, while maintaining the required level of rigour and protection.

A strong QMS can mitigate many of the risks above. But it is a control framework, not a guarantee.

It only identifies a change of legal role if it is established early enough and tracks the relevant development. It can specify what evidence must be obtained, but it cannot create evidence another party has not supplied. It can structure self-assessment, but it does not make that assessment independent. It can support consistent supervision, but it cannot guarantee that authorities will reach consistent conclusions.

Software can support a QMS, but its availability alone does not demonstrate that a particular provider’s QMS is effective.

The question is therefore not whether the Act contains safeguards. It is whether those safeguards—including the QMS—will work consistently and quickly enough in practice.

Can smaller firms build and maintain an effective QMS, obtain the evidence they need, afford legal and technical expertise—and receive consistent judgements across 27 Member States?

If the current design cannot deliver real assurance without stifling innovation, should Europe retain its prohibitions, narrow mandatory duties further to the clearest high-risk uses—and rely more on voluntary standards elsewhere?

Or will Europe eventually need a “Digital Omnibus 2”?

Share This Story, Choose Your Platform!