The Regulator's Gift

The question at the centre of this research area is deceptively simple: can a regulation designed to constrain Big Tech inadvertently hand it the market?

The EU AI Act imposes uniform compliance obligations regardless of operator size. For large technology companies, compliance is a marginal cost. For European startups and SMEs, the same obligations can be operationally insurmountable — particularly when compounded with parallel regulatory regimes such as the Medical Devices Regulation.

The result is a structural asymmetry: local, privacy-respecting, sovereignty-aligned operators face higher effective costs than the non-EU cloud providers EU digital policy was meant to constrain.

This page tracks the development of that argument — the evidence that supports it, the counterarguments worth taking seriously, and the specific policy mechanisms that could address it without dismantling the protections the Act was designed to provide.

The Clause, as usual, has no comment on the asymmetry. It rarely does.


The architecture of the argument

The compliance asymmetry. A Croatian AI startup attempting to build a closed, local blood biomarker analysis system — privacy by design, physician in the loop, no external connections — encountered cumulative AI Act and Medical Devices Regulation obligations that made the project financially unviable. The system was never built. The patients it would have served are unaffected by AI risk, because there is no AI. Meanwhile, Malta deployed ChatGPT Plus as a universal public service — a US commercial AI system with no published controller arrangement and no documented DPIA — and the institutional response has been silence. The startup that builds locally cannot comply. The government that outsources globally is not asked to. (The startup →) (Malta →)

The standardisation trap. When SQLite published AGENTS.md — a format for telling AI agents what they may do inside a repository — it was doing something worth doing. Standardising agent constraints is a prerequisite for everything that follows. But de facto standardisation without a legal framework is the regulator's gift running in reverse: industry builds the standard, and the legal framework, when it arrives, ratifies what already exists. Responsibility is relocated, not distributed. The organisation with AGENTS.md in its repository is not protected by the document it wrote. It is protected — or it is not — by the architectural controls that prevent the agent from doing what the document says it should not. (Read the analysis →)

The capital moat. Anthropic raised $65 billion in May 2026 at a $965 billion valuation. The compute agreements attached to the round — five gigawatts from Amazon, five from Google, GPU access from xAI's Colossus at $1.25 billion per month — define what "frontier" means. At this scale, compliance is a line item. For a European startup, the same compliance obligations are existential. The asymmetry is not regulatory intent. It is structural consequence: the regulation is the same for everyone; the capacity to absorb it is not. When two companies define the frontier, standard deployment practices form around their choices, not around the governance frameworks that are still being written. The EU AI Act's phased implementation timeline was not designed to accommodate the speed at which industry-standard practices solidify. It is running behind the facts. (Read the analysis →)

The enforcement gap. In December 2024, the Italian Garante fined OpenAI €15 million for multiple GDPR violations related to ChatGPT. It was the only significant GDPR fine imposed on a generative AI company in Europe. In March 2026, the Court of Rome annulled it — not on the merits, but on jurisdiction. The only enforcement action that tested whether GDPR's provisions apply meaningfully to large language models was resolved on a procedural technicality. The substantive questions remain unanswered. Separately, the EDPB's coordinated enforcement action on the right to erasure — thirty-two DPAs, the largest coordinated action on a single article — found that seventeen authorities raised concerns about controllers lacking basic erasure procedures. The enforcement infrastructure is testing itself and finding gaps. The gift, in the meantime, continues to accrue to those large enough to navigate the ambiguity. (Read the analysis →)

The regulatory rotation. The European Commission proposed that AI providers could process personal data under legitimate interest, provided they offered an unconditional opt-out. The EDPB said the opt-out mechanism didn't work. The Council's response was to remove the provision entirely — not because it disagreed, but because the existing EDPB opinion already permits the practice under existing GDPR provisions. The result: the practice continues. The legal basis is the same as before the proposal. The opt-out that nobody could exercise has been replaced by the absence of a framework, which produces the same practical outcome for data subjects with the additional disadvantage that the conditions are now less explicit, not more. The institutional machinery consumed considerable energy arriving precisely where it started. (Read the analysis →)

The temporal paradox. GDPR Article 32 requires security measures "appropriate to the state of the art." The Cyber Resilience Act mandates SBOM requirements from December 2027. An organisation that has not implemented SBOM practices in June 2026 is formally compliant with the CRA — the deadline is eighteen months away. Whether it is compliant with Article 32 is a different question, assessed under a different standard, at a different time. The compliance timeline and the security timeline are not the same timeline. An organisation can be in the CRA grace period and in an Article 32 risk exposure simultaneously, for the same gap in the same security control, without having done anything wrong in either direction. The paradox is structural. The gift — regulatory complexity as competitive advantage — operates in the gap between the two timelines. (Read the analysis →)

The transatlantic loop. The gift has an international circuit, and in June 2026 it became visible. On the enforcement side, US federal enforcement is becoming a negotiable, personal asset: the rules stay general on paper while their application is settled bilaterally, signature by signature, for favoured parties. On the access side, US-hosted model access was switched off by nationality overnight — Fable 5 and Mythos 5 disabled for all foreign nationals without judicial review — and the European Commission's first response (14 June) was to flag it as a dependency risk and warn that such measures "should not be discriminatory against partners." Both developments strengthen the case for comprehensive European regulation as the adult in the room. And comprehensive European regulation builds the compliance moats that only incumbents can cross — incumbents who, with impressive overlap, finance the American deregulation push. American personalised regulation strengthens European general regulation, which strengthens the incumbents, who finance the personalisation. Viewed from sufficient altitude, the gift is a closed loop: the system is not in conflict with itself, only with everyone underneath it. (Enforcement side →) (Access side →)


Counterarguments and open questions

The strongest objection: without the AI Act, the asymmetry would be worse. In a purely unregulated market, Big Tech's advantages — data, compute, distribution — would be even more decisive. Regulation at least creates a framework within which smaller operators can claim rights and contest practices. The compliance cost is real, but the alternative is not a level playing field. It is a field with no rules, where scale wins absolutely.

This is a serious argument. It is also compatible with the thesis: the regulation can be both necessary and asymmetric. The question is not whether to regulate, but whether the regulatory design accounts for the asymmetry it creates. Tiered compliance thresholds, SME exemptions, shared compliance infrastructure, and public investment in open-source compliance tooling are all mechanisms that could reduce the gift without reducing the protection. The AI Act includes some of these. Whether they are sufficient is an empirical question that deployment will answer.

A second objection: the compliance industry itself creates infrastructure that SMEs can use. Consulting firms, tooling providers, and industry consortia are building compliance-as-a-service offerings that reduce the effective cost for smaller operators. This is happening. Its pace relative to enforcement deadlines is the open question.

The deepest open question is whether the gift is intentional. The charitable reading is regulatory design under uncertainty — the Act's drafters faced genuine complexity and made reasonable choices that produced unintended asymmetries. The less charitable reading is that lobbying during the legislative process shaped the compliance architecture in ways that favour incumbents by design. The truth is probably both: genuine complexity created space that lobbying filled. The gift was not planned. It was planted — and it grew in soil that regulation had prepared.