American start-ups capture 61 % of global AI funding. European ones capture 6 %. That figure does not come from a lobby group: it comes from the report Mario Draghi delivered to the European Commission.
It has since become the killer argument for anyone claiming that Europe shot itself in the foot by regulating AI. The reality is more interesting, and the valid criticism lies elsewhere.
The number that frames the whole debate
The Draghi report on the future of European competitiveness, delivered on 9 September 2024, quantifies the funding gap between Europe and the United States and puts Europe's investment need at 800 billion euros a year, or 4 to 5 % of EU GDP.
The figure still deserves a careful reading. A funding gap measures capital flows, not the causal effect of a piece of legislation. Europe's venture capital lag largely predates the AI Act, which was not in force when those gaps opened up.
It remains true, it comes from the Commission itself, and it puts the debate at the right level: not the compliance form, but Europe's place in an industry being built right now.
What the AI Act actually requires today
Before forming an opinion, you need to know what applies. Most commentary concerns obligations that do not exist yet, or that target someone other than who people assume.
- 2 February 2025: prohibited practices and AI literacy. Applies to providers and deployers, proportionate to context.
- 2 August 2025: governance, penalties, general-purpose models. Mainly model providers.
- 2 August 2026: most of the regulation, including the Article 50 transparency duties. Depends on your role and your use case.
- 2 December 2027: Annex III high-risk systems. Biometrics, employment, creditworthiness of individuals, education, critical infrastructure.
- 2 August 2028: high-risk systems embedded in regulated products, Annex I.
One point of vocabulary decides almost everything. The AI Act distinguishes the provider, who designs or commissions the system and places it on the market under their own name, from the deployer, who uses it under their own authority. Their obligations differ.
Under Article 50, it is the provider who must design a system that informs people they are interacting with an AI, unless that is obvious from the context. Technical marking of synthetic content also falls on the provider. The deployer must disclose deepfakes and certain texts published to inform the public on matters of public interest, with an exemption where the content has undergone substantive human review together with editorial responsibility.
A small business plugging in a third-party conversational agent is therefore, in principle, a deployer. It must check that the notice appears, not build it. But it becomes a provider again if it has the tool developed and puts it into service under its own brand, which is common and rarely recognised.
What changed in July
The high-risk regime was postponed before its application date had even arrived. The rest of the regulation was already in force.
The timeline is public. The Commission tabled its digital simplification package on 19 November 2025. The Council agreed its mandate on 13 March 2026, Parliament its position on 26 March, and the co-legislators reached agreement on 7 May. Regulation (EU) 2026/1744 was published on 24 July and entered into force on 27 July.
It postpones Annex III to 2 December 2027 and Annex I to 2 August 2028. It extends simplifications reserved for SMEs to small mid-cap companies, and provides a transition for marking certain generative systems already on the market.
But calling it deregulation would be inaccurate, and that matters for what follows. The final text restores a simplified registration duty, keeps a strict necessity test for certain sensitive data processing, and adds new prohibited practices. It is a mixed text, not a rollback.
The real criticism, and it is more serious
You often read that Europe legislated on AI without measuring anything. That is false, and it should be said plainly.
The 2021 proposal came with a formal impact assessment, comparing several options and costing compliance. The work was done.
The problem is its date. That assessment describes the state of technology and markets in 2021, before generative models spread widely and long before agents. It still underpins the architecture of the regulation today.
And for the 2025 to 2026 reform, which touched deadlines, AI literacy, registration, sensitive data and the allocation of supervisory powers, the Commission produced no separate impact assessment. It considered the changes technical. The European Parliament's research service explicitly notes that absence, along with the relative brevity of the consultations.
The defensible criticism is therefore not that Europe decides blindly. It is that the original assessment predates the generative shift, and that the accelerated revision was never reassessed in proportion to what it actually changed.
The data protection authorities say much the same. In their joint opinion, the European Data Protection Board and the European Data Protection Supervisor support the simplification objective while contesting specific points: the loosening of AI literacy requirements, the removal of certain registration duties, and the widening of sensitive data processing for bias detection. Their position is neither "change nothing" nor a blanket condemnation of the method.
What industry says when you listen to all of it
On 12 May 2026, Arthur Mensch, chief executive of Mistral, testified under oath before the French National Assembly's committee of inquiry into digital dependencies and vulnerabilities. The clip that circulated shows a French entrepreneur looking at the regulatory mood and leaving for the United States.
The full hearing says something else, and it is more interesting.
When he describes what costs him most, he does not point at the AI Act. He points at the absence of a single market, which he calls the "main burden": a legal entity to open in every country, hundreds of documents to sign, dozens of bank accounts, a different stock option regime and different labour law at every border, and unharmonised taxation.
The AI Act comes only afterwards, in a criticism of accumulation: GDPR, copyright and text and data mining, AI Act, three frameworks covering neighbouring subjects without saying the same thing, enforced by twenty-seven authorities of varying zeal.
The distinction is not splitting hairs. If the AI Act were the problem, easing it would be enough, which has just happened without anyone declaring the problem solved. If the problem is the fiscal, social and banking fragmentation of twenty-seven markets, no amount of AI Act flexibility will change it.
A second point, and it is the strongest in the hearing: Mensch says Mistral absorbs this burden "because we are big enough", with five people dedicated to compliance. A thousand-employee company absorbs a fixed cost. A fifteen-person business does not.
This is the argument that should dominate the debate and never does: fixed-cost regulation does not penalise Europe, it penalises small players in favour of large ones, on both sides of the Atlantic.
One caveat. Mensch runs a company that stands to benefit directly from regulatory relief and from European public procurement. He spoke under oath, which commits the sincerity of his testimony, not the accuracy of his forecasts. His field observations are valuable, his extrapolations need checking.
The debate's numbers, put to the test
The macroeconomic thesis put forward at the hearing runs as follows: if Europe buys its artificial intelligence abroad, it adds a massive trade deficit to the one it already carries on digital services. The reasoning holds. The arithmetic, less so.
- "At Mistral, AI accounts for 10 % of payroll." An unaudited internal statement. To be attributed, not generalised to a company that does not build the technology.
- "10 % of European employee compensation, or 1,000 billion." Compensation of employees is 48.0 % of an EU GDP of roughly 18,800 billion, so close to 9,000 billion. Ten per cent is about 900 billion. Coherent order of magnitude.
- "400 million people times 10,000 euros, or 8,000 billion." The product is 4,000 billion. And the EU has 452 million inhabitants but roughly 221 million people in employment, which would give about 2,200 billion. An arithmetic error compounded by a population error.
- "One kilowatt per equipped employee, half a GPU." No public methodology. Not verifiable as it stands.
- "France has 9 GW, or 90 TWh a year." Nine constant gigawatts would produce 78.8 TWh. RTE separately measured 92.3 TWh of net exports in 2025. A loosely defined approximation rather than an error.
The third line is the one that matters, and the error is not only arithmetic: it mixes total population with working population, two quantities that differ by a factor of two. Between 900 billion and 8,000 billion there is no nuance, there is the difference between a large market and a market that would rewrite European GDP.
This is not an accusation of dishonesty: these are orders of magnitude offered in spoken testimony. But they now circulate without their caveats, and states are being asked to commit hundreds of billions on that basis.
One more limit, which Mensch states himself: he acknowledges the lack of hindsight and notes that continuous delegation of tasks to an agent has only worked for six months. The productivity gains he cites, including a factor of five in some customer service operations, are observations reported by a vendor about its own clients, without protocol or control group. Available estimates remain early and hard to generalise.
The question the regulatory debate hides
While we argue about forms, a physical constraint is advancing quietly.
Mensch describes his business as turning electrons into compute, and proposes thinking of artificial intelligence as a resource whose supply must be secured. He argues the current constraint sits on the supply side rather than demand: what is missing is chips, memory and electrons.
The quantities must not be confused, however. 9 GW is a power rating, 90 TWh an annual energy volume. An observed annual export balance is neither a guaranteed reserve, nor firm capacity available at any hour, nor grid connection capacity where data centres would actually be built.
That said, the hearing raises a question we put forward here as our own, and it remains conditional. If new concentrated loads increase grid scarcity or investment needs, their costs may be spread beyond the direct users of AI alone. Settling that would require examining network tariffs, capacity mechanisms and infrastructure financing. A parliamentary hearing does not suffice.
But if the hypothesis holds, the debate changes nature. The question is no longer whether Europe regulates too much, but who pays the energy bill for a technology whose gains are very unevenly distributed. And this is a field where decisions are slow: a rule can be amended in eighteen months, as the Omnibus has just shown. A grid connection cannot.
What a small business should actually do
The debate is geopolitical. Your situation is not. Five actions, in this order.
- Qualify your role, system by system. Are you a provider, deployer, importer or distributor? That answer determines your obligations, not the technology involved. A company can hold several roles across different tools.
- Check transparency, including other people's. For a conversational agent, make sure the notice appears from the first interaction, and keep a record that you checked. The design obligation sits with the provider, but the diligence is yours.
- Keep a one-page inventory sheet per system. Purpose, provider, data processed, people affected, internal owner, oversight, incident procedure. That sheet is not proof of compliance, it tells you which further analyses to trigger.
- Promote AI literacy, and document what you do. Since 2 February 2025, providers and deployers must take measures suited to the context and to what the people involved already know. General awareness, plus specific guidance for the most exposed roles, beats identical training for everyone.
- Do not order a high-risk audit without prequalification. Most ordinary administrative uses do not fall into it, but qualification depends on purpose. The credit use case in Annex III concerns creditworthiness assessment of natural persons, not every financial operation. Qualify before you audit.
Our take
The question is not whether we need more rules or fewer. It is whether each change answers an identified problem, with measured effects and a burden proportionate to company size.
The AI Act rested on an impact assessment, but it dates from 2021, before generative AI spread widely. The Omnibus answers genuine implementation difficulties, notably the absence of technical standards in time, but the Commission produced no separate impact assessment for that reform. And the final text mixes postponements, simplifications, restored safeguards and new prohibitions.
Arthur Mensch's testimony usefully shifts the debate. The legal, fiscal, social and banking fragmentation of the European market probably weighs more on a company's international growth than the AI Act taken alone.
That is the debate's blind spot. We argue about whether Europe regulates too much, never about who pays for the rule. An identical obligation costs the same to a thousand-person company and to a fifteen-person one, which amounts to protecting incumbents.
For you, the approach stays proportionate. Qualify your role for each system, keep an inventory, check the transparency obligations, promote AI literacy, and only commission a specialist audit once you have identified a purpose or a risk that warrants it.
support_agentDeploying AI in your business?
We help Belgian small businesses qualify their role, inventory their systems and check their transparency obligations, without selling an audit you do not need.
Get in touchchevron_rightReferences & further reading
- Regulation (EU) 2026/1744, AI Omnibus, EUR-Lex
- Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence
- Draghi report on the future of European competitiveness, European Commission
- Eurostat, income components of GDP
- French National Assembly, committee of inquiry into digital dependencies and vulnerabilities, hearing of 12 May 2026, official report no. 42