Discussion about this post

User's avatar
ToxSec's avatar

now that i've published enforcement timelines for three separate regulatory deadlines, i fully expect all of them to get delayed by at least six months. you're welcome. consider this article a public service.

Jonatan's avatar

Solid overview. Enterprises with compliance experts and budgets will figure this out. It'll be painful and expensive, but they'll get there. What I keep thinking about is the gap below: SMEs and solo developers shipping or deploying increasingly capable AI systems without meaningful governance infrastructure. If those systems land in high-risk territory under the EU AI Act, they'll need the high-risk compliance stack across the system's lifecycle. The Act has sandboxes and microenterprise carve-outs, but no blanket SME exemption. When enforcement hits, flying without governance becomes bet-the-company.

15 more comments...

No posts

Ready for more?