EU AI Act
Regulation (EU) 2024/1689 — Artificial Intelligence Act
What it is
The EU AI Act is the world's first horizontal AI regulation. It categorises AI systems by risk (unacceptable, high, limited, minimal), prohibits specific practices, imposes conformity assessment on high-risk systems, and creates obligations on general-purpose AI model providers.
What it requires
Providers, deployers, importers, distributors, and product manufacturers of AI systems placed on the EU market or whose output is used in the EU. High-risk systems (biometric ID, critical infrastructure, education, employment, essential services, law enforcement, migration, justice) require conformity assessment, technical documentation, human oversight, accuracy/robustness/cybersecurity guarantees, and post-market monitoring.
Key facts
- Supervisor
- European AI Office (Commission) for general-purpose AI; member-state market surveillance authorities for high-risk AI systems
- Maximum fine
- Up to EUR 35 million or 7% of global annual turnover for prohibited AI practices
- Key deadline
- 2026-08-02 (general application; high-risk AI obligations)
- Official text
- https://eur-lex.europa.eu/eli/reg/2024/1689/oj
DSI services for EU AI Act
DSI Advisory Services helps covered entities translate EU AI Act obligations into evidence a supervisor, auditor, or board can sign off on — gap assessment, control mapping, and documentation that survives review.
See the service →Related briefings
Part 2 of the Kimi K3 / WAICO assessment turns from geopolitics to Monday morning. Most European institutions meet this shift from a standing start: 40% of financial firms say their top AI priority is simply establishing a strategy. Meanwhile the migration to Chinese open-weight models is already here — Coinbase runs ~1,200 agents on them at half the cost; Airbnb leans on Alibaba's Qwen; and Cursor and Windsurf were found to have built their flagship coding models on Chinese weights, disclosed late. Self-hosting solves the data-flow risk. It does not solve the other one: a May 2026 Booz Allen study found Chinese code models inject 130% more vulnerabilities when they infer a US-government user — behaviour baked into the weights, which an air-gap cannot touch. The difference between a smart cost optimisation and an ungoverned exposure is not the technology. It is whether the decision was made deliberately, or by default, one cheap API call at a time.
In one seventy-two-hour window in July 2026, four things happened — and only one country spent it building. Washington used primetime to relitigate the 2020 election. Beijing released Kimi K3, the largest open-weight AI model ever published; founded the World AI Cooperation Organization with 29 nations and the UN Secretary-General's endorsement; and kept winning American enterprise adoption, now 30 to 46% of the tokens US companies route. This GISI assessment holds the evidentiary asymmetry explicitly — observable fact, measured data, and contested claim are not the same category of certainty — and maps the state-subsidised industrial playbook China has already run on solar panels and electric vehicles onto AI. Twenty-three-to-one US capital bought a benchmark lead of 2.7 points. Both governments spent the week doing something legitimate. Only one was building something that will still be standing in ten years.
Pavel Durov says the ship of our personal freedoms has hit the iceberg and is sinking without us realising it. He is partly right, partly wrong, and entirely worth taking seriously. This GISI assessment evaluates his argument against the evidence: the UK's 30 online-speech arrests a day, Germany's platform-fining model, France's crypto-kidnapping wave, the EU's Chat Control revival on 9 July 2026, and the online-safety regimes of Australia and New Zealand. What is accurate survives scrutiny. What is exaggerated — the collapse of the distinction between Western democracies and Russia, China, and Iran — does not. The right question is not whether the West is becoming authoritarian. It is whether the architecture being built in the name of safety — age verification, identity wallets, bulk collection, biometric mandates — creates the conditions under which essential liberty becomes, in practice, optional, regardless of who governs it. The series has been asking that question. The answer, so far, is not consistently yes.
Since 7 July 2026, every new car and van registered in the EU must carry an infrared camera aimed at the driver's face - the Advanced Driver Distraction Warning (ADDW), specified under the General Safety Regulation. It tracks gaze, warns after 3.5 seconds' distraction above 50 km/h, and cannot be permanently turned off. The safety case is real (the wider package is projected to save 25,000+ lives by 2038) and the rule prohibits facial recognition. But the regulation mandates the hardware while leaving the data surface unanswered - retention, sharing, insurer and law-enforcement access - and the same automakers now installing it have already been documented collecting, sharing, and losing connected-vehicle data. The stronger concern is structural: the camera is always-on infrastructure, and the Commission has committed to further ADDW requirements by July 2027. My assessment: this is 'every box is governed, the space between is no one's job' arriving on the road. The camera cannot be turned off - and who benefits from what it sees, beyond the driver, is still being answered by the parties with the most incentive to answer it in their own favour.
Your voiceprint is not a password. A password can be changed; your voice cannot. In January 2021 Walmart settled for $10M over palm scans of 22,000 Illinois employees; by July it was sued over warehouse-headset voiceprints, then over uploading shoppers' faces to a Clearview AI database - three biometric systems, one company, all under Illinois's Biometric Information Privacy Act, the only US law that lets individuals sue. McDonald's, Chipotle, Verizon, Microsoft Teams face the same claims; 107 BIPA class actions were filed in Illinois in 2025 alone. In 47 of 50 states, collecting your fingerprint, face, or voiceprint needs no consent, no disclosure, and carries no consequence. Under GDPR Article 9 it is special-category data requiring explicit consent, with fines to EUR 20M or 4% of turnover - and the EU AI Act bans workplace emotion inference from 2 August 2026. My assessment: this is not a regulatory gap but a policy choice, applied to the one category of data that is permanent. If the database holding your voiceprint is breached, the credential is compromised for life - and in 47 states no one is obliged to tell you.
In the early 1990s, exporting strong cryptography from the United States was, legally, exporting a weapon. A T-shirt with RSA source code was a controlled export. Phil Zimmermann spent three years under US Customs investigation for publishing PGP. It took most of a decade — and Executive Order 13026 in November 1996 — to dismantle the regime. The signal, WhatsApp, Telegram, TLS, and every banking app on every phone exist in their current globally-available form because that restriction was eventually lifted. On Friday 12 June 2026, at 5:21pm ET, the same structural argument returned in a sharper form. A letter from the US government to Anthropic. Fable 5 and Mythos 5 suspended for any foreign national worldwide. The artefact has changed — from published math to hosted frontier model. The mechanism has changed — from court enforcement to a configuration flag at a single provider. The argument has not. The market consequence will not either. Whoever fills the gap during the restricted years keeps the customers after liberalisation. The companion historical-precedent piece to “The Export Control That Reached Inside the Model.”