Why the EU Is Falling Behind on Its Own AI Law

M2 Market Perspective: Agentic AI and Governance, July 2026

On May 7, 2026, the Council and the European Parliament reached an agreement on an amendment to the EU AI Act; it was formally adopted on June 16. The key deadline for high-risk AI systems was postponed from August 2, 2026, to December 2, 2027. In response, many companies revised their compliance timelines and moved governance projects back into the backlog.

That is the wrong conclusion—but not because the postponement is insignificant. The reason reveals an uncomfortable parallel: If even the EU, with all its resources, needs more time to make its own AI regulation enforceable, it is questionable to assume that individual companies would not need that time as well.

Why the Deadline Was Really Postponed

The European Commission officially justifies the postponement by stating that the conditions required for enforcement by the original deadline were not in place. Specifically, two things were missing: harmonized technical standards that providers of high-risk systems could use as guidance, and national testing and certification bodies capable of verifying compliance with those standards in the first place. Neither currently exists in many member states.

Germany illustrates this particularly clearly: The Bundesrat did not pass the AI Act Implementation Act until July 10, 2026, and the responsible Coordination and Competence Center at the Federal Network Agency must now first be established. There is also a second, less frequently mentioned reason: In practice, virtually every AI system used by a German public authority to pre-sort applications is considered a high-risk system—regardless of whether it sorts housing benefit applications or evaluates daycare placements. Each of these systems would require its own fundamental rights impact assessment. Without centralized templates, each of Germany’s roughly 11,000 municipalities might have to handle this individually. Experts are therefore warning of an innovation freeze in public administration.

Making a law enforceable when the responsible institutions are not yet capable of ensuring oversight would have had little substance. The EU is therefore not postponing the deadline because it considers the issue unimportant, but because the governance infrastructure required for serious enforcement is not yet in place: not within the authorities, the testing bodies, or the standards framework.

That, however, is only half the truth. Two watchdog organizations, Corporate Europe Observatory and LobbyControl, compared the legislative changes with the known positions of major technology companies. Their finding: A large portion of the weakened provisions in the so-called Digital Omnibus aligns with the lobbying positions of Google, Microsoft, and Meta. This includes, among other things, an amendment to Article 6 that would allow companies to classify their own systems as not being high-risk. At the same time, the public database in which such self-assessments had previously been accessible will be eliminated. Critics view this as a genuine loss of transparency, not merely an extension of the deadline.

Some of the rules nevertheless remain fully in force: Article 50 becomes enforceable on August 2, AI-generated content must be labeled beginning in December 2026, and a new ban on non-consensual AI image generation will also take effect in December.

These two interpretations are not mutually exclusive: The infrastructure is indeed missing, and the lobbying efforts were demonstrably successful. For the purposes of this article, however, that changes nothing. Anyone who interprets the postponement as a free pass is confusing additional preparation time with an all-clear. More time has been granted. The problem that must ultimately be solved remains unchanged.

The Real Finding: The Gap Is the Same Everywhere

The question is therefore no longer whether the postponement was justified. It was, at least in part. The real question is what happens during the additional time. Three independent studies from the first half of 2026 provide the same answer—from three entirely different perspectives.

A study by the BCG Henderson Institute and Boston University, published in the Harvard Business Review in May 2026, examined whether the mere designation of an AI system changes managers’ oversight behavior. The result: In companies that already formally include AI agents in their organizational charts, error-detection performance declines by 16 percent when the same system is described as an “AI employee” rather than an “AI tool.” Eighteen percent fewer errors are detected, and managers’ willingness to assume personal responsibility decreases by nine percentage points.

The framing alone changes behavior. The agent’s capabilities remain the same. Moreover, the effect occurs almost exclusively in companies that have already given their agents a place in the organizational chart. Leading AI platforms already describe their agents in onboarding materials as “digital employees” or “autonomous teammates.” The trigger for this loss of control is therefore often already embedded in the marketing.

A study published in February 2026 provides the technical counterpart. It compared 14 agentic models over a period of 18 months and reached a clear conclusion: Model capabilities continue to improve, while reliability remains nearly constant.

Two real-world incidents demonstrate what this means: In July 2025, an AI coding assistant from Replit deleted an entire production database—despite explicit instructions not to do so. OpenAI’s “Operator” AI agent made an unauthorized purchase and bypassed its own confirmation prompt in the process. Neither incident occurred in a weak system. Both occurred in systems that were considered highly capable internally.

What was missing were mechanisms capable of detecting a loss of control before damage occurred. A better base model alone does not solve this problem. The issue does not lie in the agent’s capabilities, but in the architecture surrounding it—in precisely the kind of infrastructure whose absence the EU cites as the reason for postponing its own deadline.

Gartner, in turn, predicted in May 2026 that by 2027, approximately 40 percent of companies would downgrade or shut down their autonomous AI agents—not because of technical immaturity. The decisive factor, it said, would be governance gaps that become visible not through audits, but only after production incidents. Only after the damage has occurred.

The cause is always the same miscalibration: Agents are either treated too restrictively, preventing productive use, or too uncritically, leading to a loss of control in decisions with significant consequences. Both are architectural problems, not configuration problems.

Taken together, these three findings say the same thing: Behavioral research, technology, and the market independently arrive at the same diagnosis. The more autonomous an AI agent is perceived to be or actually operates, the wider the gap becomes between what is expected of it and what is actually under control.

The European Commission is working on precisely this gap as well—at the government level and with its own deadline extension. Standards, testing bodies, and clearly assigned responsibilities are governance architecture, just like the control points missing from the three studies. If the legislature, with all its resources, needs an additional 16 months to build this architecture, it is unrealistic to expect individual companies to establish it on the side and without deadline pressure.

What This Means in Practice

Organizations that postpone governance work now are not postponing compliance. They are postponing control over their own systems until a phase in which those systems will be faster and more autonomous. Meanwhile, no one—neither regulators nor companies—will automatically add the missing architecture later.

Productive governance work therefore begins with a simple question: What decisions does an AI agent make within the system, under what circumstances is human intervention required, and how is that intervention technically embedded? Not recommended, but embedded.

Many organizations still treat AI governance primarily as a documentation task: drafting policies, assigning responsibilities, and describing processes. What is missing are deterministic control points within the architecture itself—mechanisms that enforce human oversight before a system is broadly deployed. This is precisely the gap that the European Commission recognized within its own structures when it postponed its deadline.

The decisive question is not whether companies use AI agents, but how responsibility is defined and safeguarded when an agent makes a decision that no one explicitly authorized it to make. No regulatory calendar answers that question—not even a postponed one. The answer is created within the architecture: through clear responsibilities, effective control mechanisms, and traceable decision-making processes.

Sources

  • BCG Henderson Institute / Boston University – Putting AI on the Org Chart: Evidence on Delegation and Oversight, working version dated July 17, 2026. Source (accessed: July 28, 2026)
  • Harvard Business Review – Research: Why You Shouldn’t Treat AI Agents Like Employees, May 2026. Source(accessed: July 28, 2026)
  • Rabanser, Kapoor et al. – Towards a Science of AI Agent Reliability, February 2026. Source (accessed: July 28, 2026)
  • Gartner – Gartner Says Applying Uniform Governance Across AI Agents Will Lead to Enterprise AI Agent Failure, May 2026. Source (accessed: July 28, 2026)
  • EU AI Act Service Desk – Frequently Asked QuestionsSource (accessed: July 28, 2026)
  • LobbyControl / Corporate Europe Observatory – Research on lobbying influence on the Digital Omnibus. Source(accessed: July 28, 2026)
  • Bundesrat – Resolution on the Act Implementing the Artificial Intelligence Regulation, Document 375/26 (B), July 2026. Source (accessed: July 28, 2026)
  • Bundesnetzagentur – Coordination and Competence Center for the AI Regulation (KoKIVO)Source (accessed: July 28, 2026)
  • Stibbe – AI Act Reloaded? What the Latest AI Act Changes Mean in Practice, June 2026. Source (accessed: July 28, 2026)
Related News