Skip to content

Europe · Analysis

Independent · Brussels & Berlin

Technology · Digital regulation

EU Commission signals openness to targeted AI Act changes after implementation review

Kilian Gross says Brussels will prioritise simplifying compliance before considering legislative amendments, as general-purpose AI code of practice faces delay amid US lobbying.

By , Technology Editor

Published

8 min read

The European Commission has cracked open the door to legislative changes on its flagship Artificial Intelligence Act, signalling that Brussels is prepared to amend the regulation if efforts to simplify its implementation fall short. The concession came from Kilian Gross, head of the Commission's AI policy unit, speaking at POLITICO's AI and Tech Summit in Brussels on Tuesday.

Gross was explicit that the Commission does not envisage reopening the AI Act for fundamental reform. "For the time being, I can say we don't really envisage to reopen for instance fundamentally the AI Act," he said. But he added a qualifier that will be closely watched by industry and national capitals alike: "if anything happened, it would certainly be targeted."

A deregulation drive with political tailwinds

The statement fits a broader pattern. Since the start of its new mandate, the Commission has launched a sweeping review of existing legislation under the banner of simplification and competitiveness. President Ursula von der Leyen has made reducing regulatory burden a centrepiece of her second term, arguing that the accumulated weight of European rules risks stifling innovation and investment just as the United States and China accelerate their own AI programmes.

The AI Act, which entered into force in August 2024 after a tortuous three-year negotiation, is the most comprehensive attempt anywhere to regulate artificial intelligence by risk category. It bans certain practices outright, imposes strict requirements on high-risk systems such as those used in recruitment, credit scoring and critical infrastructure, and creates a dedicated regime for general-purpose AI models, the large language models that underpin services like ChatGPT, Gemini and Llama.

Companies have warned that compliance costs, legal uncertainty and overlapping obligations with other digital rules, from the Digital Services Act to the General Data Protection Regulation, could push European startups to incorporate elsewhere. The Commission's willingness to consider targeted changes is, in part, a response to that pressure.

Implementation first, legislation second

Gross made clear the sequence. The Commission's "first focus" is to simplify implementation: guidance, templates, standards and the interplay with sectoral legislation. Only if that proves insufficient will Brussels contemplate surgical legislative edits. That ordering matters. Reopening a regulation that took three years to negotiate, required agreement between the Council and Parliament, and survived a change of Commission leadership, would consume political capital and time that the current majority may not have.

It also reflects a lesson from the GDPR. The data protection regulation, now seven years old, has been amended only once, a minor tweak for scientific research, because member states and MEPs have little appetite for reopening a text that became a global benchmark. The AI Act's architects may be gambling that implementation tools can resolve most friction without touching the law itself.

The general-purpose AI code of practice

The most immediate test of that approach is the code of practice for general-purpose AI models. The AI Act requires providers of models deemed to pose systemic risk, a threshold tied to computing power used in training, to adhere to obligations on transparency, copyright, risk assessment and cybersecurity from 2 August 2025. A voluntary code of practice, drawn up with industry, civil society and academia, is meant to translate those obligations into actionable measures.

The Commission missed its self-imposed 2 May deadline for publishing the code. Gross attributed the delay to "heavy lobbying from the US government," a rare public acknowledgment of foreign pressure on an EU legislative file. The code is now expected "in weeks," well before the August deadline, he said. The AI Office, the new body inside the Commission tasked with supervising general-purpose models, will release it.

Washington's shadow over Brussels

The reference to US lobbying is notable. Since the AI Act's adoption, American technology companies and the US administration have argued that the general-purpose AI rules discriminate against non-European providers, duplicate voluntary commitments made at the G7 and G20, and could breach trade commitments. The previous US administration raised the issue in the Trade and Technology Council; the current one has intensified engagement, according to officials familiar with the talks.

European officials privately acknowledge that the code of practice has become the arena where those tensions play out. If the code is seen as too prescriptive, Washington will cry protectionism. If it is too lax, the European Parliament and member states will accuse the Commission of gutting the Act through the back door. Gross's promise that the code will land "well before" the August deadline suggests the Commission wants to avoid a last-minute scramble that would fuel both narratives.

Industry reaction: caution over celebration

Industry groups welcomed the emphasis on implementation but stopped short of declaring victory. The Computer and Communications Industry Association, whose members include Google, Meta and Amazon, said simplification guidance was "necessary but not sufficient" and called for a "clear timeline" for any legislative review. DigitalEurope, representing large European tech firms, warned that "targeted changes" could become a euphemism for reopening the entire file if the scope is not tightly defined from the start.

Startups, meanwhile, are more concerned with the immediate compliance burden. A survey by the European Digital SME Alliance published in March found that 68 per cent of small AI developers expected to spend more than 5 per cent of annual turnover on AI Act compliance in the first year. For companies with under 50 employees, that figure can be existential.

The review mechanism baked into the Act

The AI Act contains its own review clause. Article 112 requires the Commission to assess the regulation's application by 2 August 2026, two years after entry into force, and every four years thereafter. The review must cover the list of prohibited practices, the classification of high-risk systems, the thresholds for systemic-risk general-purpose models, and the functioning of the governance architecture. Gross's comments suggest the Commission may front-load parts of that assessment, using the simplification exercise as a de facto early review.

That approach has precedent. The Medical Devices Regulation, which faced severe implementation problems after its 2017 adoption, was amended in 2023 to extend transition periods and adjust classification rules after a Commission review identified "unintended consequences" for supply chains. The AI Act could follow a similar path if evidence mounts that specific provisions are unworkable.

Governance and the AI Office

The AI Office, formally established in February 2025, sits at the centre of this dynamic. It is responsible for supervising general-purpose models, coordinating national market surveillance authorities, issuing guidance, and managing the code of practice. Its head, Lucilla Sioli, reports directly to the Director-General of DG CONNECT, giving the unit unusual political weight for a technical body. How the Office interprets its mandate, particularly on what constitutes a "systemic risk" model, will shape the regulatory landscape more than any legislative tweak.

National authorities are also finding their feet. France's CNIL, Germany's BfDI and Ireland's Data Protection Commission have all published preliminary guidance on AI Act overlaps with GDPR. But a coherent European enforcement culture is still absent. The first coordination meetings of the European Artificial Intelligence Board, the forum of national supervisors, took place only in March.

For now, the Commission's message is deliberate: implementation first, legislation only if necessary. Whether that discipline holds when the first compliance reports land, the first enforcement actions bite, and the first trade disputes flare will determine if the AI Act becomes a living framework or a frozen monument. The next twelve months will answer that question more decisively than any summit statement.

Sources

  1. POLITICO

    politico.eu · 2025-05-13

People mentioned

  • Kilian Gross

    Head of the European Commission's AI policy unit, European Commission

Organisations

European Commission · European AI Office

Related analysis

Selected because they share topics with this article

The newsletter

One important European story. Explained properly.

Delivered to your inbox on the days we publish. No daily digest, no push notifications, no advertising.

We store your address only to send the briefing. Unsubscribe in one click.