← Back
AI News

Bruegel note proposes replacing the AI Act's pre-market checks with liability and ex post oversight

A new policy note from Bruegel proposes a rebalancing of the EU's AI Act: reducing the ex ante controls for most AI providers, and swapping them for robust ex post control through a dedicated AI liability framework and new tools for…

AIMag.no
AIMag.no
September 24, 2026 · 8 min
Illustration of a digital brain behind a gavel and scales, with EU stars in the background.

Bruegel note proposes replacing the AI Act's pre-market checks with liability and ex post oversight

A new policy note from Bruegel proposes a rebalancing of the EU's AI Act: reducing the ex ante controls for most AI providers, and swapping them for robust ex post control through a dedicated AI liability framework and new tools for learning, monitoring, and enforcement. The proposal arrives at a moment when deregulation holds the political momentum in the EU – even as privacy organisations fight rule changes that make room for AI.

The Note That Names the Dilemma

The policy note, "The right balance: how to fix European Union artificial intelligence regulation" (Policy Brief 12/2026), was written by the economist Mario Mariniello and published by Bruegel, the Brussels-based economic think tank, on 11 June 2026 (Bruegel, fc25a818).

The core of Mariniello's argument is that the AI Act, as designed, does not solve the problem it is meant to solve. The note's summary states that the AI Act "is unlikely to protect against AI harms while minimising market distortion," and that the regulation "risks replicating the outcomes of the EU's General Data Protection Regulation of 2016, which has contributed to market concentration by disproportionately burdening smaller companies" (fc25a818).

That is a double attack on the same legislation: the AI Act neither provides adequate protection nor is neutral in the market. And it is not an argument for scrapping the regulation – it is an argument for rebuilding it.

Why Ex Ante Doesn't Fit AI

The AI Act is built as a product safety regime: risk-categorised systems, conformity assessments, and documentation requirements before a system is placed on the market. It is a model inherited from machinery safety and pharmaceutical approval, where the product is fixed and the failures can be anticipated.

Mariniello's point is that AI breaks this assumption (fc25a818). Language models and other learning-based systems behave differently in different contexts, and harms can arise long after the conformity assessment has been carried out, in usage patterns the developers could not have foreseen. A regime that concentrates its scrutiny before launch therefore either catches too little (the harm occurs anyway) or too much (bureaucratic burden without a safety gain).

The second half of the critique is structural. Bruegel points to the GDPR as a warning: the 2016 regulation contributed, according to the note, to market concentration because compliance burdens hit smaller companies harder than the big ones (fc25a818). That is Bruegel's claim, not an established fact – but the argument is familiar from the debate on European tech regulation: fixed compliance costs are regressive, and if you cannot afford to pay them, you lose. If the AI Act repeats this pattern, the EU risks protecting its citizens from AI harms by leaving the technology in the hands of the largest players alone.

The Trade: Less Pre-Approval for More Accountability

The solution in the note is framed as an explicit trade. From the summary: "A reduction in the AI Act's ex ante compliance burden for most AI providers should be traded for robust ex post legal control based on an ad hoc AI liability framework, together with new ex post tools for learning, monitoring, and enforcement" (fc25a818).

The logic is that if you ease the requirements before market launch, you must tighten them afterwards. A liability framework makes it possible for injured parties to seek compensation after harm has occurred, and the courts then become the place where risk assessment actually happens – concretely, case by case, with real facts about what went wrong. That is a different kind of scrutiny than paper-based conformity assessments: it rewards actors who can document that their system behaved responsibly, and it punishes those who cannot.

The new tools for learning, monitoring, and enforcement are meant to supplement this – but this is where the source material runs thin. The available Bruegel page is truncated mid-document, so the mechanical details of the liability framework and the monitoring tools cannot be quoted or verified from the excerpt (fc25a818). That is a genuine gap in the evidentiary basis: we know what Mariniello wants the direction to be, but not fully how he intends to build it.

The Context: Deregulation Has the Momentum

The note does not arrive in a vacuum. Mariniello himself places it in a political landscape where simplification and loosening have taken over: "A regulatory simplification programme, known as the Digital Omnibus and AI Omnibus, agreed in principle at EU level in May 2026, illustrates this orientation – it relaxes, among other things, the deadlines for the rules on high-risk AI systems," he writes (fc25a818). He notes that work to limit AI harms continues in parallel through the implementation of the 2024 AI Act (Regulation (EU) 2024/1689), drafts of the Commission's guidelines on classifying high-risk systems, and work on liability – "but it is deregulation that has the political momentum" (fc25a818).

That description is corroborated by independent coverage. The Digital Omnibus on AI, formally EU Regulation 1744/2026, became applicable on 27 July 2026, with a stated purpose that, according to Volkov Law Group, was explicitly to simplify implementation, reduce double regulation against existing EU frameworks, and give certain categories of obligations more time before enforcement kicks in (JDSupra, 23 September 2026, e89609c0). Concretely, that means the obligations for high-risk AI systems in Annex III are postponed to 2 December 2027 (e89609c0).

Resistance to the loosening is also visible. The privacy organisation noyb, known for having forced the EU's highest court to strike down previous data transfer agreements with the US, has attacked the latest changes to European privacy law made to make room for AI (The Register, 22 September 2026, 10a4c9b9). Max Schrems and noyb are central figures in this resistance, and the conflict shows that the question of how EU rules should be adjusted for AI is politically contested – it is not merely a technical matter of calibrating deadlines, but a fundamental trade-off between protection and innovation.

Bruegel's Counterpoint: Regulation as Strength

What separates the note from plain deregulation is its defence of the very idea of European regulation. According to Bruegel, "the EU regulatory framework based on the AI Act should be seen as a strength, not a weakness, for stimulating AI development. It can remove uncertainty, reduce harmful AI effects, stabilise demand, and foster technology adoption, thereby increasing investment" (fc25a818).

This is Bruegel's claim, not a documented finding – but the argument deserves to be taken seriously because it inverts the standard narrative. In this reading, regulation is not a cost companies must carry, but a predictability they can plan around: clear rules of the game reduce the risk that an AI venture ends up in legal grey zones, and that makes both buyers and investors willing to commit. The note also points out that the US lacks federal AI oversight tools (fc25a818) – meaning the European alternative is not "regulation versus the American model," but "repaired regulation versus piecemeal state-level rules and case law."

What Remains to Be Answered

Three caveats should follow this article going forward.

First: the details are missing. The Bruegel excerpt is truncated, so the mechanics of the proposed liability framework – who can sue, which burdens of proof apply, how "learning" and monitoring are concretely to be organised – are not available in the source material (fc25a818). Without that detail, one cannot assess whether the proposal actually compensates for reduced pre-approval, or whether the ex post oversight is a weaker protection dressed in stronger words.

Second: there are no documented reactions from the Commission, industry, or academia to the note in the available material. Assessments of whether the proposal is politically viable are therefore analysis, not reported fact. What can be established, however, is the political current it is swimming against: deregulation has the momentum (fc25a818), and the privacy community is already resisting loosening (10a4c9b9). A proposal to reshuffle the compliance burden rather than remove it must navigate between a deregulation-minded majority and an activist privacy wing – two groups that, for different reasons, may have little appetite for the compromise.

Third: Bruegel's claims about the GDPR's concentration effects and about regulation as an investment engine should be read as the think tank's analysis. The evidence behind both claims is disputed in the literature, and the note does not document them in the available excerpt.

What remains, nevertheless, is a concrete and unusual proposal in a debate that too often revolves around all or nothing. Mariniello is not saying the AI Act is wrong – he is saying it is wrongly engineered for the technology it regulates, and that the answer is to shift the weight from paper requirements before launch to accountability and legal control after harm. Whether the EU follows up is set to be one of the most important regulatory questions for AI in the period ahead. The deadline for the Annex III obligations now sits at 2 December 2027 (e89609c0) – it is by then that the debate over what applies afterwards must be settled.

AIMag.no
AIMag.no
The AIMag.no editorial team covers artificial intelligence, tools, research, and regulation.

Sources

  1. The right balance: how to fix European Union artificial intelligence regulation — www.bruegel.org
  2. Privacy group slams EU for changing the data rules to cater to AI — www.theregister.com
  3. The EU AI Act: The Digital Omnibus, the Current Timeline, and What to Do Now (Part II of II) | The Volkov Law Group - JDSupra — www.jdsupra.com