Technology · Digital regulation
EU signals willingness to amend AI Act under industry pressure
European Commission tech chief Henna Virkkunen says Brussels will review administrative burdens in the year-old regulation as US trade policy shifts and Big Tech lobbying intensifies.
The European Union's landmark artificial intelligence regulation is barely a year old, but Brussels is already signalling it may rewrite parts of it. On Wednesday, the European Commission unveiled a strategy that explicitly opens the door to reducing compliance burdens in the AI Act, marking a notable shift from the tone that accompanied the law's adoption in late 2023. When legislators reached agreement on what was billed as the world's first comprehensive AI rulebook, Commission President Ursula von der Leyen called it a historic moment. The political emphasis then was on guarding against risk. Now the emphasis is on competitiveness.
A change in political weather
Several things have changed since the AI Act was finalised. The new US administration has made no secret of its view that Europe regulates too aggressively, a message delivered alongside tariff threats that have rattled transatlantic trade relations. At the same time, von der Leyen has recast AI as a lever for European competitiveness and strategic autonomy. The Commission's tech chief, Henna Virkkunen, put it plainly when addressing European Parliament lawmakers: "When we want to boost investments in AI, we have to make sure that we have an environment that is faster and simpler than the European Union is right now."
The language is deliberate. The Commission is not proposing to scrap the AI Act. Virkkunen committed to its main goals. But she also said the executive is looking into "administrative burden" and considering "some reporting obligations [that] we could cut." A senior Commission official briefing reporters went further: "Nothing is excluded" when asked about the scope of a wider review of digital rulebooks planned for the end of this year. That review will now feed industry views on where regulatory uncertainty is hindering AI development and adoption.
Industry lobbying finds an open door
The shift did not happen in a vacuum. Big Tech lobby groups have been pressing the case that the AI Act, alongside the Digital Services Act, the Digital Markets Act and the GDPR, creates a cumulative compliance load that discourages investment. The Computer & Communications Industry Association (CCIA), which represents Amazon, Google, Meta and others, acknowledged Wednesday's strategy as a first move to simplify tech rules. Its Europe policy manager, Boniface de Champris, said: "This is only the first step. What matters most is tackling them head-on."
OpenAI sent its top lobbyist, Chris Lehane, to Brussels for the unveiling. He had told POLITICO beforehand that the industry needs "simple and predictable rules." John Collison, co-founder of the Irish-US payments company Stripe, was more blunt. In an interview published on Tuesday, he called the AI Act "a priori regulation of speculative harms" and argued: "The AI industry is very nascent and we would probably be able to make better choices if we waited five years."
The most contested part of the Act concerns general-purpose AI models, the large language models such as OpenAI's GPT and Google's Gemini. A voluntary code of practice for providers of these models is still being drafted, and AI companies have warned that it could become another binding obligation in disguise. The Commission's strategy acknowledges the need to "facilitate compliance" with the Act, a formulation that replaced stronger language about minimising compliance burden in a leaked draft.
Civil society and lawmakers push back
Not everyone in Brussels welcomes the pivot. Maximilian Gahntz, AI policy lead at Mozilla, warned that a push for simple rules "should not lead to undermining the effectiveness of the EU's AI Act rules and what they were meant to accomplish." His formulation, "Simplification should not mean deregulation", captures the core anxiety of civil society groups that fought for strong protections during the legislative process. They argue that the Act's risk-based framework, which bans certain AI practices outright and imposes strict requirements on high-risk systems, is already a compromise.
Two leading European Parliament lawmakers also pushed back on Wednesday against the Commission's February decision to withdraw a proposal for a single EU liability scheme for harm caused by AI. They described the Commission's reasoning as "premature and unconvincing." The liability directive was meant to complement the AI Act by making it easier for individuals to claim compensation when AI systems cause damage. Its withdrawal was seen by industry as a concession; by consumer advocates, as a hole in the enforcement architecture.
The liability gap
The withdrawn AI liability directive is a case study in the new dynamic. The Commission argued that existing national liability regimes, combined with the AI Act's transparency and documentation requirements, would be sufficient. Critics counter that without a harmonised EU framework, victims face a patchwork of 27 different legal systems. The European Parliament's legal affairs committee had already approved the directive in 2023. Its abandonment suggests the Commission is willing to sacrifice legislative coherence for the sake of a simplification narrative.
This matters because the AI Act's enforcement relies heavily on post-market surveillance and the ability of individuals to seek redress. If liability rules remain fragmented, the Act's deterrent effect may be weaker than its architects intended. The Commission says it will assess the need for liability rules as part of the end-of-year review. For now, the gap remains.
A wider deregulation agenda
The AI Act review is not happening in isolation. It is part of a broader "simplification" drive that touches the Corporate Sustainability Reporting Directive, the Corporate Sustainability Due Diligence Directive, and the taxonomy regulation. The Commission has already proposed delaying some reporting deadlines and raising thresholds for compliance. The omnibus simplification package, expected before summer, will test whether the European Parliament and Council share the Commission's appetite for rolling back obligations they approved only months ago.
The political calculus is delicate. Member states are divided. France has historically pushed for lighter regulation to nurture domestic AI champions such as Mistral. Germany's position has shifted with the change of government; the new coalition agreement emphasises innovation-friendly implementation. Eastern European capitals tend to favour less regulation. The Parliament's centre-right EPP group, the largest in the hemicycle, has been vocal about competitiveness but remains wary of alienating voters who expect protections.
What the Act actually does
It is worth recalling what the AI Act contains, because the debate about burden often obscures the substance. The regulation classifies AI systems into four risk tiers. Unacceptable risk, social scoring, real-time biometric identification in public spaces, manipulative systems, is banned. High-risk systems, used in recruitment, credit scoring, critical infrastructure, medical devices, face conformity assessments, data governance requirements, human oversight obligations and post-market monitoring. Limited-risk systems, chatbots, deepfakes, carry transparency obligations. Minimal-risk systems are unregulated. General-purpose AI models face a separate regime with documentation, copyright and systemic risk requirements for the most powerful models.
Compliance costs are real. A 2023 study for the Commission estimated that high-risk AI providers could face one-off costs of €160,000 to €330,000 and annual costs of €70,000 to €140,000. For SMEs, the figures are lower but proportionally heavier. The Act includes some SME relief: reduced fees for conformity assessment, priority access to regulatory sandboxes, and simplified technical documentation. Whether that is enough is now the subject of the review.
What happens next
The Commission will launch a public consultation on AI Act implementation challenges in the coming weeks, feeding into the end-of-year digital package. Simultaneously, the AI Office, the new enforcement body inside the Commission, is finalising the general-purpose AI code of practice, due by May. That code will be the first real test of whether "facilitating compliance" means practical guidance or substantive dilution. MEPs have already tabled written questions demanding clarity on the liability withdrawal. The Council has not yet taken a formal position. The next European Council meeting in June will indicate whether heads of state and government want the simplification agenda to go further.
Sources
People mentioned
John Collison
Maximilian Gahntz
Organisations
European Commission · European Parliament · CCIA Europe · OpenAI · Stripe · Mozilla