Europe's AI Rule Book Is Getting Too Complex to Enforce. Here's What Experts Say Needs to Change
Europe's ambitious effort to regulate artificial intelligence and digital markets has created an unintended problem: the rulebook itself has become so complex that regulators, businesses, and even experts struggle to navigate it effectively. A new analysis from the Centre for European Policy Studies (CEPS) reveals that the EU's digital regulatory framework, which includes the AI Act, General Data Protection Regulation (GDPR), Digital Services Act (DSA), and dozens of other laws, has reached a critical turning point where managing what already exists matters more than creating new rules.
The scale of regulatory expansion is striking. In just 12 years, the number of EU digital laws grew from 20 in 2012 to 88 by 2024. While each law addresses real problems, the sheer interconnectedness of these regulations has created a maze that even specialized compliance teams find difficult to navigate. The result is uneven enforcement across member states, contradictory obligations for businesses, and a compliance burden that falls heaviest on companies operating across borders.
Why Is Europe's AI Rulebook Becoming Unmanageable?
The problem isn't that Europe is overregulating; it's that the regulatory system itself lacks coherence. Different laws use different enforcement models. The Digital Markets Act (DMA) operates through centralized EU-level enforcement, the DSA relies on a hybrid structure involving national authorities, the AI Act introduced a new institutional actor called the AI Office, and cybersecurity rules scatter responsibility across multiple national agencies. Meanwhile, the GDPR depends on independent data protection supervisors in each member state.
This fragmentation creates practical headaches. A company trying to comply with data governance rules, algorithmic transparency requirements, and interoperability standards across multiple laws may receive conflicting guidance from different authorities. Smaller firms and startups, which lack dedicated compliance departments, face disproportionate burdens. The enforcement inconsistency also undermines the EU's goal of creating a level playing field across the Single Market.
The CEPS Task Force, which convened more than 20 experts from industry, academia, civil society, and European institutions, identified a critical gap: regulatory ambition has grown faster than the capacity of member states and regulated firms to implement it. Only around 40 percent of legislative proposals come with impact assessments, and many digital laws haven't been evaluated at all to determine whether they're actually working.
What Do Regulators and Businesses Need Right Now?
Rather than proposing new legislation, the CEPS analysis emphasizes that the EU must focus on making existing rules work better together. The task force identified six key priorities for strengthening the digital rulebook without expanding it further:
- Strengthen coherence across laws: Ensure that overlapping regimes operate consistently and don't impose contradictory obligations, especially where they interact on data governance, algorithmic transparency, and interoperability requirements.
- Provide legal certainty: Give firms clear indicators of success for the DMA, verifiable outcome indicators and audit guidance under the DSA, and harmonized standards with practical, example-based guidance under the AI Act.
- Boost institutional capacity: Authorities at both EU and member state levels need more expertise to supervise complex digital systems, including specialized technical knowledge and continuous monitoring capabilities.
- Improve the Better Regulation process: The European Parliament and Council must strengthen impact assessments, evaluations, and burden reduction tools like REFIT and the Digital Omnibus to ensure legislative changes are grounded in evidence.
- Reduce unnecessary complexity: Systematically simplify the regulatory acquis following good process, with the goal of making regulation more streamlined rather than deregulating entirely.
- Enhance cross-border implementation tools: Maximize the potential of the SOLVIT network and Single Digital Gateway to reduce fragmentation and ensure consistent rules across member states.
The challenge is particularly acute for the AI Act, Europe's first horizontal regulation for artificial intelligence systems. While the AI Act introduced groundbreaking rules for high-risk AI applications, its implementation depends on clear guidance that many firms still lack. Harmonized standards and practical examples would help companies understand exactly what compliance looks like in practice.
How to Navigate Europe's Evolving AI Rulebook
For organizations operating in or selling to Europe, adapting to this regulatory environment requires a strategic approach. Here are practical steps to manage compliance as the rulebook continues to evolve:
- Map your regulatory exposure: Identify which EU digital laws apply to your business model, including the AI Act, GDPR, DSA, DMA, and cybersecurity regulations, then document how these rules interact and potentially conflict.
- Build cross-functional compliance teams: Create teams that span legal, technical, and product functions to ensure that AI systems, data practices, and platform governance all align with multiple regulatory frameworks simultaneously.
- Engage with regulatory guidance: Monitor updates from the AI Office, national data protection authorities, and digital services coordinators for clarifications and harmonized standards that reduce ambiguity in compliance requirements.
- Invest in documentation and audit trails: Maintain detailed records of AI system design decisions, data governance practices, and algorithmic transparency measures to demonstrate compliance across multiple regulatory regimes.
- Participate in industry coalitions: Join industry groups and standard-setting bodies that work with regulators to develop practical compliance frameworks and harmonized approaches across member states.
The broader context matters here. The EU's regulatory ambition reflects a deliberate strategic choice to prioritize fundamental rights and market stability over speed to innovation. However, that choice only works if the rules can actually be enforced consistently and understood clearly by those who must follow them.
The Draghi report, which examined Europe's competitiveness challenges, made clear that simplification is no longer a technocratic nicety but a precondition for productivity and competitiveness. As the CEPS analysis notes, the goal isn't to deregulate but to regulate better, with clearer structures, stronger institutions, and a much more coherent approach to the digital world.
For now, the EU's digital rulebook remains the world's most extensive regulatory framework for the digital economy. Its effectiveness in the coming years will depend not on adding more rules but on ensuring that the 88 laws already in place work together seamlessly, that regulators have the capacity to enforce them consistently, and that businesses receive the guidance they need to comply. The next chapter of European digital regulation will be written not through new legislation but through better implementation of what already exists.
" }