Skip to content
Tillbaka till bloggen
The EU AI Act Delay Is a Coffin Built in Slow Motion
Svensk Teknik

The EU AI Act Delay Is a Coffin Built in Slow Motion

F
Fredrik BrunnbergVD & Skribent
11 juni 20269 min läsning

The 18-Month Gift Nobody Asked For

The European Parliament just voted 569-45 to push AI Act compliance deadlines to 2027. The European Commission released draft high-risk AI guidelines after months of delays. Sweden's privacy authority, IMY, is finally getting a budget increase to handle AI Act enforcement. And somewhere in Shenzhen and San Francisco, engineers shipped three new foundation models before lunch.

I run an AI development company in Europe. From Jönköping, Sweden. I am watching this play out in real time, and I need to say this clearly: this delay is not relief. It is the sound of a coffin being nailed shut, one committee vote at a time.

If you are a CEO, CTO, or founder building in Europe right now, the next twelve minutes of reading this might save you twelve months of strategic drift.

What Actually Happened This Week

Let me lay out the facts, because the press releases make this sound reasonable.

The EU extended the timeline for companies to comply with the AI Act's high-risk provisions to 2027. The €35 million fine ceiling remains. The European Commission's draft guidelines for high-risk AI systems arrived after significant delays. These guidelines are supposed to tell companies what "high-risk" actually means in practice.

Meanwhile, US companies are treating the possible August 2026 enforcement date as optional homework. Not because they are reckless. Because they looked at the enforcement mechanism and did the math.

The math is simple: who enforces this?

In Sweden, the answer is IMY. Our privacy authority. The same agency that has been chronically underfunded for GDPR enforcement is now supposed to also police AI systems across every sector. They are getting a budget increase. That is like giving a bicycle cop jurisdiction over a Formula 1 race. The intention is there. The capacity is not even close.

The Swedish Situation: Structurally Honest, Practically Stuck

I want to be fair to Sweden here, because we get some things right. Swedish institutional culture is built on trust, transparency, and process. Our approach to technology governance has historically been thoughtful. The offentlighetsprincipen (principle of public access) means we default to openness in ways most countries do not.

But thoughtful is not the same as fast. And right now, fast is the only thing that matters.

Here is what I see from Jönköping as someone doing software development in Sweden every day:

Swedish AI startups are not waiting for the AI Act. The good ones are building anyway. They are treating compliance as a moving target and shipping products while keeping one eye on Brussels. But they are doing this with significantly less capital than their US counterparts. A Series A in Stockholm buys you roughly what a seed round buys in the Bay Area. The regulatory uncertainty is not helping with fundraising.

Swedish enterprise is cautious by nature. Large Swedish companies, the Ericssons, the Volvos, the banks, were already moving slowly on AI adoption. The AI Act delay gives their internal legal teams another excuse to pump the brakes. "Let us wait until the guidelines are finalized." I hear this constantly. It is poison for competitiveness.

Sweden's AI talent is world-class but mobile. We produce exceptional engineers. They can work anywhere. If the regulatory environment makes building in Europe feel like swimming in concrete, they will go where the water flows. Some already are. As a tech company in Jönköping, I compete for talent not just with Stockholm but with remote positions at US companies paying in dollars.

Compare this to what is happening across the Atlantic and the Pacific. The US has effectively chosen a light-touch regulatory approach, betting that innovation speed matters more than precautionary frameworks. China is taking a different path: heavy state involvement, but with the explicit goal of global AI leadership by 2030. Both approaches, whatever you think of them politically, share one thing in common. They prioritize building.

The EU's approach prioritizes categorizing.

The Enforcement Gap Is the Real Story

Everyone is writing about the compliance delay. Almost nobody is writing about the enforcement gap. That is the real story.

The AI Act creates obligations. But obligations without enforcement are suggestions. And the enforcement architecture across the EU is, to put it directly, a mess.

Each member state is supposed to designate national competent authorities. Some have. Many have not finalized their approach. The ones that have, like Sweden with IMY, are working with budgets and headcounts designed for a pre-AI regulatory world.

Consider what IMY is being asked to do. Enforce GDPR. Handle the AI Act. Evaluate high-risk AI systems across healthcare, finance, employment, law enforcement, education. Assess technical documentation from companies deploying foundation models. Do all of this while competing for AI-literate staff with the private sector, where salaries are three to five times higher.

This is not a criticism of IMY. The people there are competent and serious. It is a criticism of the political class that writes ambitious legislation and then funds enforcement with pocket change. Dagens Industri has covered the funding gap, but it deserves more attention than it gets.

The practical result is predictable. Large companies with legal departments will paper-comply. They will produce documentation that checks boxes without meaningfully changing how their AI systems work. Small companies will either ignore the rules or spend disproportionate resources on compliance theater. And the actually dangerous AI applications, the ones the Act was designed to address, will continue operating in jurisdictions that do not care about EU regulations.

Writing the Rulebook for a Game That Already Moved

The European Commission's draft high-risk AI guidelines arrived this week. I read them. They are thoughtful. They are detailed. They are also describing a technological reality from approximately 2023.

The AI Act was conceived in a world before GPT-4 existed. Before multimodal models became standard. Before AI agents started chaining together API calls autonomously. Before open-weight models made it possible for anyone with a GPU cluster to run something approaching frontier capability.

The classification system, minimal risk, limited risk, high risk, unacceptable risk, assumes you can neatly categorize AI applications into boxes. But modern AI systems do not stay in boxes. A general-purpose model can be a chatbot, a medical diagnostic tool, a hiring screener, and a legal research assistant depending entirely on how it is deployed. The risk is not in the model. It is in the application context. And application contexts change every time someone writes a new prompt.

The Act tries to address this with the "general-purpose AI" provisions. But those provisions are already struggling with the reality of open-source models, fine-tuning pipelines, and the fact that the same base model can be simultaneously low-risk and high-risk depending on who is using it and for what.

We are watching regulators write rules for a world that has already moved to a different stadium. The 18-month extension does not fix this. It makes it worse. By 2027, the technology will have shifted again. We will be discussing autonomous AI agents, self-improving systems, and models with capabilities we can not fully predict today. The guidelines being drafted right now will be quaint by the time they are enforced.

Where This Goes: 2027-2030

Let me look forward, because that is what matters for anyone making decisions today.

The compliance industry will boom. Just like GDPR created a cottage industry of consent management platforms and privacy consultancies, the AI Act will create a compliance-industrial complex. This is already happening. Tools like CISO Assistant (open source GRC platform supporting 150+ frameworks including the AI Act) and Comp (an open-source compliance platform positioning as a Vanta alternative) are trending on GitHub right now. The market is forming around compliance tooling because builders can see what is coming.

The real regulatory battle will be about foundation models. The current framework's biggest gap is how it handles the companies building the most powerful systems. If we are on a trajectory toward AGI, or even just significantly more capable AI, the high-risk classification system becomes irrelevant. You can not regulate the atom bomb by categorizing what buildings it might hit. You have to regulate the bomb. The EU will have to confront this, and it will require a fundamentally different approach than what is in the current Act.

European AI companies will split into two camps. Those that treat the AI Act as a competitive moat (we are compliant, trust us) and those that build outside EU jurisdiction first, then comply later for market access. Both strategies can work. But the second one is faster, and speed determines survival in AI right now.

Sweden's position is precarious but not hopeless. We have the engineering talent, the institutional trust, and the infrastructure. What we lack is urgency and capital. If Swedish policymakers treated AI competitiveness with the same urgency they treated the banking crisis in the 1990s, we could build something real. But they are not doing that. They are giving IMY a slightly bigger budget and calling it a strategy.

What to Look At

If you are a founder or technical leader dealing with this right now, here are specific things worth your time:

CISO Assistant — Open-source GRC platform that already supports AI Act mapping alongside ISO 27001, NIS2, DORA, and 150+ other frameworks. If you need to start building compliance documentation now without paying six figures to a consultancy, start here. Self-hostable, which matters for data sovereignty.

Prowler — Cloud security and compliance automation. If your AI systems run on AWS, Azure, or GCP, Prowler gives you automated compliance checking. Nearly 14,000 stars on GitHub. Battle-tested. The AI Act requires you to document your infrastructure security, and this tool helps you actually do it instead of just writing policies.

Baserow — Open-source, GDPR-compliant database and automation platform. Relevant here because if you are building AI workflows and need to keep data processing inside EU jurisdiction, tools like Baserow let you self-host the operational layer. GDPR, HIPAA, SOC 2 compliant. The kind of infrastructure that makes "data sovereignty" a reality instead of a slide in a pitch deck.

Bearer — Code security scanning (SAST) focused on discovering privacy risks in your codebase. If you are building AI applications that process personal data, which is most of them, Bearer helps you find the exposure points before a regulator does.

What Builders Should Actually Do

Enough analysis. Here is what I think you should do if you are building AI products in Europe right now.

Do not wait for final guidelines. Build your AI systems with documentation-first architecture now. Log your training data provenance. Log your model evaluations. Log your deployment decisions. Not because the AI Act demands a specific format yet, but because any eventual format will require this underlying data. The companies that start documenting now will spend weeks on compliance. The ones that wait will spend months.

Build for portability. If your AI systems are tightly coupled to a single cloud provider or a single jurisdiction, you are vulnerable. Design your AI agent architectures so they can run in different environments. The regulatory map will keep shifting. Portability is insurance.

Treat compliance as a product feature, not a cost center. European customers, especially enterprise, will pay a premium for AI systems they can trust. If you can genuinely demonstrate compliance, not performatively but structurally, that is a differentiator. We build this into our work at HEIMLANDR because our clients need to ship products that their own customers trust.

Do not confuse the delay with permission to ignore the Act. €35 million fines are real. The 2027 deadline will arrive faster than you think. And the reputational risk of being the first company publicly fined under the AI Act is worth more than the fine itself. Prepare now, deploy later.

The Uncomfortable Truth

I am going to end with something that might make me unpopular in certain circles.

The EU AI Act, for all its problems, is trying to solve a real problem. AI systems that affect people's lives, their job applications, their loan approvals, their medical diagnoses, should be built responsibly. I believe that. We build with that principle at HEIMLANDR every day.

But the execution is failing. The timeline is wrong. The enforcement architecture is underfunded. The technical understanding embedded in the legislation is already outdated. And the pace of iteration is bureaucratic when it needs to be adaptive.

The result is the worst of both worlds. European builders carry the compliance burden without getting the trust dividend, because consumers do not know or care about the AI Act. And the companies building the most capable and potentially dangerous AI systems are not in jurisdictions where the Act applies.

From Jönköping, I watch this with the same feeling you get watching a friend make a slow-motion mistake. You can see exactly what is going to happen. You have said something. And they are doing it anyway.

The delay is not a gift. It is time being wasted. And the only people who can fix it are the ones building despite the friction. That is you. Ship things. Document what you build. Make the compliance argument a strength rather than a weight. And do not, whatever you do, let an 18-month extension become an 18-month nap.

We are building through this at HEIMLANDR. If you need someone to help you ship an AI product fast while keeping it defensible, that is what we do. From Sweden. For builders who do not have time to wait for Brussels to finish writing the rulebook.

Fredrik Brunnberg is the CEO of HEIMLANDR.IO, building AI and software solutions from Jönköping, Sweden. This is the daily HEIMLANDR briefing. If you found this valuable, share it with someone who builds things.

#EU AI Act#AI regulation Europe#software development Sweden#AI compliance#Nordic tech policy
F
Fredrik Brunnberg

VD & Skribent

VD för HEIMLANDR.IO. Punk rock-teknik från Jönköping, Sverige. Bygger AI-system, blockchain-infrastruktur och skriver om vart branschen faktiskt är på väg — inget ekokammare, ingen hype.