Council Post: Insufficient, Incomplete And Unenforceable: The State Of Modern AI Regulation
tags:Peter Garraghan, Founder and Chief Science Officer, Mindgard.

getty
Article 50 of the EU AI Act mandates strict disclosure and transparency measures for both AI providers (those who provide the AI models) and deployers (those who use models to build AI solutions). The measure entered full enforcement on August 2, 2026, and while this is a step in a positive direction, it highlights several issues about the state of AI regulation. As well-intentioned as the EU AI Act may be, its focus is too narrow whilst failing to define what “AI” means in a meaningful or actionable way.
This raises issues as these new transparency measures enter enforcement. When regulations are too broad to provide effective guidance, it isn’t precisely clear how businesses should proceed. Is there a more pragmatic way for vendors to build trust with their customers that does not involve waiting for regulators to take the lead? Ultimately, the future of AI governance won’t be driven by legislators but by domain experts who understand the specific safeguards and the response to serious events that lead to direct personal, financial or societal harm.
Modern AI Regulations Are Too Broad To Be Effective
To the average consumer, AI might feel very new. Yet the term Artificial Intelligence dates back to a workshop held at Dartmouth in 1956. The Artificial Neural Network—a model from which modern LLMs and agents are derived—was conceived in the 1940s. While the capabilities and sophistication of these AI models have improved by leaps and bounds (and generative AI has emerged), those same core principles still underpin many leading AI technologies.
While regulations like the EU AI Act have been geared towards addressing the operation of generative AI models, their language leaves much to interpretation. The type of AI model that has captured industry (and society)’s attention is just a small part of the much broader AI and Machine Learning category. Transparency is great in principle, but do vendors really need to disclose every piece of software that uses decision trees, logistic regression or k-nearest neighbor? If a software provider uses 1,000 different libraries, do they need to disclose each one? It is likely to be difficult for consumers to identify which disclosures are relevant to AI regulations amid an overwhelming flood of information.
To complicate matters, agentic AI (which, like AI, has existed as a concept for decades) is rapidly evolving in terms of both capabilities and adoption, and may very well already fall outside the bounds of current regulations. The EU AI Act mandates that providers must disclose if their AI solutions can generate or manipulate content (including text, audio and video), but AI agents are not designed to generate content, and instead perform and facilitate actions. Does that exempt AI agents from existing legislation? There’s a strong argument to be made that yes, it does, further underscoring the ineffective nature of today’s regulations.
Focusing On AI Is Not The Answer
Regulators need to consider what they are ultimately trying to achieve. It’s true that generative AI tools are being used to manipulate public interests, and governments are understandably fearful that a lack of regulation could lead to undesirable outcomes. AI allows bad actors to move so quickly and create campaigns so targeted that they can overwhelm individuals’ ability to identify and reject falsehoods. Fear has long been one of the primary drivers of regulation, along with prosperity and control. As a lucrative technology with the potential to damage the social fabric if left uncontrolled, AI ticks all three boxes.
The current hyper-fixation on AI is part of the problem. Regulators can improve their approach by focusing not on “AI” as a category of technology, but on the specific capabilities and features that make AI dangerous. Technology capable of manipulating images, audio and video has been available for decades, long before generative AI became readily available. If software can manipulate content and incite a reaction, isn’t that more important than whether a solution falls within the frustratingly broad definition of “AI?” Customers are better served when vendors are transparent about the capabilities their solutions offer, whether or not they fall under the modern interpretation of AI.
The issue is that too many organizations rely on regulations to inform their approach to AI and software development. Unfortunately, no one really knows how to regulate AI. Its capabilities, features and risks are evolving too quickly (and speculative fiction may have colored public perception of what the technology actually does). Software developers and AI providers using regulations as their primary source of guidance will quickly find themselves falling behind the real driver of change: industry standards and customer expectations.
Building Trust In Ways That Matter
The way a manufacturing company uses AI is very different from the way a healthcare provider leverages technology. It doesn’t make sense to expect broad, top-down regulations to cover these sector-specific use cases effectively. Organizations shouldn’t wait for governments to take the lead on AI governance. They should instead consider how AI is used within their industries and what safety, security and transparency standards their partners and customers expect. When it comes to transparency, it’s always better to be proactive than reactive. Why wait for legislators to catch up to agentic AI when you can put your own safeguards in place now—ones that cover all relevant capabilities and reflect what your customers actually want?
By adopting a more pragmatic approach to AI governance, you can build trust with your partners and customers without chasing today’s inconsistent and ineffective regulatory guidelines. Today, it’s the EU AI Act. Soon, a dozen different states will have their own guidelines, with more jurisdictions to follow. Some will be flexible, whereas some will be strict. The most effective and responsible approach to managing AI will come from those who ask the question “What if I replaced the word ‘AI’ with technology?”, backed with specific domain knowledge, an understanding of practical use cases and a vested interest in building trust with their customers.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?