I can answer that. A higher regulatory overhead that means less money for R&D and decreased profit margins for companies here in the EU. That's what's going to happen.
As models become more capable, this could have serious economic consequences. :(
EU will mandate labels on authentic-looking AI content starting August 2
Re. disclosure: How do they want to do it? It seems to be similar to a “disclosure” used in students’ works: “Source: internet”…
Thank god Xi Jinpeng has the best interests of Europe at heart...
Regulation doesn't hinder innovation, it's just that CEOs want that quick buck instead of being responsible and using regulation for their advantage.
I think enforcing compliance with the law will be rather simple, just like it happened with GDPR, food labeling and many other regulations. But I wonder how will the disclaimers/declarations even be verified? The more I think about it the more I see open sourced (both dataset and weights) models as the only truly verifiable solution. And that makes it less attractive as a business foundation if. So we might end up with state-funded models working in similar fashion to museums it other culture/art institutions ensuring that original material creators are treated fair. But that will bring whole other set of challenges...
General statement that means zilch. Regulation depending on particular conditions can definitely curtail innovation or destroy it completely. Bureaucracy wants to regulate everything including how often we fart.
"Not a requirement under GDPR", yes, but certainly not "nothing to do with GDPR". It directly has to do with GDPR, in conjunction with business' decisions and how to comply with the law.
And of course, we can then argue our faces off about what's good and necessary in the world, in businesses and data protection, but saying it has nothing to do with it is just wrong.
From my reading, it seems that while cookie permissions first became an explicit EU law concept in a 2009 amendment to ePrivacy Directive (not GDPR), companies were able to get away with passive consent banners (not popups).
It was GDPR's new definition of consent which then retroactively strengthened the existing ePrivacy Directive cookie consent to explicitly require user action to give consent (i.e. popups, banners large enough to push users to interact with them, etc.).
Unless your point is that GDPR has nothing to do with popups because the companies could just not use non-strictly-necessary cookies and therefore not need a popup, but I think that's a stretch to jump from there to "nothing to do with GDPR".
https://wp-gdpr.eu/gdpr-cookie-consent-2026/
https://eulawanalysis.blogspot.com/2022/01/consent-and-cooki...
I remember European efforts to create search engine, digital library. And a lot of EU-funded projects in Horizon 2000 are useless, just an expensive bureaucracy…
GDPR and cookie consent bars are pain in the a* and ux/ui failures.
What I mean - intention is good, realisation is often bad. (But I don’t think that rest of world would be better btw :)
/end-of-rant
That is "reductio ad absurdum".
quality regulations don't curtail innovation.
I repeat, if your business model (which like the big majority of the entrepreneurial world is based on) is against regulation, it's wrong.
I don't think it's acceptable to have a billionaire tech bro dictating everything I do in my life while he gets rich by selling my data. One of the reasons regulation exists is to protect customers.
It's about damn time the business world moved away from the capitalism mindset that you NEED to explore the consumer to be successful. We have a lot of examples in Europe where if the company is even a bit less shitty and is sympathetic to the customer, it increases trust and brings in more revenue because your customers trust it.
nor there is regulation to inform a user something uses AI or the dangers of being dependent on this magical oracle.
"i.e." doing a lot of work there.
GDPR doesn't require pop-ups or banners for providing consent. It mentions "ticking a box when visiting an internet website" as an example implementation. But it's just there as an example.
https://gdpr.eu/Recital-32-Conditions-for-consent/
the mechanism for gathering consent is an implementation detail left to the site to handle because GDPR applies to far more than websites. i've had to provide consent for things completely unrelated to websites.
you could add a line of text saying "please write us a letter with the following information (user account, blah, blah) if you are willing to provide consent for optional tracking like blah blah" and this is perfectly in line with GDPR.
sure, it's more expensive and you'll get fewer people who you can track. but make no mistake, sites make a decision and choose pop-ups/banners as their implementation for gathering consent because they don't want to lose out. they're happy inflicting pop-ups/banners on their users instead so they can keep their precious tracking cookies going.
i.e. GDPR doesn't require pop-ups/banners, sites choose pop-ups/banners.
My personal GDPR hot take: it's actually been 2 steps forward and 1 super clumsy super loud and obnoxious step back.
I agree with the spirit of comment above. The common sense part of it (if there is one) might just end up eclipsed by wonky UX absurdity. Someone will find a way to paint this picture that our EU reality is a Kafkaesque dystopia.
Well, there's the White House blocking models on a whim. I guess that's the closest they'll get to something resembling regulation.
The aviation industry must be one of the most regulated ones and it's entirely necessary to guarantee the safety of passengers and crew. You don't see anyone complaining about it except Boeing who failed QA in the past couple of years and killed some hundreds of people due to their oversight.
And yes, it is deliberate misinformation.
You can extend causality as far as you want if you're willing to sound like this in the open. If there were no cookies, there'd be no banners. There, found you a new target.
So on one side you have decent regulation that tries to balance the interest of the user without over regulating and becoming too prescriptive, and on the other side you have abusers who most of the times are actually in malicious non-compliance... and you find a way to blame the regulation.
Good thing it's in the rules that HN is not Reddit.
You've put such discrediting words in my mouth with your straw man, touche! By the way, have you stopped beating your wife?
Some time after IE6 and Firefox and before Chrome, the default policy switched from "prompt" to "accept".
GDPR was an attempt to restore that default behavior, however no browser did so. I'd've guessed Mozilla could be convinced to revert, but Google presumably paid them enough to look the other way.
Moments ago it was "misunderstandings or malicious compliance". Did you misplace one on your apologetic quest?
I'm really trying not to assume the worst about you. Is there any reason you insist so much on giving the benefit of the doubt to every law breaker out there? Especially when we're sometimes talking about very deep pockets who can afford lawyers?
Well, you are. Maybe don't do that?
As of today, the EU's rules on AI models become enforceable, cementing the European Commission's role as the world's most prominent regulator of this disruptive technology. Euronews takes a deep dive into what the rules mean for Europe and beyond.
The AI Act is the first comprehensive law regulating artificial intelligence. Passed in 2024, some of its most significant provisions — notably those regulating large language models — become applicable this August.
As the law introduces first-of-its-kind rules, enforcing them presents a unique set of challenges, not least because new generations of AI technology emerge every few months. Brussels' experience is likely to resonate well beyond Europe's borders.
Initially, the AI Act was only meant to regulate AI applications. But when the public launch of ChatGPT took the world by storm in 2022, EU policymakers decided also to cover the underlying technology: large language models.
The rulebook sets out rules for all models that lack a specific purpose but can be adapted to a variety of use cases, requiring transparency on how a model was built, disclosure of any copyright-protected content used for training, and enough information for downstream users to understand the model's capabilities.
Additional requirements fall on companies developing the most powerful "frontier" models — those pushing the boundaries of the technology — compelling AI firms to identify and mitigate risks to society at large.
Last year, the Commission endorsed a voluntary code of practice drafted by world-leading experts, including Yoshua Bengio, detailing how developers should comply with the rules. Most leading Western AI labs, with the notable exception of Meta, signed the code.
"We've collaborated closely with the European Commission and the wider ecosystem on implementing the AI Act, including its Codes of Practice, and will continue working together to help Europe realise the benefits of the Intelligence Age," Tom Duff Gordon, OpenAI's Vice President and Head of EMEA Policy, told Euronews.
The Commission set up the European AI Office to drive enforcement of the AI Act's rules on AI models. The task is enormous, taking on one of the most complex technologies of our time and some of the richest companies in the world.
The EU's resources are knowingly limited, and AI talent is in high demand, with public authorities competing with the private sector. The Commission is therefore seeking to tap into external expertise, namely a panel of scientists and a pool of highly specialised AI safety firms.
Still, AI in general, and frontier models in particular, remain a moving target: officials will have to keep pace with fast-moving technological developments without much prior experience or scientific consensus on how to prevent harm at scale.
At the same time, any decisive action from Brussels in this area is bound to draw the attention, if not the ire, of Washington, with the Trump administration particularly assertive in attacking the EU's digital rules when they affect American companies.
"The danger is that the current US administration treats this as an attack on US commercial interests, as it did when the Commission sought to implement its digital markets' rules in December 2025 and more recently this month when it sought to fine Google under the EU's Digital Markets Act," MEP Michael McNamara (Ireland/Renew) told Euronews.
The AI Act's core purpose is to make technology safer for European citizens, ensuring it does not harm their safety and fundamental rights. As such, it also applies to foreign companies that commercialise their AI technologies in the EU.
The industry has repeatedly attacked the law, arguing that it will slow innovation by placing an unnecessary burden on tech companies, forcing them to divert money from hiring engineers to hiring lawyers to handle the paperwork.
In practice, for European consumers and businesses, that might mean some of the most advanced AI models launch in the EU a few weeks later than in other markets, as firms ensure they have done their compliance homework.
Still, it will also mean that, at least in theory, Europeans can trust that if an AI model is available in the EU, it is safe to use. Given how embedded AI is becoming in everyday products and services, that time lag might be worth it.
MEP Axel Voss (Germany/EPP) called on the Commission to enforce the AI Act in close alignment with other digital issues, since AI technologies are increasingly embedded in connected products and online services.
"Taking the AI Office's lack of capacities into account, I very much hope that they do not waste their energy on niche concerns but instead align strongly with the priorities of their platform regulation colleagues," Voss told Euronews.
As the Commission has become the world's most prominent AI regulator, it will inevitably set the benchmark for how public authorities approach the technology, especially since other jurisdictions have taken a more wait-and-see approach.
That is why the enforcement priorities the AI Office sets for itself are bound to have an impact well beyond Europe's borders — not to mention the so-called "Brussels effect," the EU's capacity to set compliance standards for global companies.
There are two main schools of thought on the main risks AI regulation should address. The AI ethics tradition focuses on fundamental rights violations, such as discrimination and privacy, and the need to ensure human oversight.
Effective altruism, by contrast, emphasises so-called existential risks: the possibility that AI could cause catastrophic harm by helping build nuclear or biological weapons, enabling massive cyberattacks, or escaping human control altogether.
Recent episodes — Anthropic's Mythos-based model being pulled under US export control restrictions over concerns about its cyber capabilities, and an OpenAI AI agent hacking into an AI firm during testing — might push the Commission to focus its scarce resources solely on existential risk scenarios.
"The Commission must resist the temptation to devote its enforcement resources solely to cyber-offence and loss-of-control systemic risks," Laura Lazaro Cabrera, a director at the Center for Democracy & Technology, told Euronews.
"Enforcement should not be headline-driven, but should address the full spectrum of risks and ask whether fundamental rights and societal risks have been adequately considered," she said.