· Alexander Lewisch

The AI Act in 2025 – What Happened So Far

Governance architecture, staggered deadlines, the GPAI dispute and national fragmentation: a stocktake

Digital illustration: an ‘EU AI ACT’ scroll beside a floating smart-city scene with a shield and a ‘Reality’ checkmark.
AI-generated image

The EU AI Act 2025: An Analysis of Implementation, Controversies and Global Positioning

Introduction: From Legislative Act to Lived Reality

The EU AI Act, adopted by the Council of the European Union in May 2024, was positioned as the world’s first comprehensive framework for regulating artificial intelligence (AI). Based on a risk-based approach that classifies AI systems into four categories (from unacceptable risk to minimal risk), the regulation pursues the dual objective of protecting the fundamental rights of EU citizens while creating a harmonised legal framework for innovation. Conceived as a regulation, it has direct effect in all member states without requiring national transposition.

This article now attempts to analyse the transformation of that legislative theory into operational practice in 2025. While the AI Act formally entered into force on 1 August 2024, the year 2025 was shaped by the first phases of its staggered applicability, the establishment of a new governance architecture and, crucially, by substantial implementation hurdles, a fragmentation of oversight and intense political controversy. For this reason, 2025 can already be seen as the year in which the practical and political enforcement problems began to call the legislative achievement into question.

Establishing the Governance Architecture

The regulation’s governance provisions in Chapter VII formally entered into force on 2 August 2025. This operationalised the three-part oversight structure consisting of the European AI Office, the AI Board and a scientific panel of independent experts.

The EU AI Office

The EU AI Office was already set up by a Commission decision on 21 February 2024 and took up its full operational activity on 2 August 2025. It is structured as an integral part of the European Commission (Directorate-General for Communications Networks, Content and Technology). The AI Office’s core responsibility lies in supervising and enforcing the novel rules for GPAI models and in ensuring a coherent application of the regulation across the Union, often in cooperation with national authorities. The AI Office was already highly active in 2025. It took the lead in finalising the controversial “Code of Practice” for GPAI models and published initial guidelines, for example on interpreting the prohibitions under Article 5 (in force since 2 February 2025) as well as reporting templates for serious incidents involving GPAI models (valid from November 2025).

The AI Board and the Scientific Panel

In parallel with the AI Office, the AI Board began its work on 2 August 2025. This body consists of senior representatives of the member states and has an advisory and coordinating function. It is meant to support the Commission and the member states in a “consistent and pragmatic application” of the AI Act. As a third pillar, the establishment of a scientific panel of independent experts was initiated in summer 2025. Its defined task is to provide scientific and technical advice to the AI Office, especially in assessing the systemic risks of GPAI models. The establishment of this panel, however, proceeded sluggishly. According to reports, the panel’s work was subject to delays, and a call for applications for experts ran until mid-September 2025. This indicates that the panel was not yet fully operational at the end of 2025.

The AI Act’s governance structure thus started in 2025 with a significant operational imbalance. The centralised, executive body was fully operational and drove the agenda forward, particularly on GPAI regulation. By contrast, the bodies intended as a corrective lagged massively behind: the independent scientific panel, whose expertise is essential precisely for GPAI assessment, was delayed, while the decentralised supervisory authorities in the member states, responsible for on-the-ground enforcement, had not even been designated in key countries such as Germany. This power vacuum strongly concentrated operational authority in the European Commission during the critical initial phase of implementation.

Illustration of the EU AI Act's governance architecture.

Staggered Applicability – Analysis of the 2025 Implementation Phases

2 February 2025 – The Prohibitions

The first wave of applicability entered into force on 2 February 2025. Since that date, the prohibitions on AI practices with unacceptable risk apply (Chapter II, Article 5). Crucially, these prohibitions also apply to systems that were already placed on the market before this date. Companies were thus forced to subject their existing systems to an immediate re-evaluation. Also since February 2025, the “AI Literacy” obligations under Article 4 apply, requiring providers and deployers to undertake training measures.

2 May 2025 – A Missed Deadline: The GPAI Code

Under Article 56(9) of the AI Act, the “Code of Practice” for GPAI models was to be completed by 2 May 2025. This deadline was missed owing to the complexity and the controversial negotiations with industry. The final code was published only in July 2025.

2 August 2025 – GPAI and Governance

The second wave of applicability entered into force on 2 August 2025. Since that date, the obligations for providers of GPAI models apply (Chapter V). At the same time, the governance provisions (Chapter VII) and the provisions on confidentiality and penalties (Chapter XII) became applicable. The penalties are draconian and run up to 35 million euros or 7 % of worldwide annual turnover for breaches of the Article 5 prohibitions.

The staggered implementation created a “compliance backlog” in 2025, characterised by an asynchrony between legal obligation and legal enforcement. Since February 2025, using a prohibited system (Art. 5) is unlawful and can in theory be penalised. At the same time, as will be explained later, key member states such as Germany had not even designated the supervisory authority responsible for enforcement as of August 2025. These cases of applicability without an executive created a period of legal uncertainty that provided fertile ground for lobbying against the AI Act’s provisions.

The Article 5 Prohibitions in Practice

The entry into force of the prohibitions on AI with unacceptable risk on 2 February 2025 marked the regulation’s first practical test. The immediate publication of Commission guidelines on interpreting these prohibitions just two days later (4 February 2025) underlines the high degree of legal uncertainty surrounding these provisions. Contrary to public perception, the Article 5 prohibitions are legally “soft”, as they are characterised by indeterminate legal concepts and far-reaching exceptions.

Civil-society organisations such as AlgorithmWatch sharply criticised the drafts of the Commission guidelines. They warned that the law was full of serious loopholes. The core criticism is that certain prohibitions, for example on predictive policing, needed to be made more precise and expanded, and that regulation should be guided not by technical complexity but by potential consequential harm.

The entry into force of the prohibitions was thus not the end of these practices, but the beginning of an intense legal dispute over their interpretation. While court decisions were still pending at the end of 2025, initial trends emerged in administrative enforcement, as national data protection authorities (DPAs) began to use the delays in national transposition and the resulting governance vacuum to seize the competences for themselves. In Spain, the data protection authority (AEPD) announced that, on the basis of its existing powers under the GDPR, it could take action against prohibited AI systems under Art. 5 that process personal data, even before the AEPD is formally appointed as the AI supervisory authority. This means that enforcement of the AI Act is being strongly steered towards data protection law.

The Epicentre of the 2025 Controversy: The Regulation of GPAI

While GPAI models had previously been treated merely as one of four risk tiers with transparency obligations, this topic developed in 2025 into the central controversy over the future of the AI Act. Since 2 August 2025, providers of GPAI models have been subject to the obligations under Article 53, i.e. primarily technical documentation and compliance with EU copyright law. Providers of GPAI models with systemic risk are additionally subject to the stricter obligations under Article 55, i.e. assessment of systemic risks, rigorous testing and cybersecurity.

To give concrete form to these abstract legal obligations, Article 56 provides for a voluntary code of practice (CoP – Code of Practice), which has increasingly become a flashpoint. Compliance with it grants providers a presumption of compliance, which massively reduces administrative burden and legal uncertainty. This expert-developed code missed its original deadline (2 May 2025) and was only published and confirmed as adequate by the AI Office on 10 July 2025. Immediately after publication, a scandal erupted that split the “Big Tech” industry. While Google (Alphabet) announced on 30 July 2025 that it intended to sign the code, and Microsoft expressly endorsed the code of practice, Meta (Facebook) refused to sign the CoP. Google’s agreement, however, came with sharp reservations, as Google representatives publicly voiced the concern that the AI Act and the code would slow Europe’s development and deployment of AI and jeopardise its competitiveness. Meta described the code as ambiguous, excessive and a threat to growth. Meta stressed that it would adhere to the AI Act but not to the voluntary code.

Meta’s refusal poses a direct strategic challenge to the Commission’s entire enforcement mechanism. The AI Office’s plan was based on establishing the CoP as a scalable compliance path. Meta now decouples the voluntary code from the mandatory law and forces the AI Office to assess the compliance of Meta’s models directly against the abstract legal text of Art. 53/55. For the new authority, this is a resource-intensive and legally high-risk path. This dispute politicised the entire implementation. The technical criticism of the CoP, which was also shared by industry associations such as the CCIA and European corporations such as Siemens, SAP and Airbus, culminated in the political demand for a halt to the regulation or at least a regulatory pause (“potential EU AI Act pause”).

National Implementation Strategies Compared

Although the AI Act is conceived as a regulation that applies directly and aims at harmonisation, it requires member states to designate competent national authorities and market surveillance authorities. The deadline for this was 2 August 2025. In practice, this process led to a paradoxical outcome in 2025. Instead of harmonisation, a profound regulatory fragmentation emerged. As early as November 2024, only 3 of 27 member states had clearly designated their competent authorities.

Austria

Austria’s implementation strategy in 2025 was marked by delays and a lack of regulatory clarity. Although the country proactively set up an “AI service point” (AI Service Desk) at the Broadcasting and Telecommunications Regulatory Authority (RTR-GmbH), this serves primarily as an information and contact point for companies. Crucially, Austria did not meet the deadline of 2 August 2025 for designating the central market surveillance authority and the notifying authority. A corresponding national implementing law, originally expected in the first quarter of 2025, has still not been passed. Although an “AI implementation plan” and a list of 19 bodies for the protection of fundamental rights (under Article 77) were published in November, the core responsibility for market oversight remained vacant. This regulatory uncertainty meets an economy which, according to studies (e.g. McKinsey “State of AI in Austria 2025”), lags behind the EU average (34) in AI maturity (AIQ score 30). Only 20 % of Austrian companies stated that they possessed a formulated AI strategy.

Germany

Germany missed the deadline of 2 August 2025 for designating its supervisory authority. This situation led to massive legal uncertainty for companies and sharp criticism from data protection advocates, who warned of a control gap and a lack of points of contact. The political debate in Germany within the framework of the AI Market Surveillance Act is currently still ongoing and revolves around competence: the Federal Network Agency, the data protection authorities or a newly created authority.

Italy

Italy pursued a diametrically opposed, proactive approach. The government enacted a comprehensive national AI law of its own (Legge No. 132/2025), which entered into force on 10 October 2025. This law supplements the AI Act and introduces additional national rules (“gold-plating”). These include extended transparency obligations for employers when using AI in the workplace and a new criminal offence for the unlawful dissemination of AI-generated content (deepfakes), punishable by one to five years’ imprisonment. The designation of the supervisory authorities was delegated by the law to the government.

France and Spain

France announced a national oversight plan in September 2025 that appears to be heading towards a division of competences among existing regulators such as the data protection authority, the competition authority and the media regulator. Spain, which plans to set up a dedicated AI authority (AESIA), was confronted with a proactive declaration of competence by its data protection authority (AEPD).

These developments undermine the core objective of a harmonised single market. A provider of AI operating in the EU in 2025 faces a regulatory vacuum in Germany, additional criminal statutes in Italy and a sectoral patchwork in France.

The “Brussels Effect” Put to the Test

The hope that the AI Act would trigger a “Brussels effect” and become the de facto global standard remains highly contested in 2025. For instance, the political scientist Ben Crum insists that the AI Act is not a classic “Brussels effect”. He assumes that AI, unlike earlier regulatory topics such as data protection, is characterised by fundamental uncertainty and existential risk. Crum suggests understanding the AI Act not as a global standard but as experimental regulation, one regional approach among many that would have to evolve cooperatively.

The EU finds itself in a geopolitical dilemma in 2025, as it is isolated with its path of human-centred regulation. While the USA relies on active deregulation and, under President Trump, has already reversed initial AI safety requirements, China is forcing state-driven technology development. When US companies such as Meta begin openly to reject EU compliance mechanisms such as the code of practice, and the US government politically backs this through deregulation, the EU’s global standard-setting power erodes. From the US perspective, the previous paradigm “the U.S. innovates, and the EU regulates” largely persists in 2025 as well.

Illustration of the EU AI Act's global positioning.

The AI Act in Everyday Life in 2025: First Visible Implications

In the everyday life of citizens and companies in 2025, the effects of the AI Act are twofold: transparency for citizens under Article 50 and obligations for companies under Articles 4 & 5. The AI Act thus acts simultaneously as a consumer-protection information law and as part of employment and organisational law.

For citizens as consumers of media, the “soft” transparency obligations of Article 50 are the most visible. When using chatbots, users must be informed that they are interacting with an AI system. Artificially generated or manipulated audio, image or video content must be labelled as such. In view of global concerns about disinformation and new national laws, the EU Commission is actively advancing this topic and, on 5 November 2025, began work on a separate “Code of Practice on labelling AI-generated content”.

For companies as deployers and employers, the effect is hard and mandatory. The obligation under Article 4 (AI Literacy), in force since February 2025, to ensure “AI competence” among staff who operate AI systems (especially high-risk systems) creates a new compliance and education sector. Companies are obliged to invest in training and to build governance structures. Despite this legal obligation to build AI competence in companies, a new representative survey by the digital association Bitkom shows that in Germany only 20 % of employees receive AI training and that 70 % of firms ignore the AI training obligation entirely.

For companies there is also the prohibition on using emotion recognition in the workplace and in educational institutions (Article 5 – prohibition of emotion recognition), which has been legally binding since February 2025 and makes the use of corresponding HR or education software illegal.

Conclusion and Outlook: The Future-Proofing of the AI Act

The year 2025 marked the transition of the AI Act from legislative ambition into operational reality. The milestone described in 2024 was put to the test in 2025 by four key factors. The (1) establishment of central governance (AI Office) is counteracted by (2) decentralised fragmentation through national delays. The (3) entry into force of the first legal consequences is almost ineffective, because their enforcement is uncertain for lack of authorities. Added to this is the (4) strategic conflict with global GPAI providers, which threatens and calls into question the timetable and the core of the regulation.

The European Commission is therefore already planning to water down central parts of its historic law regulating artificial intelligence, or to delay their introduction. This is happening in response to massive pressure from US technology corporations and the US government. The EU is thus considering a grace period for companies, the suspension of fines until August 2027 and certain simplifications and exceptions. A decision on these measures was to be taken in November 2025, in order to strengthen the EU’s competitiveness vis-à-vis the USA and China and to allay industry concerns about excessive compliance costs and innovation barriers. While business representatives welcome the plans as a necessary step to avoid stifling innovation in Europe, civil-rights and data-protection organisations are alarmed, warning that these changes could hollow out safety standards and weaken the protection of citizens.

The AI Act thus threatens to fail operationally even before its most important provisions for high-risk AI systems enter into force in 2026. The implementation of the supposedly simpler governance and GPAI rules in 2025 was meant to be the preparation phase. In essential parts, it has failed. If the EU already fails at establishing the structure, it is seriously in doubt how it intends to enforce the coming substance in 2026.

Originally published at SEQIS Blog