The Closing Window
The roots of AI governance are setting now. The shape of the next decade is being decided by who is inside the standard before it hardens, not by who reads it after.
Future Proof Intelligence. Research. No. I. MMXXVI
Abstract
There is a widespread assumption that the rules governing artificial intelligence are still being written, that the field is open, and that there is time to position once the law is final. This paper argues the assumption is wrong in a specific and consequential way. The binding text of European AI law has existed since 2024. What is being decided now, in 2026, is not whether there will be rules but what those rules mean in practice: which technical standards carry the presumption of conformity, which conformity routes a system must pass, what an insurer will underwrite, what a certification must attest. That meaning is being set in a soft state, by standards bodies, codes of practice, conformity infrastructure, and an insurance market, and it is about to set hard. We trace the real 2026 state of play: the phased EU AI Act timeline, the prohibited practices already in force, the obligations on general-purpose models, the deferral of the high-risk regime and what that deferral actually reveals, the standardisation bodies, the relocation of liability into a strict product regime, and a hardening AI insurance market. Governance of this kind is decided at the root, before the visible structure exists, by whoever is operating there while it is still soft. The window for that is closing on a published schedule. This paper describes the window, why it closes, and what it means to already be inside it.
1. The premise: law is the visible part of a much larger structure
1.1 What people think is happening
Ask a serious operator what the state of AI regulation is, and the answer usually arrives in the future tense. The rules are coming. The Act is being finalised. We will see what the obligations look like and then decide how to position. There will be guidance. There will be standards. There will be time.
Every clause of that answer is reasonable and every clause of it is a misreading of where the structure actually is. The binding instrument has existed for years. The European Union's Artificial Intelligence Act, Regulation (EU) 2024/1689, was published in the Official Journal of the European Union on 12 July 2024 and entered into force on 1 August 2024. It is the first comprehensive horizontal law for artificial intelligence in any major jurisdiction. It does not become real in some future year. Parts of it are operative now, parts became operative in 2025, and the question of what the rest of it means is being answered this year, in 2026, by a process most operators are not watching.
The misreading matters because it produces a posture of waiting. Waiting is the wrong posture for a structure that is being decided in a soft state and is about to set. By the time the structure is visible enough to react to, the reacting will be to something already shaped.
1.2 The law is not the structure. It is the surface of the structure
A statute of this kind is a shell. It states requirements at the level of principle: a high-risk system must have a risk management system, must be trained on appropriate data, must be transparent to its deployer, must allow human oversight, must be accurate and robust and secure. These are not operational instructions. They are placeholders. Each one points downward to a layer where the principle is given an operational meaning precise enough to test against.
That lower layer is where governance actually lives. It is made of harmonised technical standards, common specifications, conformity assessment procedures, codes of practice, the decisions of an emerging institutional apparatus, and, running alongside all of it, the underwriting judgements of an insurance market that has to price the risk whether or not the public layer has finished defining it. None of that lower layer is in the statute. All of it determines what the statute does to you.
This is the central observation of this paper, and it is structural rather than rhetorical. The visible part of a governance system, the law, is the part that arrives last and changes least once it exists. The part that decides what the law means arrives earlier, changes constantly while it is forming, and then stops changing. It hardens. After it hardens, the meaning of the law is fixed not by anyone reading the law but by the settled state of the layer beneath it.
We will use one figure throughout this paper to hold the idea.
Figure 1. The visible layer and the load-bearing layer. Imagine the governance of a technology as a structure with two parts. The visible layer is the statute, the headline, the deadline, the fine. It is what gets reported and what most people mean when they say "the regulation." Beneath it sits the load-bearing layer: the standards that define what a requirement actually demands, the conformity routes that decide who has to be checked by whom, the codes of practice that decide what counts as good behaviour, the certifications that travel as proof, and the insurance that decides what is fundable at all. The visible layer is read. The load-bearing layer is built. While the load-bearing layer is still being built it is soft and it can be shaped. Once it is built it is hard and it can only be complied with. The shape of the next decade is set during the soft phase, by whoever is present in it, and is then inherited by everyone who arrives during the hard phase.
The rest of this paper is an account of where, precisely, the load-bearing layer of AI governance is in 2026, why it is still soft, why it is about to set, and what it means to be operating inside it now rather than reading about it later.
1.3 The pattern is not new, only fast
There is a reason to trust this two-layer reading beyond the AI case, and it is worth establishing before we get to the specifics, because it inoculates the argument against the objection that artificial intelligence is sui generis and that nothing about prior technology tells us anything useful. The objection is wrong, and the way it is wrong is instructive.
Consider how the safety of pressure equipment, electrical goods, machinery, medical devices, and toys is actually governed in the European single market. In each case there is a directive or regulation that sets essential requirements at the level of principle. In each case the operative content, the numbers, the test methods, the tolerances, the documentation, lives in harmonised standards drafted by standardisation bodies, and conformity with a cited standard yields a presumption of conformity with the law. This is not a workaround or a degeneration. It is the deliberate design of the European New Legislative Framework, and it has governed the safety of an enormous share of physical commerce for decades. Anyone who has placed a regulated product on that market knows that the binding directive is the thing you cite and the harmonised standard is the thing you actually engineer to.
What is genuinely new about the AI case is not the structure. It is two things layered on top of the structure. First, the requirements being delegated to standardisation are not bolt torques and insulation thresholds; they are fairness, contestability, oversight, and the treatment of fundamental rights, which raises the stakes of who drafts them by an order of magnitude. Second, and this is the part this paper most wants the reader to feel, the technology underneath is moving faster than any technology this framework has ever been pointed at, which compresses the soft phase. The same two-layer structure that took a decade to set around a class of machinery is being set around general-purpose artificial intelligence in a window measured in a few years. The pattern is old. The speed is not. A slow-setting structure can be joined late. A fast-setting one cannot, and the people who treat the AI case with the patience appropriate to the machinery case will discover that the appropriate patience was calibrated to a different clock.
1.3 Why this is not a story about Europe
It would be easy to read what follows as a European compliance briefing. It is not. The European instrument is the case in front of us because it is the most developed and the most documented, but the argument is about a mechanism, not a jurisdiction. Wherever a major economy regulates a general technology, the same two-layer structure appears: a visible statute and a load-bearing layer of standards, assessment, certification, and insurance that decides what the statute means. The mechanism by which a regional rulebook becomes the operative global default has a literature of its own, and we will return to it. The point to hold from the start is that the closing window is not a European deadline. It is the moment, in any such system, when the soft layer stops being shapeable.
2. The real 2026 state of play
This section is deliberately concrete. Every date and obligation in it was verified against current sources in 2026 and is recorded in the notes. We are precise here because the entire argument depends on the difference between what people assume the timeline is and what it actually is.
2.1 The phased design
The AI Act does not switch on all at once. It was built to apply in phases, and the phases are the thing to understand, because the gap between phases is exactly the soft window this paper is about.
The Act entered into force on 1 August 2024. From that date the clock started, but almost nothing was yet enforceable. The phasing then proceeds in steps, each step turning a different part of the structure from dormant to live.
The phasing itself is a design decision worth pausing on, because it is not how laws usually work and the difference matters. A typical statute has a commencement date: before it, nothing; after it, everything. The AI Act instead has a sequence of commencement dates, ordered by how ready the corresponding part of the structure is. The prohibitions came first because a prohibition needs no standard to be enforceable; it is a line, and you are either across it or not. The general-purpose obligations came next because the parties they bind are few, identifiable, and capable of being brought to a drafting table quickly. The high-risk regime comes last because it is the part that most depends on the load-bearing layer being built, and that layer is the slowest thing to build. The order of the phases is, in effect, a public ranking of how soft each part of the structure still is. Read that way, the timeline is not a schedule of when things become illegal. It is a schedule of when each part of the structure stops being shapeable. The later the phase, the longer the window, and the high-risk window is the one that matters most and is open longest, which is precisely why it is the one being misread as a pause.
2.2 The prohibitions are already in force
On 2 February 2025 the first substantive phase took effect. Article 5, the list of prohibited practices, became applicable. These are the uses the Union has decided are incompatible with its order at any level of safeguard: certain manipulative and exploitative systems, social scoring of natural persons drawn from unrelated contexts and producing disproportionate detriment, untargeted scraping to build facial recognition databases, emotion inference in workplaces and education institutions outside narrow medical and safety exceptions, and biometric categorisation that infers sensitive characteristics such as political opinion, religious belief, or sexual orientation.
The prohibitions carry the heaviest penalty in the Act. Under Article 99, a breach of the prohibited practices can attract administrative fines of up to thirty five million euro or, for an undertaking, up to seven per cent of total worldwide annual turnover, whichever is higher. Other breaches sit at a lower tier, up to fifteen million euro or three per cent of worldwide turnover. For smaller enterprises the lower of the two figures applies.
The same February 2025 phase introduced an obligation around AI literacy: that providers and deployers take measures to ensure a sufficient level of understanding among the people operating these systems on their behalf. Note this obligation. It becomes relevant later, because it is one of the things being quietly softened in 2026, and the softening tells us something about how the structure moves.
2.3 The general-purpose layer went live in 2025
On 2 August 2025 the second substantive phase took effect: the Act's governance provisions and the obligations on providers of general-purpose AI models.
General-purpose models, the large foundation models that sit beneath much of the application layer, carry their own set of duties around documentation, transparency to downstream developers, copyright policy, and, for the small set of models judged to pose systemic risk, additional obligations around evaluation, risk mitigation, and incident reporting.
The instrument that operationalised this is itself the clearest single illustration of the paper's thesis. Rather than wait for the statute's principles to be litigated into meaning, the Commission convened a General-Purpose AI Code of Practice. It was published on 10 July 2025 and endorsed by the Commission and the AI Board, through adequacy decisions, around 1 August 2025. It has three chapters: Transparency, Copyright, and Safety and Security. The first two apply to all providers of general-purpose models. The third applies only to providers of models above the systemic-risk threshold, a small group.
The Code is voluntary. That word is doing an enormous amount of work and it is worth slowing down on it. The Code is voluntary in the sense that no one is legally compelled to sign it. It is not voluntary in the sense that matters. A provider that adheres to the Code is treated as demonstrating conformity with the corresponding statutory obligations. A provider that does not adhere to it has to demonstrate conformity some other way, alone, against a regulator, with no presumption in its favour. Within weeks of publication a long list of the most significant model providers had signed. At least one signed only the Safety and Security chapter and pointedly not the others, which is itself informative: even a refusal is a positioning move inside the soft layer, made while the layer is still soft enough for the move to register.
The lesson of the Code is the lesson of the whole paper in miniature. The binding text said "providers of general-purpose models shall." What that sentence means in operation was decided not by the sentence but by a document drafted in 2025 by the parties who showed up to draft it, and then blessed. Everyone who arrives later inherits that meaning. They did not get a vote on it. They get to comply with it.
It is worth dwelling on the mechanism by which a voluntary instrument acquires this force, because the mechanism repeats throughout the structure and recognising it is most of the analytical work this paper is asking the reader to do. A voluntary code becomes binding in effect through three steps, none of which is a legal compulsion. First, an authority declares the code an adequate way to demonstrate compliance with a statutory obligation. Second, the parties who can most cheaply comply, the large, well-resourced, already-present ones, sign, because for them the marginal cost of signing is low and the benefit of a presumption is high. Third, their signing establishes the code as the market expectation, so that the cost of not adhering shifts onto everyone who did not sign, in the form of having to prove compliance the hard way against a regulator with no presumption in their favour. After the third step the code is voluntary only in the narrow legal sense and mandatory in every operational sense. The decisive move in that sequence is the second one, and it is available only to the parties already operating at the relevant level when the code is being drafted. This is the general shape of how soft layers harden, and the general-purpose code is simply the first place the AI structure shows it cleanly. The same shape will repeat in the standards and, as we will see, in the insurance references. The reader who internalises the shape now will recognise it three more times before the paper is finished.
2.4 The high-risk regime, and the deferral that reveals everything
The third phase, the one most operators have in mind when they picture "the AI Act," concerns high-risk systems. These are the systems listed in Annex III and those embedded in regulated products: AI used in employment and worker management, in education and access to it, in essential public and private services, in critical infrastructure, in law enforcement, migration, and the administration of justice. For these, the Act imposes its full architecture: a risk management system, data governance, technical documentation, logging, transparency, human oversight, accuracy, robustness, cybersecurity, a conformity assessment before market entry, and a CE marking on the way out.
Under the original timeline, the bulk of these obligations, including the high-risk regime, would have become applicable on 2 August 2026.
They will not. And the reason they will not is the most important single fact in this paper.
On 19 November 2025 the European Commission published a package known as the Digital Omnibus on AI. Among other simplifications it proposed to defer the application of the high-risk obligations. After one failed attempt, on 7 May 2026 the Council and the Parliament reached a provisional political agreement on the package. Under that agreement the application of the high-risk regime is pushed back substantially: to 2 December 2027 for standalone high-risk systems under Article 6(2) with Annex III, and to 2 August 2028 for high-risk systems embedded in regulated products under Article 6(1). The transparency and watermarking obligation under Article 50(2) moved from 2 August 2026 to 2 December 2026. A new prohibition on the generation of non-consensual intimate imagery and child sexual abuse material was added with effect from 2 December 2026. The AI literacy duty on organisations was softened into an encouragement on the Commission and Member States. Relief for smaller and mid-cap enterprises was widened.
As of mid-2026 this is a political agreement, not yet law. The Parliament is expected to vote on the final text by early July 2026, with formal adoption expected before the original 2 August 2026 date, followed by publication in the Official Journal and entry into force shortly after.
It would be easy to read the deferral as a relaxation, a sign that the structure is loosening and that the waiting posture was correct after all. That reading is precisely wrong, and seeing why it is wrong is the hinge of this paper.
2.5 What the deferral actually tells you
A government does not defer the most important part of a law it spent years building because it has changed its mind about the law. It defers because the layer underneath the law is not ready, and a requirement cannot be enforced against a standard that does not yet exist.
The Commission's original framing of the deferral made this explicit. The proposal tied the postponement to the readiness of the supporting layer: the harmonised standards, the common specifications, the guidance and support tools that turn the statutory principles into something a provider can actually conform to and a regulator can actually test. The final political text fixes dates rather than leaving everything to a readiness trigger, and sources differ on exactly how much conditionality survives into the adopted text. The contested mechanism detail is not the point and we will not cement it. The structural truth is not contested and it is this: the high-risk regime was deferred because the load-bearing layer beneath it is not finished. The law has been waiting for its own foundations.
That single fact reorganises the entire picture. It means the binding text is real and settled, and the part that is unsettled, soft, still being decided, is exactly the part this paper has been pointing at: the standards, the conformity infrastructure, the supporting apparatus. The deferral is not the structure relaxing. It is the structure admitting, in public, that the load-bearing layer is still being poured and has not set. The extra time is not a reprieve for those who waited. It is the precise interval during which the shape is decided. It is the open window, and the Omnibus is the official confirmation that the window is open, with a date on which it closes.
3. The standards layer: where the law is actually written
3.1 The mechanism nobody campaigns about
If you want to know what a high-risk obligation in the AI Act actually requires, you do not read the Act. You read a harmonised standard. The Act tells you that a system must have, for example, an appropriate level of accuracy and robustness. It does not tell you what appropriate means, how it is measured, against what benchmark, with what tolerance, documented how. A harmonised technical standard does. And the law gives that standard a power that is easy to underrate.
Under Article 40 of the Act, a high-risk system that conforms to a harmonised standard whose reference has been published in the Official Journal benefits from a presumption of conformity with the corresponding requirement. In plain terms: meet the standard and you are presumed to have met the law. Do not meet the standard and you carry the burden of proving, alone, against a regulator, that whatever you did instead was equivalent.
Formally the standard is voluntary. Functionally it is the path of least resistance and the only one with a presumption attached, which means that in practice it is the route nearly everyone takes and therefore the place where the operative content of the law actually gets written. The principle is in the statute. The meaning is in the standard. The standard is drafted somewhere else, by other people, under different rules of access, and the law then points at it and says: that.
3.2 Who holds the pen
The standards are not drafted by the legislature. The Commission issues a standardisation request to the European standardisation organisations. For the AI Act the relevant request is M/593, adopted in 2023, with an original delivery date of 30 April 2025, subsequently amended by M/613 in 2025 with a revised delivery date of 31 August 2025. The technical work is carried out principally by the joint technical committee of the two European standardisation bodies, CEN and CENELEC, the committee designated CEN-CLC/JTC 21, Artificial Intelligence. That committee leverages, rather than overrules, the existing international work done at ISO and IEC, principally in their joint subcommittee on artificial intelligence.
This is not a criticism of those bodies. The point is structural and it is older than artificial intelligence. The European model for regulating products, the framework the AI Act deliberately adopts, has always worked this way: the legislator sets essential requirements at the level of principle, and the technical content is delegated to standardisation. It is an efficient division of labour for bolts and pressure vessels. It becomes something else when the essential requirements being operationalised are about fundamental rights, discrimination, contestability, and human oversight, and when the question of what counts as adequate fairness in an automated decision is settled in a technical committee rather than a parliament. The literature on the AI Act has been direct about this tension: the observation that drafting happens with limited transparency, that participation favours the well resourced, and that the clarification of rights-bearing requirements is in effect delegated to private standardisation, is not fringe commentary, it is a documented and live debate.
We are not resolving that debate here. We are noting what it implies for the operator. If the operative meaning of the law is set in standardisation, then the relevant question is not "what does the law say" but "who is in the room where the law is given its meaning, and when does that room close." The answer to the second half is now in the calendar.
There is a deeper point underneath the access question, and it is the point that makes standardisation the true centre of gravity rather than merely an administrative detail. When a parliament writes a law, it writes at the level of principle precisely because principle is what a parliament is competent to decide and what a democratic process can legitimately produce. The principle "a high-risk system shall be subject to appropriate human oversight" is the kind of sentence a legislature can debate and own. But that sentence does not constrain any actual system until someone decides what oversight means concretely: at which decision points, with what authority to override, with what information presented to the overseer, within what time, with what record. Every one of those concretisations is a value-laden choice that materially determines whether the oversight is real or decorative, and none of them is in the statute. They are in the standard. Which means the standard is not implementing a decision the legislature already made. The standard is making the decision, under cover of implementing one. This is the structural reason the standards layer is load-bearing and the statute is not: the statute carries the legitimacy, but the standard carries the decision. A reader who grasps that will never again treat "voluntary technical standard" as a phrase that can be safely skimmed past. It is the phrase under which the real law is written, and it is being written now.
3.3 The standards are late, and lateness is the whole story
By late 2024 it was already clear that the harmonised standards would not be ready for the original timeline. The chair of the relevant committee indicated that completion was likely to slip by roughly eight months. The Commission revised the delivery date. In October 2025 the technical boards of CEN and CENELEC took the unusual step of adopting an exceptional acceleration package, allowing, on a positive enquiry vote, direct publication of drafts without a separate formal vote, in order to get the key deliverables available by late 2026.
Read that sequence again with the thesis in mind. The standards are late. The high-risk regime was deferred. The deferral and the lateness are the same fact seen from two sides. The law was waiting for the standards, the standards slipped, so the law's most consequential phase moved with them. This is not a failure of the system. It is the system showing you, in public and on the record, exactly where the soft layer is and exactly how long it stays soft. The acceleration package is the sound of the concrete being poured faster. The deferral dates are the inscription on the form telling you when it sets.
There is a precise consequence here that is worth stating without ornament. The interval between now and the close of the deferral is the interval during which the operative content of European AI law is being finalised in documents that are still drafts. Everyone who treats this interval as dead time, time to wait out until the rules are clear, is misreading a drafting window as a grace period. The rules will be clear because they will have been written, in this window, by whoever was contributing to them in this window.
4. Conformity, certification, and the architecture of proof
4.1 Compliance is not a state. It is a demonstration
There is a quiet but decisive shift inside the AI Act that operators consistently underestimate. The Act does not ask whether a high-risk system is, in some abstract sense, safe. It asks whether the provider can demonstrate conformity through a defined procedure before the system reaches the market, and can keep demonstrating it afterwards. Compliance is not a property of the system. It is an evidentiary performance the provider must be able to give on demand.
This is the architecture of the European New Legislative Framework, the same machinery that governs the safety of physical products and that the AI Act consciously adopts. A product does not become lawful because it is good. It becomes lawful because it has passed through a conformity assessment, carries the conformity marking, and is backed by a technical file that can be produced for an authority. The AI Act ports this directly onto software and models. The same CE marking that appears on a kettle is the marking the Act places on a high-risk AI system, with, where relevant, the identification number of the body that assessed it.
4.2 Two routes, and the gap between them
Under Article 43 there are two principal conformity assessment routes for high-risk systems. The first is internal control under Annex VI: the provider assesses its own system against the requirements, compiles the technical documentation, and declares conformity, without a third party in the loop. For most of the Annex III categories this self-assessment route is the route. The second is third-party assessment under Annex VII, involving a notified body, an accredited external assessor, for certain categories where the legislator did not trust self-declaration alone.
The existence of the self-assessment route is frequently read as a weakening of the regime. It is the opposite, and the reason is the part of the picture this paper most wants the reader to hold. When the law lets you assess yourself, it does not reduce the burden of proof. It moves the burden of proof onto you, privately, in advance, with the regulator's scrutiny waiting on the other side and a heavy penalty tier behind that. Self-assessment against a vague principle is not relief. It is exposure. The only thing that converts that exposure back into safety is the existence of a credible, external, recognised reference that the self-assessment can be conducted against and, crucially, can be shown to have been conducted against. That reference is the standard. And the certification that the assessment was done, and done against the right thing, is what travels.
So the conformity architecture creates a demand it does not itself satisfy. It demands proof. It does not, by itself, manufacture the trusted reference against which proof is measured, nor the attestation that proof was produced. It points, again, downward and outward, to the standards layer and to whatever certification and assurance practice grows up around it. The architecture of the law generates a need for a trust layer that the law assumes but does not build.
4.3 Certification as the thing that actually moves between parties
Step back from the statute and watch how trust will actually flow once this regime is operative. A deployer adopting a high-risk system does not want to re-derive the provider's entire conformity case. A procuring institution does not want to. An insurer underwriting the deployment does not want to. An investor doing diligence on a company whose product is a high-risk system does not want to. What each of them wants is a compact, credible, portable attestation that the work was done properly against a recognised reference. That attestation, that certification, is the object that moves between parties. The technical file stays with the provider. The certification is what crosses the table.
This is why a trust standard is not a nice-to-have layered on top of the law. It is the missing connective tissue the law structurally requires and does not supply. The law creates the obligation to prove. The market creates the demand for portable proof. Between those two there is a load-bearing gap, and whatever fills it becomes infrastructure: not because anyone announced it as infrastructure, but because everyone starts depending on it and then stops being able to operate without it.
The shape of that connective tissue, what a credible AI trust attestation has to cover, how many dimensions of a system it has to speak to, how it maps onto the statutory requirements and onto what an insurer needs to see, is being decided now, in the same soft window as the standards, by the same logic. It is not yet hardened. It will be.
4.4 The capacity problem nobody priced in
There is a further, more practical reason the conformity layer is soft, and it is one of the clearest illustrations in this paper that the load-bearing layer is not merely undefined but materially under-built. For the categories of high-risk system that require third-party assessment, the assessor must be a notified body: an organisation accredited and designated to carry out conformity assessment against the AI Act. A notified body for AI does not exist by writing it into a statute. It exists only after it has been built, staffed with people who can competently assess machine learning systems against requirements that are themselves not yet finalised, accredited, and designated. That is a slow process, and it is dependent on the very standards that are late, because an assessor cannot be accredited to assess against a reference that has not been published.
Stack the dependencies and the picture is unambiguous. The high-risk regime depends on conformity assessment. Third-party conformity assessment depends on notified bodies. Notified bodies depend on accreditation against standards. The standards are late. Therefore the assessment capacity that the regime assumes will exist on the day it applies is, as of now, not built at the scale the regime implies, and cannot be until the layer beneath it sets. This is not a marginal logistical footnote. It is a second, independent confirmation of the paper's central claim, arriving from the infrastructure side rather than the legal side: the structure has been deferred because it is not merely undefined but physically unbuilt, and the interval before it is built is precisely the soft window. An operator who reads the deferral as the law relaxing has not noticed that the law could not have been enforced on the original date even if every operator had been ready, because the machinery to enforce it against did not yet exist. The window is not a gift. It is the time the structure needs to build itself, and whatever is built into it during that time is what everyone else later has to pass through.
5. Liability did not soften. It relocated and hardened
5.1 The directive that was withdrawn
For several years the European approach to AI harm was expected to rest on two legs. One was the AI Act, which is preventive: it regulates how systems are built and placed on the market. The other was to be the AI Liability Directive, proposed in 2022, which was corrective: it would have harmonised, across Member States, the fault-based rules under which a person harmed by an AI system could bring a claim, easing the claimant's evidential burden in a domain where the defendant holds all the technical knowledge.
That second leg is gone. The Commission signalled the withdrawal of the AI Liability Directive in its 2025 work programme in February 2025, confirmed it after a meeting in July 2025, and the formal withdrawal notice appeared in the Official Journal in October 2025. The bespoke, AI-specific, fault-based liability instrument was abandoned for want of agreement.
An operator scanning headlines could be forgiven for filing this under "the rules are loosening." It is the third time in this paper we have met that misreading, and it is the same error each time. Something visible was withdrawn, so the structure looks lighter. The structure is not lighter. The load moved.
5.2 Where the load moved to
In parallel with the abandoned directive, the European Union revised the instrument that had governed liability for defective products since the 1980s. The revised Product Liability Directive, Directive (EU) 2024/2853, was published in the Official Journal on 18 November 2024. Member States must transpose it into national law by 9 December 2026, and it applies to products placed on the market or put into service after that date.
The revision does something quietly decisive. It brings software, and expressly AI systems, inside the definition of a product subject to strict, no-fault liability. It is no longer necessary, under this regime, to prove that anyone was at fault. It is necessary to show that a product was defective and caused damage, and the revision introduces disclosure duties and presumptions that ease even that, in cases of technical complexity, in the claimant's favour.
Put the two moves together. The Union dropped the fault-based AI liability instrument and simultaneously pulled software and AI into the strict, no-fault product liability regime, with the claimant's path made easier. That is not a softening of liability. It is a hardening of it, achieved by relocation. The fault question, the hardest thing for a person harmed by an opaque system to prove, was not made easier within a special AI regime. It was removed from the equation by routing AI through strict product liability instead. Liability did not get smaller. It got simpler to impose and harder to escape, and it now attaches by default.
5.3 The pattern is now unmistakable
Three times in this paper the same shape has appeared. The high-risk regime was deferred, which looks like relaxation and is actually the structure waiting for its load-bearing layer to set. The AI literacy duty was softened, which looks like retreat and is actually the structure shedding a clause it could not yet operationalise while keeping everything that bears weight. The AI Liability Directive was withdrawn, which looks like the liability problem going away and is actually liability relocating into a stricter regime that attaches automatically.
The pattern is not coincidence and it is not contradiction. It is what it looks like when a governance structure sheds the parts that do not bear weight and reinforces the parts that do, while the whole thing is still soft enough to be reshaped. Reading any one of these moves as loosening is reading a single beam being removed and concluding the building is being demolished, when in fact the building is being engineered, in real time, around the beams that carry the load. The operator who waits because the structure looks like it is loosening has misread engineering as abandonment, and will arrive to find the load-bearing members exactly where the engineers always intended them, set hard.
6. The other root: insurance as a private gate
6.1 The regime the statute does not contain
There is a second load-bearing root growing beneath AI deployment, and it is not in the statute at all. It is the insurance market.
The reason it matters is mechanical. An institution does not deploy a consequential system it cannot insure. A board does not sign off on uninsurable exposure. A lender does not finance it. Long before a regulator inspects a system, an underwriter has already decided whether the risk it carries is one the market will accept and on what terms. Insurance is therefore not a downstream consequence of AI governance. It is a parallel gate, and in practice it is often the gate that opens or closes first, because it operates on commercial time, not legislative time.
6.2 What the market is actually doing in 2026
The shape of this gate became visible during 2025 and 2026 and it is worth stating concretely because it is the clearest evidence in this paper that the load-bearing layer forms ahead of the statute, not behind it.
On one side, dedicated AI liability cover emerged. In April 2025 a specialist managing agent launched an AI liability product backed by Lloyd's syndicates. A major reinsurer brought a product addressing model performance failure and hallucination. A large cloud provider's risk protection programme was extended with affirmative AI wording from established carriers. On the other side, and at the same time, the general market began to wall the risk off: in January 2026 standard generative-AI exclusions for commercial general liability were filed and adopted by multiple carriers, and larger insurers began retreating from silent, unpriced AI exposure while specialist entrants moved in. Capital followed the convergence of AI liability and cyber cover at scale in early 2026.
Notice what is being described. The market did not wait for the high-risk regime to become applicable. It did not wait for the harmonised standards. It is pricing, excluding, and affirmatively covering AI risk now, while the public layer is still soft. It has to, because exposure does not pause for legislation. And it is doing so in a specific way that matters for this paper's argument: underwriters increasingly require evidence before binding, telemetry, continuous performance monitoring, demonstrable governance. They are asking the insured to prove the system is what it claims to be. They are, in other words, demanding exactly the portable attestation that the conformity architecture also demands and does not supply.
6.3 Two demands, one missing object
This is the convergence the paper has been building toward. The public regime, through self-assessment against standards and conformity routes, generates a structural demand for portable proof of trustworthiness. The private regime, through underwriting, independently generates the same demand from the other side. A high-risk system that wants to reach the market needs to demonstrate conformity. The same system, to be deployed by any serious institution, needs to be insurable. Both requirements resolve to the same missing object: a credible, recognised, portable attestation, mapped to the obligations on one side and to the risk model on the other, that lets a third party trust the system without re-deriving it.
6.4 The cyber precedent, read correctly
The most useful precedent for what is happening is the development of cyber insurance, and it is worth reading correctly because the obvious reading misses the load-bearing part. The obvious reading is that cyber insurance grew from a niche product into standard infrastructure, and that AI insurance will do the same. That is true and it is not the point. The point is what cyber insurance did on its way to becoming infrastructure. To price cyber risk, insurers had to decide what good security practice was, because they would not underwrite an organisation that could not demonstrate it. In deciding what they would accept as evidence of adequate practice, insurers became, in effect, a private standard-setter for security, often ahead of and more operationally consequential than the public one. An organisation's security posture came to be shaped substantially by what its insurer required to bind cover. The insurer's checklist became the de facto standard, not because anyone legislated it, but because the gate would not open without it.
AI insurance is now at the same juncture, and the window is open in exactly the same way it once was for cyber. Underwriters are deciding, right now, what they will accept as evidence that an AI system is governed well enough to be insurable: what telemetry, what monitoring, what attestation, what continuity between claim and reality. Whatever they settle on becomes the de facto trust reference for the deployment side of the entire market, and it settles during the soft phase, before any public standard is cited, by the parties already credible enough to be at the table when underwriters decide what counts. This is the third time the paper has shown the same hardening mechanism: an authority or a market accepts something as adequate, the already-present parties supply the form it takes, and everyone who arrives later inherits it. Standards, codes of practice, and now insurance references all harden by that identical sequence, which is why the question is never which document wins but who was operating at the relevant level while the document was still being written.
6.5 Two roots, one trust layer
Insurance follows the historical path of cyber cover, from a niche product to standard infrastructure that adoption depends on. As it hardens, the reference it underwrites against hardens with it. The standard an insurer treats as sufficient evidence of governance becomes, in practice, the standard the market treats as the definition of governance. That is a second route by which the operative meaning of AI governance is being set now, in a soft state, off to the side of the statute entirely, and is about to set hard. Whoever is shaping the trust reference while it is still soft is shaping what both roots, the regulatory and the actuarial, will later treat as given.
7. How a regional rulebook becomes the global default
7.1 The mechanism, briefly
It is reasonable to ask why an operator outside the European Union should treat any of this as load-bearing. The answer is a well-documented mechanism and we will state it without overclaiming it.
A large, wealthy, regulatorily credible market that sets demanding product rules tends to export those rules in two ways. One is direct: other jurisdictions, lacking the capacity or appetite to design their own framework from scratch, adopt the template, sometimes nearly verbatim. The other is indirect: firms operating across many markets find it cheaper to build to the strictest applicable standard once and ship that everywhere than to maintain divergent versions, so the strict standard becomes the de facto global one even where it is not the local law. This is the mechanism Anu Bradford named the Brussels effect, and the AI Act is its current test case. The literature is not unanimous. There is a serious counter-reading that the AI Act's complexity and its experimentalist, standards-dependent design may blunt the effect rather than amplify it, and we record that honestly rather than pretend the question is closed.
7.2 Why the debate does not change the conclusion
For this paper the academic dispute is interesting but not decisive, and it is worth being clear why. Both readings agree on the part that matters here. Whether the European framework propagates strongly or weakly, the operative content of it is being set in the standards and conformity and insurance layer, not in the statute, and that layer is forming now. If the Brussels effect is strong, then what is decided in that European soft layer becomes the global default and the window is global. If the effect is weaker than claimed, then multiple regional soft layers are forming in parallel, each one shapeable now and hardening soon, and the window is plural rather than singular. In neither case is there a reading under which the soft layer does not exist, or under which it stays soft. The closing window is not contingent on the Brussels effect being total. It is contingent only on governance of a general technology having a load-bearing layer that forms before it sets, and that is not in dispute in any serious account.
8. The orchestration layer and the identity layer
8.1 Why the soft layer settles around identity, not capability
There is a question the preceding sections have circled without answering directly. The standards, the conformity routes, the insurance references all converge on a demand for portable proof. Proof of what, exactly. It is worth answering precisely, because the answer determines what the hardening structure actually hardens around, and that determines what it means to be operating at the root of it.
Begin with a distinction. There is a layer of the AI stack concerned with capability: models, weights, inference, the orchestration of tools and agents into systems that do things. This layer is improving very quickly and, just as importantly, commoditising very quickly. Capability that was scarce and defensible in one year is a baseline expectation the next. Anything improving and commoditising at that rate is, by definition, not where durable position accrues, because position requires something that does not reset every cycle.
There is a second layer, and it is the one the entire load-bearing apparatus described in this paper is actually reaching for. It is not concerned with what a system can do. It is concerned with whether a system is what it claims to be, whether its behaviour is accountable, whether there is continuity between what was attested and what is running, whether the entity standing behind it can be identified and held. Call this the identity layer: the layer at which a system, and the practice around it, has a stable, attestable, accountable identity over time. The conformity regime is reaching for it when it demands a technical file and a marking that says this system is the assessed system. The insurance market is reaching for it when it demands telemetry and continuous evidence that the bound risk is the actual risk. The liability regime is reaching for it when it attaches strict liability to a product and asks who stands behind it. None of these are asking what the system can do. All of them are asking who and what it is, and whether that holds.
Figure 2. The orchestration layer and the identity layer. Picture the AI stack as two layers. The lower, larger, louder layer is orchestration: capability, models, agents, the machinery of doing. It moves fast, commoditises fast, and is where most attention and most capital currently sit. The upper, quieter, slower layer is identity: the attestable, accountable, continuous answer to the question "is this system what it claims to be, and who stands behind it." The governance structure described in this paper, standards, conformity, liability, insurance, is not regulating the orchestration layer for its own sake. It is using the orchestration layer's behaviour as the thing to be accounted for, and it is hardening around the identity layer, because identity is what accountability actually requires. The orchestration layer is where the technology is. The identity layer is where the durable position is, because it is the layer the hardening structure settles onto.
8.2 Identity is the only layer slow enough to set hard around
The reason the structure hardens around identity rather than capability is not a preference. It is a property of hardening itself. A structure can only set around something stable enough to take and hold an impression. Capability is not stable enough; it changes faster than any standard, conformity route, or insurance reference can be written, which is exactly why those instruments do not specify capabilities and instead specify processes, attestations, documentation, and accountability, all of which are properties of identity, not of capability. The governance layer cannot grip a moving thing. It grips the part that holds still long enough to be gripped, and the part that holds still is identity: who built this, what was attested, is the running system the attested system, who is accountable when it is not.
This is why the durable position in the AI era is not at the orchestration layer at all, even though that is where almost all the attention is. The orchestration layer is where the technology lives and it is precisely therefore where nothing sets, because nothing there holds still. The identity layer is where the hardening structure comes to rest. An entity operating at the identity layer while it is still soft is operating at the exact place the structure will set, which is the definition of being inside it when it hardens rather than outside it reading the date.
8.3 What it means to operate there before it sets
To operate at the identity layer before the structure sets is not to predict which standard will be cited or which insurance reference will dominate. It is to be, already, in the present tense, the kind of thing that the conformity demand and the actuarial demand both resolve to: a recognised account of whether an AI-era system is what it claims to be, continuous over time, mapped to obligations on one side and to risk on the other, treated as a reference rather than sold as a product. This is the problem Future Proof was built underneath. Not as a commentary on the closing window but as one of the things already operating at the identity layer while that layer is still soft: an AI-era trust standard held as a foundational reference, an identity layer over the orchestration layer rather than a competitor within it, the connective tissue between what the law will require and what the market will underwrite. The argument has been describing the shape of that root since its first page. A reader who has followed it will recognise the shape: a layer the statute assumes and does not build, the place the whole structure is reaching toward, forming now, about to set. Being there before it sets is not a claim one makes. It is a position one already holds or does not, on the day the window closes.
9. The closing window, stated precisely
We can now state the central claim without metaphor and without slack.
The binding law is settled. The operative meaning of the binding law is not, and it is being decided in 2026 in the standards, the conformity infrastructure, the codes of practice, the certification practice, and the insurance market that sit beneath the statute. That layer is currently soft: still drafted, still negotiated, still priced provisionally, still open to being shaped by the parties present in it. The Digital Omnibus deferral did not relax the structure. It documented, officially and with dates, that the load-bearing layer is not yet set and named the interval before it sets. That interval is the window. When the standards are cited, the conformity routes are exercised at scale, the certification practice is established, and the insurance references are settled, the window closes. After it closes the meaning of AI governance is fixed, not by anyone reading the law, but by the settled state of the layer beneath it, and everyone who arrives after that point inherits a shape they had no part in setting.
There is one further point and it is the sharpest one. A soft layer is not shaped by spectators. It is shaped by participants. The standards are written by who is in the committee. The codes of practice are shaped by who shows up to draft them, as the general-purpose code already demonstrated. The certification practice is established by whoever is already attesting at the level the market comes to expect. The insurance references are set by what underwriters are already treating as sufficient evidence. None of these are shaped by reading. All of them are shaped by operating. The question the window poses is therefore not "have you read the regulation." It is "were you already operating at the root while it was still soft, or did you arrive to comply with it after it set."
The preceding section named where that root is: the identity layer, the place the hardening structure settles because it is the only layer slow enough to set hard around. The position this paper describes is therefore a precise one, not a slogan. It is to be already operating at the identity layer while it is still soft, as a recognised account of whether an AI-era system is what it claims to be, held as a reference rather than sold as a product, the connective tissue between what the law will require and what the market will underwrite. This is the problem Future Proof was built underneath. Not built to observe the closing window from outside it, but to be one of the things already at the root while the root is still soft. The argument of this paper arrives, deliberately, at that point, because the argument has been describing the shape of that root since its first page. A reader who has followed the structure will recognise it: a layer the statute assumes and does not build, the place the whole apparatus is reaching toward, forming now, about to set. Being there before it hardens is not a claim one makes. It is a position one already holds or does not, on the day the window closes.
10. Implications
The reader of a paper like this is usually doing quiet research before a decision. The implications below are written for that reader, by the kind of decision they are facing. They are deliberately concrete and they remain in the register of the argument: this is what the structure does to you, not an offer.
For institutions
You are not waiting for AI regulation. You are inside its formation period and you are spending it as though it were a pause. The operative content of what you will have to comply with is being written, this year, in standardisation committees, conformity practice, and an insurance market, in a soft state you can still influence and will soon only be able to obey. The institutions that will look prescient in 2028 are not the ones that read the Act most carefully. They are the ones that are already operating to a recognised trust reference now, while the reference is still being defined, so that when it hardens it hardens around a practice they already embody rather than one they have to retrofit under deadline. The concrete move is not a compliance project scheduled for the year the high-risk regime applies. It is presence, now, in the layer where the meaning is being set, and adoption, now, of an attestation practice that both the conformity regime and your insurers will recognise, because the alternative is to inherit both from parties who did not have your interests in the room.
For investors
The diligence question that ages well is not "is this company compliant with the AI Act." On the current timeline that question is partly unanswerable, because the standards a high-risk system would be assessed against are not yet cited. The question that ages well is structural: is this company operating at the root of the trust layer, or is it exposed to it. A company whose product is a high-risk system, that is treating compliance as a future event, is carrying an unpriced liability that hardens on a known schedule, into a strict product liability regime, against an insurance market that is already excluding and repricing the risk. A company that is already producing portable, recognised proof of how its systems behave is holding an asset that becomes more valuable precisely as the layer hardens, because scarcity of credible proof rises exactly when proof becomes mandatory. The thing to underwrite in a portfolio is not stated compliance. It is position relative to the closing window.
For operators
The most expensive misreading available to you is the one this paper has named three times: that the structure is loosening. The deferral, the softened literacy duty, the withdrawn liability directive all look like the pressure coming off. It is not coming off. It is being engineered around the parts that bear weight, while the structure is still soft enough to engineer. If you spend the deferral as breathing room you will arrive at the close of it to find the load-bearing members exactly where they were always going to be, set hard, and yourself outside them. The operator's move is to treat the window for what it is, the only period in which the shape can still be influenced rather than only obeyed, and to be operating to the trust reference now, so that hardening confirms your position instead of indicting it.
For the people inside these systems
There is a reader this paper has not yet addressed directly: the person who is not regulating, investing, or operating, but who is subject to a high-risk system, assessed by it for a job, a loan, a place, a service. The deferral that gives industry until 2027 and 2028 is, for that person, a postponement of protection. This is the part of the structure where the substrate register matters most and where it must be most honest. A trust layer is not, finally, an instrument of compliance. It is the thing that decides whether the postponement of the rules is also a postponement of dignity. The reason to operate at the root before it hardens is not only that the position is durable. It is that the shape of the root determines whether the systems that sort people are accountable to the people they sort, or only to the parties that built them. That is the load the layer actually bears. Everything else in this paper is the engineering around it.
11. Coda
The instinct, faced with a structure this large and this much in motion, is to wait for it to be finished and then read it. The argument of this paper is that the instinct is exactly inverted. A governance structure is not decided when it is finished and read. It is decided while it is unfinished and being written, in a layer beneath the part anyone reports on, by whoever is present in that layer while it is still soft enough to take an impression. By the time it is finished and readable, it has already taken the impression of whoever was there.
The European Union has, with unusual clarity, told the world when its layer sets. The deferral dates are not a reprieve. They are a published timestamp on the closing of a window, and the window is the interval in which the meaning of AI governance is still soft enough to shape. Everything visible, the statute, the headline, the fine, is the part that arrives last and matters least to the question of who shaped it. Everything that decides what those things mean, the standards, the conformity practice, the certification, the insurance, is forming now and will not be soft for long.
There is a version of being early that is just impatience. This is the other kind. To be early to a hardening structure is not to predict it. It is to already be one of the things it hardens around. When the layer sets, it does not record who understood it. It records who was inside it. The window does not close with an announcement. It closes the way concrete sets, quietly, on a schedule that was published in advance, around whatever was placed in it while it could still take the shape. The only question this paper finally asks is whether, when it sets, you are part of the structure or standing outside it reading the date.
References and Notes
The following are real, public, verifiable sources. Dates and obligations in this paper were grounded against current sources in 2026. Where a mechanism was contested between sources, the paper states the structural truth and does not cement the contested detail, as noted in the text.
- Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (the Artificial Intelligence Act). Published in the Official Journal of the European Union, 12 July 2024. Entered into force 1 August 2024. Articles referenced: 5 (prohibited practices), 40 (presumption of conformity via harmonised standards), 43 (conformity assessment), 48 (CE marking), 50 (transparency), 99 (penalties); Annexes III, VI, VII.
- Directive (EU) 2024/2853 of the European Parliament and of the Council on liability for defective products, repealing Directive 85/374/EEC. Published in the Official Journal, 18 November 2024. Transposition deadline 9 December 2026.
- European Commission, Digital Omnibus on AI, legislative simplification package. Proposal published 19 November 2025. Council and European Parliament provisional political agreement reached 7 May 2026. Formal adoption pending at the time of writing, expected before 2 August 2026.
- European Commission, Standardisation request M/593 (Commission Implementing Decision C(2023)3215) in support of the Artificial Intelligence Act, 2023, as amended by request M/613 (C(2025)3871), 2025.
- CEN-CENELEC, joint technical committee CEN-CLC/JTC 21, Artificial Intelligence. Public materials on the development of harmonised standards under the AI Act standardisation request and the October 2025 acceleration measures adopted by the CEN and CENELEC technical boards.
- ISO/IEC JTC 1/SC 42, Artificial Intelligence. The joint international subcommittee whose work the European standardisation bodies leverage in developing AI Act harmonised standards.
- General-Purpose AI Code of Practice. Published 10 July 2025; endorsed by the European Commission and the AI Board via adequacy decisions around 1 August 2025. Chapters on Transparency, Copyright, and Safety and Security.
- European Commission, withdrawal of the proposed Artificial Intelligence Liability Directive. Signalled in the Commission Work Programme 2025 (February 2025), confirmed July 2025, withdrawal notice published in the Official Journal October 2025.
- Anu Bradford, The Brussels Effect: How the European Union Rules the World (Oxford University Press, 2020), and subsequent scholarship applying and contesting the Brussels effect in the specific context of AI regulation, including the experimentalist-governance reading of the AI Act's external impact.
- Public reporting and primary materials on the AI insurance market 2025 to 2026: the emergence of dedicated AI liability cover backed by Lloyd's syndicates and major reinsurers, affirmative AI wording from established carriers, and the filing and adoption of generative-AI exclusions for commercial general liability in January 2026.
- The academic and policy literature on standards as governance and on the delegation of fundamental-rights-bearing requirements to private standardisation under the European New Legislative Framework, including the published debate on the legitimacy and transparency of the AI Act standardisation process.
A note on method. This is a reference paper, not a legal opinion. Where the adopted text of the Digital Omnibus diverges in mechanism from the provisional political agreement described here, the dates may move; the structural argument, that the operative layer beneath the statute is forming now and hardening soon, does not depend on any single date and is robust to that movement. Readers making compliance decisions should consult the adopted instruments directly.
Future Proof Intelligence . Research . No. I . MMXXVI