The European Union’s Artificial Intelligence Act was conceived as a traditional ex-ante product safety regulation: AI systems must comply with a set of requirements before deployment. Yet AI escapes the narrow product definition. It operates in unknown environments and takes actions that were unforeseen at the time of coding. Given that inherent unpredictability, an ex-ante regime cannot effectively safeguard against unforeseeable harm. The AI Act is unlikely to protect against AI harm while minimising market distortion. It risks replicating the outcomes of the 2016 EU General Data Protection Regulation, which has contributed to market concentration by disproportionately burdening smaller firms.

To rebalance EU AI regulation, the AI Act should be revised, moving away from a predominantly ex-ante approach to a balanced mix of ex-ante and ex-post measures. Ex-post regulation relies on monitoring and enforcement after deployment, typically through fines after incidents materialise. A reduction in the AI Act ex-ante compliance burden for most AI suppliers should be traded for a solid ex-post judicial review based on an ad-hoc AI liability framework, together with new ex-post learning, monitoring and enforcement tools. Because the net effect on compliance costs for AI companies would be negative, the package should garner the political support needed in the EU legislative process.

This Policy Brief benefitted from discussions within Bruegel. Many thanks in particular to Stephen Gardner, Fiona Scott Morton and Jeromin Zettelmeyer for their helpful comments.