The European Union’s attempt to create a comprehensive, rights-focused framework for artificial intelligence has produced rules that are now too brittle to adapt to rapid technological change, researchers say.
Rigid rules, limited enforcement
A study by academics from the University of Exeter, the European University Institute and the University of Lausanne concludes the EU’s architecture for AI regulation — designed to anticipate risks and impose broad “guardrails” — has instead trapped regulators in a system that is hard to update and difficult to enforce.
Because the rules required lengthy political negotiation to create, the authors write, they are “difficult to change but not to remove,” producing what the paper calls a “rigidity trap in action.” Recent legislative moves underscore that point: the EU’s 2024 AI Act, which had been expected to take effect this year, was followed by a 2026 AI Simplification Act.
“The EU regulatory architecture is grounded in the ambition to anticipate the evolution of AI risks and protect the values identified by the EU institutions. It is a guardrails-oriented architecture. Because of this clearly prescriptive orientation, the EU seeks to impose rules. Implementing a comprehensive structure of guardrails is a difficult task in AI regulation. Companies and courts are already attempting to edit and change the final outcomes of the AI Act.”
Contrast with U.S. approaches
The researchers contrast the EU’s model with what they describe as a more pragmatic U.S. pattern: intervention tends to be sector-by-sector or targeted only when specific risks become evident. That patchwork approach, they argue, creates more concrete, enforceable rules and offers room to learn from experience across states and industries.
The study suggests the U.S. approach — sometimes developed organically and reactively — produces “regulatory leashes” that can be tightened or loosened in response to emerging problems, whereas the EU’s comprehensive guardrails are less flexible.
Why this matters
For policymakers and industry, the findings spotlight the trade-offs between trying to foresee and codify all future harms and building systems that can evolve. The EU’s stated goals include promoting trustworthy, human-centred and rights-respecting AI, but the authors warn the current framework may lack the practical capacity to deliver those outcomes.
- Prescriptive EU model: aims to anticipate risks and set comprehensive rules; risks becoming inflexible.
- U.S. model: intervenes when clear risks emerge, often sectorally or state-led, yielding more enforceable, adaptive rules.
- Recent shift: EU’s 2024 AI Act followed by the 2026 AI Simplification Act signals partial retreat and reworking.
| Feature | EU (per study) | U.S. (per study) |
|---|---|---|
| Regulatory style | Comprehensive, prescriptive guardrails | Targeted, sector/state-driven |
| Adaptability | Low — hard to change | Higher — can respond to specific risks |
| Enforceability | Limited by complexity and rigidity | More concrete and enforceable |
The paper warns that an effort to anticipate every AI risk in one statute can hinder the development of adaptive regulatory tools and may limit the capacity to protect human rights and other public values effectively. For governments crafting AI policy, the study offers a cautionary note: a well-intentioned, all-encompassing framework can become operationally fragile as the technology it seeks to regulate evolves.
Because the analysis focuses on structural characteristics of regulation rather than specific technologies or companies, its arguments are relevant beyond Europe. National governments and regulators that balance durability, enforceability and flexibility in their AI rules will have to weigh whether prescriptive guardrails or more incremental, problem-driven measures better serve public-interest objectives.