One of the EU AI Act’s principal stated purposes is regulatory harmonization — replacing the patchwork of national AI regulations that were emerging across Europe with a single coherent framework that creates a genuine single market for AI. The regulation’s advocates argued, persuasively, that fragmented national approaches to AI governance would produce compliance complexity that disadvantaged European companies while leaving cross-border AI harms unaddressed.

Seven months into serious enforcement, the harmonization goal is being tested and, in important ways, failing. The EU AI Act is a single regulation. It is being enforced as at least 27 different regulations, each filtered through a national competent authority with its own resources, interpretation culture, political context, and enforcement philosophy.

The divergence isn’t arbitrary or surprising. The EU has always been a political system that balances shared rules against national sovereignty. The GDPR produced similar divergence — different DPAs have very different enforcement profiles — and the AI Act is structured similarly. But the divergence is consequential in ways that the regulation’s architects arguably underestimated, and three country case studies illustrate the range.

Germany: Process as Value

Germany’s Federal AI Office launched in January 2026 with 120 staff, a €45 million budget, and a mandate from the Federal Ministry for Digital Affairs. It is by far the best-resourced national AI competent authority in the EU. It is also, characteristically, the most procedurally rigorous.

The German enforcement approach prioritizes legality and process over speed. Before issuing a compliance notice, the Federal AI Office runs its intended action through an extensive internal review — technical assessment, legal review, proportionality analysis, parliamentary notification in some cases. This process takes months. The benefit: enforcement actions are legally robust and rarely overturned. The cost: companies can operate non-compliantly for extended periods while the Office assembles an airtight case.

Germany’s approach also reflects a genuine commitment to due process for companies being investigated. The Federal AI Office has adopted a “cooperative compliance” model — engaging companies in dialogue before formal enforcement, working toward voluntary compliance agreements rather than adversarial proceedings. This approach produced results in the ING mortgage case, where a compliance agreement was reached through cooperation rather than enforcement. It can also be used by sophisticated companies to extend the timeline for compliance indefinitely.

The German constitutional tradition matters here. The Federal Constitutional Court’s jurisprudence on the rule of law requires administrative enforcement actions to be proportionate, specific, and legally grounded. Germany’s AI Office isn’t being slow out of institutional laziness. It’s being rigorous out of institutional DNA. The same judicial culture that produced the Bundestag’s strict oversight of intelligence services, the BVerfG’s extensive review of EU treaty ratifications, and the decades-long Lüth/Spickhoff privacy jurisprudence shapes how a German federal office approaches AI regulation enforcement.

For large companies, this is somewhat favorable — the careful process creates notice and opportunity to negotiate. For smaller companies, the “cooperative compliance” model is opaque and resource-intensive to participate in. You need lawyers to have a productive dialogue with the Federal AI Office.

France: The Aggressive Interpretive Approach

CNIL — historically France’s data protection authority — has assumed the role of national AI competent authority while pending the establishment of a dedicated AI supervisory authority. CNIL has been enforcing GDPR aggressively since 2019 (far more aggressively than the Irish DPC) and has brought the same philosophy to AI Act enforcement.

France’s distinctive approach involves expansive interpretation of the Act’s provisions combined with relatively rapid enforcement timelines. The CNIL’s determination that credit “scoring” includes any AI system that “materially influences” credit decisions is broader than the German equivalent interpretation. France’s position on the vulnerability exploitation prohibition is more expansive than most other national authorities. CNIL has publicly stated that private sector biometric identification in publicly accessible spaces is prohibited under the Act regardless of the law enforcement carve-out, because the space itself — a train station, a shopping mall — is “publicly accessible” in a sense that doesn’t admit private exceptions.

This expansive interpretation has been criticized by industry as exceeding the Act’s text and by other member states as creating asymmetric compliance obligations. But CNIL’s legal basis is defensible. The Act’s provisions were written broadly enough to support France’s interpretations, even if they weren’t the interpretations the majority of the Council or Parliament anticipated. French administrative courts have, so far, upheld CNIL’s AI Act enforcement actions in the three cases that have been litigated.

The practical effect is that companies operating in France face materially more demanding compliance obligations than companies operating in Germany or Ireland — for the same regulation. A fintech serving French customers needs to assume CNIL’s broader interpretation. A fintech serving German customers can operate under the Federal AI Office’s narrower one. This is precisely the compliance fragmentation the regulation was supposed to prevent.

Ireland: The GDPR Shadow

Ireland’s AI Act competent authority sits within the Data Protection Commission — the same body that spent years being criticized by EU counterparts for slow GDPR enforcement of US tech companies headquartered in Ireland. The overlap between Ireland’s role as the EU headquarters jurisdiction for major US tech companies and the DPC’s reputation for soft enforcement is not subtle.

The DPC’s AI Act enforcement to date, eight months in, has been essentially nil in terms of formal actions. This is partly defensible — Ireland has fewer AI companies headquartered there than Germany or France, and the Notified Body designation process for Irish organizations is still underway — but it also reflects the DPC’s institutional culture and resource constraints. The Commission has a staff of approximately 170 people for all DPC functions, with only a fraction dedicated to AI Act enforcement.

The major US tech companies with Irish EU headquarters — Microsoft, Google, Meta, LinkedIn — are in active dialogue with the DPC about AI Act compliance rather than facing enforcement proceedings. This is not necessarily inappropriate; cooperative compliance can be an efficient regulatory approach. But the contrast with France’s adversarial enforcement posture is stark.

The EU AI Office has extraterritorial enforcement authority that can override national competent authorities in cases involving GPAI models and prohibited practices. This backstop was designed partly to address GDPR enforcement bottlenecks at the national level. Whether the EU AI Office will use it to compensate for Ireland’s soft enforcement posture — essentially taking over cases that the DPC isn’t pursuing — remains to be seen. The political dynamics are delicate: the EU AI Office overriding Irish DPC would create sovereign friction and set a precedent for EU-level override of national enforcement that member states are generally sensitive about.

What Divergence Means for Companies

The three-speed enforcement reality creates a genuine regulatory arbitrage opportunity for companies large enough to optimize their EU corporate structure.

A US AI company entering the EU market must designate an EU authorized representative (for GPAI providers) or operate through an EU entity. The choice of jurisdiction for that entity affects which national competent authority has primary jurisdiction over their EU operations. Choosing Ireland means the DPC. Choosing Germany means the Federal AI Office. Choosing France means CNIL.

The US tech sector has spent 20 years optimizing its EU corporate structure around Ireland. Some companies are reconsidering this under the AI Act — not because Ireland is definitively more lenient (the DPC’s long-term enforcement trajectory under GDPR has been upward) but because the GDPR enforcement embarrassments have made the Irish structure politically conspicuous. Being headquartered in Ireland while operating AI systems across Europe generates adverse media coverage that has its own cost.

The smaller, EU-native companies cannot optimize their jurisdiction — they’re headquartered where they’re headquartered. A French AI company cannot escape CNIL’s jurisdiction by redomiciling to Ireland any more than a French taxpayer can escape the French Revenue Service. The regulatory arbitrage opportunity benefits the multinational and disadvantages the domestic player.

The harmonization goal of the EU AI Act — creating a single regulatory environment that removes cross-border compliance friction — is not being achieved in its first year of enforcement. The single regulation has fractured into multiple enforcement regimes, predictably and perhaps irreversibly. As with GDPR, the divergence will likely narrow over time as the Court of Justice issues binding interpretations, as the EU AI Office asserts stronger coordinating authority, and as national competent authorities develop shared practice norms. The GDPR is a more harmonized regulation in 2026 than it was in 2018.

The question is what happens to the companies operating in the current divergent environment while harmonization catches up. Some will navigate it successfully. Some will lobby for their preferred national interpretation to become the EU standard. Some will lose the compliance arbitrage games they can’t afford to play. The regulation is creating winners and losers in ways that have more to do with corporate structure and political geography than with AI quality or safety.

The Court of Justice Question

The ultimate harmonization mechanism for the EU AI Act will be the Court of Justice of the European Union. When divergent national interpretations generate conflicting outcomes — when a company compliant in Germany is found non-compliant in France, or when an enforcement decision from one NCA contradicts guidance from another — the cases will eventually reach the CJEU for interpretive resolution.

This is how EU law achieves practical harmonization. GDPR’s harmonization in practice has come largely through CJEU judgments — the Schrems I and Schrems II decisions on data transfers, the Planet49 decision on cookie consent, the Fashion ID decision on joint data controllers. These cases established authoritative interpretations that national DPAs were then required to follow.

The first CJEU references on EU AI Act interpretation are likely several years away. CJEU cases proceed on timescales measured in years, not months. The enforcement divergence documented above will persist through at least 2028 and possibly 2030 before CJEU guidance is available on the most contested interpretive questions.

Some accelerants are possible. The EU AI Office can issue binding opinions in certain cases, particularly involving GPAI models. If national NCAs formally disagree about a cross-border case, the EU AI Office has authority to intervene. These mechanisms can produce faster convergence than waiting for CJEU references. But they require the EU AI Office to be willing to use its authority against member states whose interpretations it disagrees with — a politically sensitive exercise that the Office, staffed with officials who need to maintain working relationships across 27 member states, will use carefully.

The German precision, French aggression, and Irish accommodation are not aberrations. They’re the 27-speed Europe that the regulation was supposed to harmonize, running its normal course. The AI Act has one set of rules. It has 27 national enforcement cultures. These are not the same thing, and until the CJEU makes them more convergent, the EU’s single market for AI governance will remain more aspiration than reality.

Get the best of Think Different in your inbox

One email a month: new articles, reviews and the upcoming live webinar + free recording. No spam, unsubscribe anytime.