- Tuesday, September 8, 2026

On Aug. 2, the European Union began enforcing the first major piece of its Artificial Intelligence Act: the transparency rules, which require companies to label deepfakes and AI-written text on matters of public interest.

Weeks earlier, the same institutions had voted to push the law’s heaviest section, the rules for “high-risk” AI systems, back by 16 months, to December 2027. The reason: The technical standards and national regulators on which the law relies were not yet in place.

The people who wrote the world’s most ambitious AI law could not build the machinery to enforce it on their own schedule.



I have watched this from the inside. My company, ESBO Ltd., is a digital public relations and link-building agency in Plovdiv, Bulgaria, with about 20 employees and clients around the world.

Since February 2025, a business my size in the EU has had a legal duty to ensure that its staff has “a sufficient level of AI literacy.” Since last month, every draft an AI tool touches raises a question about whether it needs a label.

None of this has made a client safer. All of it takes time away from the work clients pay for.

Companies the size of mine do not have compliance departments. When a new rule arrives, the founder either reads it or pays a lawyer to read it, and the money comes out of the budget that would have covered the next hire.

A bank absorbs that cost without noticing. A 20-person agency, however, notices.

Advertisement
Advertisement

Europe has run this experiment once already. The General Data Protection Regulation was sold to Europeans in large part as a check on the big American platforms.

In the week after enforcement of that regulation began in 2018, websites cut their use of vendors for EU visitors by 15%, and they dropped small vendors first, according to a study in Management Science by Garrett Johnson, Scott Shriver and Samuel Goldberg.

Concentration in that market rose by 17%, and the vendors that gained share were those owned by Google and Facebook. Part of the effect faded within months, but it persisted in advertising, the category regulators cared about most.

A separate study in Marketing Science found that EU technology startups received about 26% fewer venture deals than their American counterparts after the law took effect.

Compliance regimes written with giants in mind end up protecting giants. Their smaller competitors cannot afford the attorneys, so they leave, and the market consolidates around the firms the law was meant to restrain.

Advertisement
Advertisement

Washington has flirted with the same design. Colorado enacted the first comprehensive state AI law in 2024 and built it on the European blueprint: risk tiers, impact assessments and a duty of care against “algorithmic discrimination.”

In May, after a postponement and a lawsuit by xAI, with the U.S. Justice Department joining, Gov. Jared Polis signed a bill that repealed the whole thing and replaced it with a narrower disclosure law that takes effect in January.

The one state that copied Brussels has already uncopied it, and Brussels itself has paused the hardest part of its own law.

More than 1,000 state AI bills and laws are now in some stage of the process. No company of my size can track them. In March, the White House asked Congress for a single national framework built on a plain principle: If something is legal for a person to do, it should not become illegal because software helped.

Advertisement
Advertisement

The Senate voted 99-1 last year against a blunt 10-year moratorium on state AI laws, and nothing has filled the gap since.

What should fill it is not complicated. Regulate the harm, not the tool. Fraud, discrimination and defamation are already illegal, and the statute books do not need a second copy with “artificial intelligence” in the title.

Put the rules that do need to be written at the federal level once, in language a business owner can read in an afternoon, and write in the small-business provisions on Day 1.

Brussels added simplified paperwork for small firms to its AI law only this year, two years after enacting it.

Advertisement
Advertisement

The European approach was sold as the careful one. Two years on, it has delivered a labeling rule, a 16-month delay and a high-risk rule book the bloc’s own regulators could not staff in time.

Colorado tried it and gave up. Congress does not need to run the experiment a third time to learn how it ends.

• Boris Dzhingarov is the founder and CEO of ESBO Ltd. (https://www.esbo.ltd/), a digital public relations and link-building agency based in Plovdiv, Bulgaria. He is a member of the Forbes Agency Council and the Fast Company executive board.

Copyright © 2026 The Washington Times, LLC. Click here for reprint permission.

Please read our comment policy before commenting.