Executive summary
The debate surrounding the impact of European Union and United Kingdom regulatory frameworks on the development and deployment of frontier artificial intelligence has intensified as technological capabilities approach critical economic thresholds. Critics assert that stringent regulatory regimes are inducing regulatory drag, starving domestic ecosystems of cutting-edge models, and driving capital flight to more permissive jurisdictions. Conversely, proponents argue that a rights-based, precautionary approach is essential for mitigating catastrophic risks, safeguarding democratic values, and establishing a stable, high-trust market that ultimately fosters sustainable, long-term innovation.[4]Link to footnote
This investigative report evaluates these competing claims through a systematic analysis of empirical release data, regulatory architecture, and global policy frameworks. The investigation demonstrates that while 11% of major large language model releases have been delayed or withheld from the EU, and 7% from the UK, the primary driver of these delays is not the much-discussed EU AI Act, but rather the contested application of data protection law, specifically the General Data Protection Regulation and its UK equivalent.[1]Link to footnote
Furthermore, this report reveals that the regulatory landscape is characterized by a simplification paradox. While legislative initiatives like the EU's Digital Omnibus on AI seek to streamline compliance and postpone demanding deadlines, they frequently introduce short-term legal uncertainty.[2]Link to footnote This analysis explores the first-order, second-order, and third-order effects of this regulatory friction, contrasting the European model with the flexible regimes of Singapore and the United States, and examines the emerging shift where US national security export controls, rather than European regulations, represent the most formidable barrier to European technological access.[1]Link to footnote
European enterprises should treat GDPR compliance architecture, not just AI Act conformity, as the binding constraint on frontier model access, and plan for geopolitical export-control risk as a parallel gatekeeper.
Source analysis and verification
To evaluate the validity of claims regarding regulatory drag, it is necessary to conduct a rigorous analysis of the primary empirical sources underpinning the debate. The quantitative baseline of this discussion is anchored by two key sources: the Governance of AI (GovAI) technical report by Lidiard, Vereschak, Gibbs, and Anderljung published in June 2026, and the subsequent public communications of its senior author, Markus Anderljung, on the social media platform X.[1]Link to footnote[3]Link to footnote
Primary empirical sources
GovAI technical report and public communications (June 2026)
Thematic analysis of AI deployment friction
Empirical rate of delays and non-releases
The GovAI database tracking 375 large language model releases between June 2018 and May 2026 reveals a stark divergence between EU and UK deployment patterns. Relative to the US, 11% of releases were delayed or not released to the EU and 7% to the UK. While the majority proceed simultaneously across jurisdictions, a meaningful minority face delays or complete market exclusion, with data protection compliance reviews, not AI Act obligations, driving the bulk of documented friction.[1]Link to footnote
Based on the Epoch Capabilities Index, the UK saw no delay accessing the highest-ranked model at any point; the EU faced a 71-day delay for the Claude 3 Opus web-app release while that model ranked highest, though API access was simultaneous with the US.[1]Link to footnote[5]Link to footnote
Median frontier model deployment delay
- Median delay (days)UK 15dEU 53d
Documented delay length by company, United Kingdom
Documented delay length by company, European Union
Of the four labs, Meta shows the highest overall share of delayed or withheld releases (~26% in the EU; ~15% in the UK), followed by Google (~11% EU; ~9% UK). OpenAI has the lowest EU share (~4%) and no permanent non-releases in either jurisdiction. Anthropic recorded no UK delays or non-releases, though several Claude releases were delayed or withheld in the EU in 2023–2024.[1]Link to footnote
Share of releases delayed or withheld (EU)
Company delay/withhold rates where both jurisdictions are reported
- MetaUK 15%EU 26%
- GoogleUK 9%EU 11%
Between 2023 and 2025, the annual share of delayed or non-released models fell in both jurisdictions, from roughly 28% to 8% in the EU and 18% to 4% in the UK, while Meta’s share moved in the opposite direction (about 7% → 88% in the EU and 7% → 25% in the UK). In the first five months of 2026, no publicly released model in the dataset was delayed or withheld from the EU or UK for regulatory reasons.[1]Link to footnote
Share of releases delayed or withheld (2023–2026)
Table 1 excerpt, selected delays and non-releases
| Model / release | UK delay | EU delay | Primary factor | Confidence | ||
|---|---|---|---|---|---|---|
| Meta | Meta AI Glasses (text) | Meta AI Glasses (text, Apr 2024) | 202 days | 237–365 days | Regulatory (both) | Medium |
| Llama 3.2 Meta AI text | Llama 3.2 Meta AI (text, Sep 2024) | 14 days | 177 days | Regulatory (both) | High UK / Med. EU | |
| Llama 3.2 / 4 Vision open source | Llama 3.2 / 4 Vision (open source) | Same as US | Not released | Regulatory (EU) | Low | |
| Bard PaLM 2 | Bard / PaLM 2 (May 2023) | Same as US | 64 days | Regulatory (EU), Irish DPC | High | |
| Gemini 1.0 Pro | Gemini 1.0 Pro (Dec 2023) | 13 days | 57 days | Regulatory (both) | Low | |
| PaLM/Gemini free-tier APIs | PaLM 2 / Gemini free-tier APIs (2023–24) | Not released | Not released | Regulatory (both) | Medium | |
| OpenAI | GPT-4o realtime A/V | GPT-4o realtime audio/video (Dec 2024) | Same as US | 49 days | Regulatory (EU) | Low |
| Operator | Operator / GPT-4o Computer Use (Jan 2025) | 27 days | 47 days | Other (UK) / Reg. (EU) | High UK / Low EU | |
| Anthropic | Claude 2 / 2.1 | Claude 2 / 2.1 (2023) | Same as US | Not released | Regulatory (EU) | Low |
| Claude 3 Opus | Claude 3 Opus web app (Mar 2024) | Same as US | 71 days | Regulatory (EU) | Low |
Thematic claim 1: Data protection regulation is the true driver
A critical finding of this investigation is that the primary source of regulatory delay is not the much-debated EU AI Act, but rather the long-established GDPR and its post-Brexit British counterpart, the UK GDPR. Of the 68 documented cases of delays or non-releases in the dataset, 56 are tentatively attributed to regulatory factors, specifically data protection barriers, while 9 appear driven primarily by non-regulatory factors (compute, language support, product readiness) and 3 remain unclear. The authors find no strong evidence that the EU AI Act caused delays or non-releases in the covered period.[1]Link to footnote The structural tension between large language models and the GDPR manifests across three distinct legal dimensions:
Attribution of delay / non-release cases (n=68)
- Documented cases9 other + 3 unclear56 regulatory
The lawful basis conflict: legitimate interest vs. consent
Under Article 6 of the GDPR, processing personal data requires a valid lawful basis. For frontier developers scraping billions of data points from the open web, obtaining explicit consent from millions of data subjects is technically and operationally impossible.[14]Link to footnote Consequently, developers rely on the "legitimate interest" provision under Article 6(1)(f). However, the European Data Protection Board in its seminal Opinion 28/2024 clarified that legitimate interest cannot be treated as a default legal basis for AI training, it requires a rigorous three-step assessment.[16]Link to footnote
In June 2024, both the Irish Data Protection Commission and the UK Information Commissioner's Office requested that Meta pause its plans to train models on public Facebook and Instagram data, contributing to continued UK and EU exclusions from Meta AI assistant releases.[1]Link to footnote[6]Link to footnote
Special-category data and the CJEU inference doctrine
Article 9 of the GDPR imposes a strict prohibition on processing "special-category" sensitive data without explicit consent. Under the Court of Justice of the European Union's established jurisprudence, any processing that is "liable to indirectly reveal" protected characteristics falls under Article 9, regardless of the developer's intent.[1]Link to footnote[7]Link to footnote This legal risk helps explain why OpenAI delayed the EU rollout of advanced voice and real-time audio/video modalities, and why Meta withheld multimodal vision models from the EU market.[1]Link to footnote
The free-tier API commercial conflict
Google's extensive series of non-releases for its PaLM 2, Gemini 1.0, and Gemini 1.5 free-tier APIs in 2023 and 2024 is directly traceable to these data protection boundaries. Google only unlocked free-tier API access in August 2024 after updating its terms of service to extend paid-tier data protection defaults to European free-tier users.[1]Link to footnote
Primary cause of delay / non-release cases (n=68)
Thematic claim 2: Overlapping regulatory duplication induces regulatory drag
While data protection remains the current friction point, the broader European regulatory ecosystem is characterized by what technology governance scholars term the paradox of overregulation.[2]Link to footnote The EU AI Act, with its 1,000+ recitals, articles, and annexes, does not operate in isolation; it sits alongside the GDPR, the Data Act, the Digital Services Act, and the Cyber Resilience Act.
The compliance burden duplication
The AI Act introduces requirements for Fundamental Rights Impact Assessments for high-risk systems, which often overlap with the Data Protection Impact Assessments already mandated under Article 35 of the GDPR.[23]Link to footnote Furthermore, very large online platforms face simultaneous, overlapping risk-assessment obligations under the AI Act and the DSA when deploying general-purpose generative models.[23]Link to footnote
Quantifiable economic impact
Joint industry statements from DIGITALEUROPE and Eurochambres highlight the immense economic burden of these compliance overlaps.[10]Link to footnote The Commission's own initial analysis estimated that an SME developing a high-risk AI system would face up to €319,000 in initial compliance costs, plus up to €150,000 per year thereafter, but real-world industry studies show the actual initial cost is closer to €600,000.[10]Link to footnote
SME high-risk AI Act compliance cost estimates (€ thousands)
For small businesses, this compliance overhead translates into a 30% to 40% erosion of profit, actively discouraging zero-to-one innovation.[10]Link to footnote
Thematic claim 3: The simplification paradox of the June 2026 Digital Omnibus
To address growing warnings of "slow agony" from economic leaders like Mario Draghi, the European Commission proposed a Digital Omnibus package to streamline compliance and cut red tape.[27]Link to footnote On 7 May 2026, the European Parliament and the Council reached a provisional agreement, formally adopted in late June 2026.[30]Link to footnote
- Key provisions: Stand-alone high-risk AI obligations under Article 6(2) and Annex III are delayed until 2 December 2027. High-risk systems used as safety components of products are delayed until 2 August 2028. National regulatory sandbox deadlines are postponed to 2 August 2027, and watermarking obligations for existing providers are delayed until 2 December 2026.[30]Link to footnote[32]Link to footnote
- The simplification paradox: While designed to reduce regulatory drag, the Omnibus has paradoxically introduced severe short-term instability. By modifying 30 articles and adding major substantive changes just months before original deadlines, the fast-track procedure bypassed full public consultation.[2]Link to footnote The Parliament rejected proposals to remove registration obligations for low-risk systems under Article 6(3), and a new immediate ban on AI-generated non-consensual intimate content effective December 2026 has forced rapid re-engineering.[30]Link to footnote[33]Link to footnote
The same period in which Omnibus negotiations sought to ease compliance coincides with the GovAI finding that aggregate delay/withhold shares had already fallen sharply from 2023 peaks, and that H1 2026 recorded zero public regulatory delays, underscoring that GDPR clarification and lab compliance maturity, not AI Act GPAI enforcement (still pending August 2026), explain the recent easing.[1]Link to footnote
Thematic claim 4: Geopolitical drivers surpass domestic regulation
The empirical record suggests that in the current geopolitical environment, US national security export controls and restricted corporate deployment strategies represent a more formidable barrier to European technological access than domestic regulations.[1]Link to footnote
In the first five months of 2026, there were zero instances of a publicly released frontier model being delayed or withheld from the EU and UK due to regulatory intervention. Instead, access was constrained by invite-only "trusted-access" programs such as GPT 5.5 Cyber, Claude Mythos, and GPT Rosalind.[1]Link to footnote In early 2026, US export controls forced Anthropic to pull both Claude Fable and the trusted-access version of Claude Mythos from European markets, highlighting Europe's structural vulnerability as a dependent on the American AI technology stack.[1]Link to footnote[34]Link to footnote
Comparative regulatory frameworks
The global technology landscape is characterized by a stark divergence in regulatory design. Singapore has emerged as a leader in precision technology governance, while the UK attempts a middle path through sectoral sandboxes.
Global AI regulatory framework comparison (2026)
Philosophy, legislative tools, and testing infrastructure across five jurisdictions
Singapore's Personal Data Protection Act contains a dedicated Business Improvement Exception, legally authorizing developers to use personal data to enhance and train products without obtaining consent.[21]Link to footnote Crucially, Singapore built AI Verify, a standardized, open-source testing toolkit, two years before writing any regulatory guidelines, providing technical transparency without pass-fail administrative penalties.[21]Link to footnote[44]Link to footnote
The UK's strategic pivot: sandboxes and sectoral coordination
Following Brexit, the UK abandoned proposals for a comprehensive UK AI Act, delegating enforcement to existing regulators guided by five cross-cutting principles.[12]Link to footnote The UK Department for Science, Innovation and Technology launched the AI Growth Lab on 8 June 2026, operating as a cross-economy regulatory sandbox with power to make rapid, temporary amendments to existing regulations.[47]Link to footnote The legal sector was selected as the first focus area, addressing novel risks such as loss of legal professional privilege when uploading data to open-source LLMs, as established in the landmark ruling Munir v Secretary of State (2026).[42]Link to footnote
Stakeholder perspectives and counterarguments
Stakeholder perspectives
Frontier labs, civil society, and economic analysts
Public demand for precautionary governance
National representative polling conducted in late 2025 reveals a profound misalignment between political deregulation initiatives and public expectations:
Public attitudes toward AI governance (UK/EU polling, late 2025)
Gaps in current research and recommendations
This investigation highlights several areas where current technological and economic literature remains thin, speculative, or heavily contested.
Identified gaps
- Downstream application-layer impact: While the GovAI report tracks foundational model delays, there is almost no empirical research on businesses utilizing these models via API. It remains unclear whether a 53-day delay translates into measurable productivity loss for European enterprises.[1]Link to footnote
- Asymmetry of compliance costs: Lack of independent, peer-reviewed studies comparing compliance cost distribution between large tech giants and early-stage startups. Current literature fails to model whether ex-ante conformity assessment acts as an entry barrier cementing US tech monopoly power.[2]Link to footnote[10]Link to footnote
- The quantitative Brussels Effect: The degree to which non-European companies modify global product design to comply with the EU AI Act remains speculative.[61]Link to footnote
- Non-Western jurisdiction tracking: Current analysis exhibits strong Western bias; comparative data on model release schedules in Latin America, Africa, and Southeast Asia is lacking.[1]Link to footnote
Recommendations for further investigation
- Launch a Global AI Deployment Observatory: OECD or WTO could establish a real-time public registry tracking release dates, modality availability, API pricing, and legal reasons for market exclusion.[62]Link to footnote
- Conduct sectoral productivity audits: Compare growth of firms in sandboxed environments (e.g., UK AI Growth Lab legal services cohort) with those under rigid ex-ante frameworks.[47]Link to footnote
- Empirically model privacy safeguard value: Quantify the economic value of GDPR-mandated protections, preventing algorithmic discrimination, safeguarding biometrics, and protecting data rights, to enable balanced cost-benefit analysis.[52]Link to footnote
Strategic takeaways
The synthesis of empirical release data, regulatory architecture analysis, and stakeholder perspectives indicates three core conclusions for European policymakers and enterprise strategists:
1. GDPR, not the AI Act, is the binding deployment constraint
Frontier developers face immediate, operational friction from data protection law: lawful basis conflicts, special-category inference risks, and purpose-limitation constraints on training pipelines. Enterprise AI adoption strategies must architect GDPR compliance before AI Act conformity assessments.
2. Regulatory simplification can increase short-term uncertainty
The Digital Omnibus postpones demanding deadlines but introduces legislative instability through fast-track amendments, retained low-risk registration obligations, and immediate content-safety bans. Compliance teams should plan for a volatile 2026–2027 transition window.
3. Geopolitical export controls now rival domestic regulation
With zero regulatory delays in H1 2026 but growing trusted-access program restrictions and US export-control actions, European cognitive sovereignty depends as much on bilateral technology diplomacy as on domestic regulatory design. Diversification of model providers and sovereign compute capacity are structural imperatives.
- 1.John Lidiard, Oleksandra Vereschak, Tom Gibbs, and Markus Anderljung, Delays to Frontier AI in the EU and UK: Analysis of 375 LLM Releases by Meta, Google, OpenAI, and Anthropic, technical report (Centre for the Governance of AI, June 2026), https://www.governance.ai/research-paper/delays-to-frontier-ai-in-the-eu-and-uk. Authors note the report has received extensive feedback but has not gone through formal peer review.
- 2.Nicoletta Rangone, "The Paradoxes of the European Union's AI Regulation," The Regulatory Review, March 10, 2026, https://www.theregreview.org/2026/03/10/rangone-the-paradoxes-of-the-european-unions-ai-regulation/.
- 3.Markus Anderljung, public summary of GovAI delay findings (June 30, 2026), discussed in "GovAI policy director finds 11% of frontier AI models are delayed or withheld in the EU," Digg, https://digg.com/tech/yf01vvtk.
- 4.Centre for the Governance of AI, organizational overview, Effective Altruism Forum, https://forum.effectivealtruism.org/topics/centre-for-the-governance-of-ai.
- 5.Epoch AI, "Capabilities Index," accessed April 1, 2026, cited in Lidiard et al., Delays to Frontier AI in the EU and UK (2026), n. 8. The index combines multiple benchmarks into a general-capability scale; of 14 top-ranked models in the GovAI dataset since March 2023, only Claude 3 Opus was delayed to the EU (web app), with no UK delay.
- 6.Information Commissioner's Office, "Statement in Response to Meta's Plans to Train Generative AI with User Data," June 14, 2024; Data Protection Commission (Ireland), "The DPC's Engagement with Meta on AI," June 14, 2024. See also ICO, "Statement in Response to Meta's Announcement on User Data to Train AI," September 13, 2024.
- 7.Case C-184/20, OT v Vyriausioji tarnybinės etikos komisija, ECLI:EU:C:2022:601 (CJEU inference doctrine on processing liable to indirectly reveal special-category data under GDPR Article 9).
- 10.DIGITALEUROPE and Eurochambres, "Joint Industry Letter on the AI Omnibus," March 2026, https://www.eurochambres.eu/wp-content/uploads/2026/03/Joint-Industry-Letter-on-the-AI-omnibus.pdf.
- 12."UK AI Regulation in 2026: What's in Force, What's Coming, and What Your Business Should Do," Scaffold Digital, https://www.scaffold.digital/news/uk-ai-regulation-in-2026-whats-in-force-whats-coming-and-what-your-business-should-do.
- 14."Lawfulness of the Mass Processing of Publicly Accessible Online Data to Train Large Language Models," International Data Privacy Law 14, no. 4 (2024): 326, https://academic.oup.com/idpl/article/14/4/326/7816718.
- 16.European Data Protection Board, "Opinion 28/2024 on Certain Data Protection Aspects Related to the Processing of Personal Data in the Context of AI Models," December 17, 2024. Summary: CMS, "EDPB Opinion 28/2024: Key Takeaways," https://cms.law/en/deu/legal-updates/edpb-opinion-28-2024-key-takeaways-on-processing-personal-data-in-the-context-of-ai-models.
- 21."Singapore's AI Governance: What European Companies Need to Know," EY React, https://eyreact.com/singapores-ai-governance-what-european-companies-need-to-know/.
- 23.European Parliament, Interplay between the AI Act and the EU Digital Legislative Framework, study PE 778.575 (2025), https://www.europarl.europa.eu/RegData/etudes/STUD/2025/778575/ECTI_STU(2025)778575_EN.pdf.
- 27.Mario Draghi, The Future of European Competitiveness, European Commission, September 9, 2024.
- 30."EU Lawmakers Reach Provisional Agreement to Delay Key EU AI Act Obligations," Sidley Austin LLP, June 22, 2026, https://datamatters.sidley.com/2026/06/22/eu-lawmakers-reach-provisional-agreement-to-delay-key-eu-ai-act-obligations/.
- 32."EU Agrees Digital Omnibus Deal to Simplify AI Rules," White & Case, https://www.whitecase.com/insight-alert/eu-agrees-digital-omnibus-deal-simplify-ai-rules.
- 33."The European Parliament and Council Reach Agreement on the AI Digital Omnibus," Hayes Solicitors, https://hayes-solicitors.ie/news/the-european-parliament-and-council-reach-agreement-on-the-ai-digital-omnibus-regulation-amending-the-ai-act/.
- 34.Discussion of US export-control constraints on European frontier-model access; secondary commentary at https://www.reddit.com/r/BuyFromEU/comments/1u8i891/the_us_just_proved_it_can_cut_europe_off_from/. Prefer primary company and US government notices where available; Lidiard et al. (2026) discuss trusted-access programs and export-control withdrawals (Claude Fable; Mythos) as outside the public-release delay dataset but geopolitically salient.
- 42."The UK's AI Growth Lab: A Regulatory Experiment Begins," Howard Kennedy, https://disputeresolution.howardkennedy.com/post/102n7jw/the-uks-ai-growth-lab-a-regulatory-experiment-begins.
- 44."Singapore vs EU AI Act vs NIST: Framework Comparison," Tech Jacks Solutions, https://techjacksolutions.com/ai-governance-singapore/vs-global-frameworks/.
- 47.UK Department for Science, Innovation and Technology, "Advisory AI Growth Lab to Support Responsible AI Adoption in Legal Services," GOV.UK, June 8, 2026, https://www.gov.uk/government/news/advisory-ai-growth-lab-to-support-responsible-ai-adoption-in-legal-services.
- 52."Great (Public) Expectations: New Research Shows the Growing Disconnect between the Public and Government on AI Regulation," Global Government Forum (reporting Ada Lovelace Institute polling), https://www.globalgovernmentforum.com/great-public-expectations-new-research-shows-the-growing-disconnect-between-the-public-and-government-on-ai-regulation/.
- 61.Charlotte Siegmann and Markus Anderljung, "The Brussels Effect and AI: How EU Regulation Will Shape the Global AI Market," Centre for the Governance of AI, 2022, https://www.researchgate.net/publication/363052263_The_Brussels_Effect_and_Artificial_Intelligence_How_EU_regulation_will_impact_the_global_AI_market.
- 62."AI and Trade: The WTO's Thoughtful but Incomplete Assessment," EconStor, https://www.econstor.eu/bitstream/10419/337185/1/1949859088.pdf.


