- The EU AI Act introduces a risk-based framework that classifies AI systems into minimal, limited, and high-risk categories, with staggered compliance deadlines.
- European leaders advocate for an 'AI you can trust' seal, similar to GDPR, to differentiate the continent in the global AI race.
- Small and medium-sized enterprises face compliance challenges, but the regulation includes sandboxes and support mechanisms to ease adoption.
- The Act is seen as a global standard-setter, with experts debating whether its timing and flexibility strike the right balance between innovation and protection.
The European Union’s landmark Artificial Intelligence Act, formally approved in 2024, is now moving from paper to practice. After an initial phase that banned certain AI practices and mandated basic AI literacy, the next major milestone arrives on August 2, 2025, when most of the rules covering transparency, minimal-risk uses, and prohibited practices come into full effect. This phased rollout reflects the EU’s deliberate approach to regulating AI by its applications rather than the underlying technology, a strategy that many experts believe could give Europe a unique edge in the global tech landscape.
At the heart of the regulation is a risk-based classification system. AI systems are divided into four tiers: minimal risk, limited risk, high risk, and prohibited. The highest tier—high-risk AI—includes applications in biometrics, critical infrastructure, education, and employment. For these, the EU has granted extended deadlines: standalone high-risk systems must comply by December 2027, while those embedded in already-regulated products like toys, elevators, or medical devices have until August 2028. This staggered timeline is designed to give companies enough breathing room to adapt without stifling innovation, according to several industry observers.
The ‘AI You Can Trust’ Seal
One of the most compelling ideas emerging from the EU AI Act is the notion of a trust seal. David Villalón, co-founder of Maisa, a Spanish AI platform, explains that the regulation does not target the technology itself but its uses. “It provides legal certainty for investors, protects fundamental rights for citizens, and—most importantly for business adoption—builds trust,” he says. This trust is exactly what Gil Blancafort, founder of V-Proof, believes Europe can turn into a competitive advantage. “Europe cannot win the AI race on computing power or foundational models. That train has left. But it can win on trust and legal sovereignty,” he argues. Blancafort points to the phrase “AI you can trust” as a growing message in the European tech sector, one that aligns perfectly with the legal certainty the EU AI Act aims to deliver. He compares it to the GDPR effect: “American and Asian companies wanting to operate in Europe will have to comply, making the EU AI Act a de facto global standard for the most regulated markets.”
Challenges for Businesses and SMEs
While the regulation is praised for its proportionality, it also poses significant hurdles, especially for smaller players. Patricia Pina, research director at Clarity AI, highlights two main challenges. First, technical demands: “High-risk systems must be explainable—no black boxes—and require constant monitoring to catch biases that can feed back over time. That’s not a one-time task; it’s an ongoing burden.” Second, uncertainty: “Months of back-and-forth over simplification don’t help anyone who wants to comply quickly or needs predictability.” To ease the load, the EU has mandated that member states promote information initiatives, guidance, and priority access to regulatory sandboxes for SMEs and startups. Joan Vendrell, CEO of NeuralTrust, a security platform for AI agents, notes that native AI companies often find compliance easier. “The law forces high-risk AI users to implement control mechanisms, and solutions like ours help by evaluating models, detecting biases, and monitoring constantly,” he says. For startups like Orbio, which focuses on AI-driven talent recruitment, getting ahead of the curve has been key. Co-founder Nacho Travesí says they obtained ISO 27001 and SOC 2 Type II certifications early, and conduct continuous audits to detect discrimination. “A job candidate who knows they’re interacting with a supervised AI system subject to clear standards participates with greater peace of mind,” he adds.
Timing and Global Impact
Debate continues over whether the EU AI Act arrived too early, too late, or just in time. Giovanni Alessandrello, partner at BIP Iberia, argues that the timing is reasonable. “AI is already embedded in thousands of business processes, and its adoption will only accelerate. Having a framework that sets homogeneous criteria for responsibility, transparency, and risk management brings market stability and facilitates sustainable adoption,” he says. Guillermo Hidalgo, head of cyber law at Maio Legal, agrees but warns of tension. “If it had come much earlier, it would have regulated a different technology. If much later, many practices would already be entrenched without controls. The real test is not passing the law but applying it with flexibility and common sense.” He adds that Europe must differentiate through trust and legal security, but “regulating with fear can be a drag.” The contrast with the United States is stark. While Brussels builds a comprehensive, binding framework, Washington has moved away from federal AI obligations. Patricia Pina notes, “Beyond which model works better, the problem is that AI doesn’t respect borders. A developer deploying in half a dozen jurisdictions faces a patchwork of requirements that don’t always fit together.”
The EU AI Act is more than a set of rules—it is a strategic bet. By focusing on trust, proportionality, and legal certainty, Europe aims to turn regulation into a brand. Whether that bet pays off will depend on how well the continent balances oversight with the need to keep innovating. For now, the message from Brussels is clear: the future of AI is not just about what it can do, but about who can be trusted to use it responsibly.

