Artificial intelligence is advancing faster than regulation can keep up. For policymakers, the critical question is how to narrow this gap and regulate technology that evolves in months across institutions that move in years.
The European Union has played a leading role in answering that question, building the most comprehensive AI regulatory framework through the EU AI Act. But as the potential for AI systems to be misused grows, Europe grapples with whether it can keep pace with threats already emerging beyond its borders.
On 4 May, 30 Members of European Parliament warned Commission Executive Vice President Henna Virkkunen (pictured) that the EU’s cybersecurity rules are ‘ill-equipped’ to deal with a new generation of artificial intelligence (AI) hacking tools. Alarm was recently raised when AI company Anthropic’s cybersecurity model Claude Mythos outperformed humans in finding and exploiting security vulnerabilities. The lawmakers urged reform of EU rules and pushed for EU cyber agency ENISA to gain access to Mythos to scrutinise the risks.
In response, Commission spokesperson Thomas Regnier said the Commission has held numerous meetings with Anthropic since August 2025. He added the enforcement powers under the AI Office would begin in August 2026, at which point model access could be secured ‘if needed’. For the 30 MEPs who signed the letter, and for the businesses currently exposed, that timeline feels far-off. Ultimately, Europe has been left struggling to gain access to cutting-edge AI to assess the risks.
This encapsulates the heart of Europe’s AI debate. Having spent years building this regulatory framework, the EU is left asking whether its instinct to legislate first and innovate second has left it lagging behind in a race it can no longer afford to lose?
The EU AI Act: Ensuring compliance while promoting innovation
The EU AI Act, which came into effect in August 2024, intended to set the global standard for responsible AI regulation. This included setting strict requirements on high-risk applications like biometric identification, healthcare, credit assessment and law enforcement. For a time, it has been working as intended. The purported Brussels Effect meant that even US firms were shaping their products around EU standards. In other words, the 450 million customers comprising the EU’s market were simply too large to ignore.
Yet the political consensus that produced the AI Act is fracturing. On 29 April, twelve hours of talks between EU countries and European Parliament lawmakers collapsed after they were unable to agree on proposed changes to soften the Act’s implementation. Dutch lawmaker Kim van Sparrentak said frankly, ‘European companies that care about safety and did their homework now face regulatory chaos’. Big Tech, she suggested, ‘is probably popping champagne.’
AI regulation: The opportunity cost of compliance
The dispute reflects a broader tension at the heart of Europe’s AI strategy. Critics argue that Europe’s focus on transparency and accountability through regulation risks slows innovation as global competition accelerates. The economic burden of compliance has further intensified the debate. Eurostat, the EU’s official statistical office, estimated that reporting requirements and administrative burdens cost European businesses €150 billion annually, nearly 1% of the bloc’s entire GDP. Notably, this figure does not even consider the businesses deterred from entering regulated markets in the first place because of these costs.
Indeed, the underlying tension between regulatory ambition and competitive reality remains unresolved. Siemens has already warned that EU regulations are pushing its AI spending outside Europe. To bridge this widening gap between European ambition and American innovation, AI diplomacy has become an urgent legislative priority.
This month, EU Parliament’s Vice-President Victor Negrescu led a delegation from the European Parliament to Washington to discuss AI policy coordination with US politicians and technology executives. Whether the US chooses to work with Europe on supply chains and AI infrastructure will shape the competitive landscape for years. With a €409 billion EU Competitiveness Fund beginning in 2028, Europe has the resources to compete. The question is whether it has the regulatory agility to deploy them effectively.
Dahua Technology and Siemens: Integrating compliance into business operations
Aside from cybersecurity assurances, companies who have already invested heavily in regulatory compliance will benefit once regulations stabilise. Expanding on the 2016 framework, the EU’s updated Network and Information Security directive (NIS2) adopted in December 2022 included stricter cybersecurity standards across critical infrastructure supply changes. The measures were followed by a series of EU regulations, including the EU AI Act and Digital Services Act, demonstrated the rapidly increasing layers of compliance companies work around.
To ensure compliance with NIS2, Dahua Technology implemented a comprehensive Secure Software Development Life Cycle framework, established a dedicated Product Security Incident Response Team for vulnerability management and incident reporting, and embedded Privacy by Design principles across its product development processes. Similarly, Siemens offers a compliance solution, with ongoing patches and updates to ensure products remain protected beyond their initial release. Thanks to their early investment in robust compliance frameworks, both firms are far better place to handle the rapid developments in EU technology regulation.
In a regulatory environment as complex and fast-moving as Europe’s, the proactive, standards-driven approach from Dahua and Siemens is increasingly not just good practice but a competitive differentiator. As the EU works to reconcile its ambitions for AI leadership with the realities of global competition, the companies that have already done the compliance groundwork will be best placed to move quickly when the rules finally settle.
