The European AI Act was presented as the most ambitious regulatory framework in the world for artificial intelligence. Years of negotiations, hundreds of technical pages, dozens of consultation groups. The result: a document that, on paper, sounds reasonable. In practice, it contains a loophole large enough for every actor it was supposedly meant to control to slip through.

The key lies in a single provision: "high-risk" AI systems already covered by existing sectoral regulation are excluded from the AI Act's strictest obligations. Banking, healthcare, critical infrastructure, judicial systems. Precisely the sectors where AI is already making decisions that affect millions of lives. The official logic is that regulation already exists there. What goes unsaid is that this sectoral regulation was designed before generative AI existed, and that the very actors who wrote it back then are the ones now operating the models.

This is not a design flaw. It is the predictable result of how regulatory capture works.

The process has a long history. In Rome, the collegia — guilds of merchants and craftsmen — got the Roman state to formalize their practices as law. Not to protect the public, but to crystallize competitive advantages that already existed. In medieval Europe, the guilds that supposedly regulated the quality of work also regulated who could compete and under what conditions. In the late nineteenth century, Standard Oil didn't disappear with antitrust regulation: it fragmented into subsidiaries that continued coordinating prices informally for decades, while the legal framework gave the appearance of competition. The regulated party doesn't just survive regulation; it frequently ends up writing it.

What's interesting is that no corruption is needed for this to happen. You don't need bribes, conspiracies, or backroom deals. The physics of resources alone is enough. When the European Commission opens a technical consultation period on AI structures in critical infrastructure, who has the specialized lawyers, the public policy teams, and the budgets to participate with four-hundred-page submissions? Not civil organizations. Not independent academics on temporary contracts. It's Microsoft, Google, the major European banks, and insurers with entire divisions dedicated to regulatory management. Capture isn't a conspiracy; it's gravity. Resources flow toward those who already have them.

The same process repeats itself in the energy transition. The big oil companies didn't disappear with climate agreements: they reinvented themselves as "energy companies" and captured the green subsidies. Extractive dynamics persisted under new vocabulary. Something analogous happens with the AI Act: language models keep being trained on the same data, the same five or six players keep controlling the compute infrastructure, and the same lobbyists who took part in the technical consultations now publicly explain that the European framework is "balanced" and "responsible." The vocabulary changed. The power structure did not.

There's a constant that repeats itself in complex regulatory frameworks: exceptions don't get renegotiated, they get inherited. Every "reasonable" exception becomes the starting point for the next negotiation. Companies don't go back to the table to defend what they've already won; they simply build on top of it. That's how it went with tax exemptions for certain financial instruments before 2008. That's how it went with liability exemptions for digital platforms in the nineties, which remain in force decades later under the label "safe harbor." What's granted today as a temporary exception becomes a vested right tomorrow. And vested rights don't get touched.

This is more complicated than it looks from the outside. There are researchers who have spent years arguing that sectoral regulation can be more effective than horizontal frameworks, precisely because sectoral regulators know specific contexts better. That's not an argument without merit. The problem is that it assumes independent, well-funded sectoral regulators with real technical capacity to audit AI structures. In practice, European sectoral regulators in banking and healthcare already have significant technical capacity deficits. Handing them oversight of advanced AI structures without additional resources isn't smart decentralization; it's abdication with good PR.

What the AI Act certainly changes is the vocabulary of the debate. There are now official terms: "high-risk systems," "data governance," "human oversight." Those terms matter because they define what can be discussed and how. But the new vocabulary doesn't change who controls the servers, who owns the training data, or who can actually audit a seventy-billion-parameter model. The infrastructure remains concentrated. The incentives remain aligned with concentration.

I don't have a clear answer for how to fully solve this, and I distrust anyone who claims they do. But there are signs of which direction is worth exploring. The governance models that have historically worked in situations of regulatory capture are not the ones that try to regulate from above with more technical detail. They are the ones that build counterweights from below: citizen audits with real access to systems, public funding for independent technical participation in regulatory consultations, and — this is key — mechanisms that make the cost of capturing regulation higher than the benefit. Today that calculation is inverted. Capturing is cheap; resisting capture is expensive.

The AI Act is not the end of artificial intelligence's regulatory history. It's the first chapter. And as with any first chapter, what gets established here — which actors hold the power to define terms, which exceptions get codified, which vocabulary becomes official — will shape everything that comes after. The medieval guilds didn't start with absolute monopolies. They started with reasonable exceptions.

Stones don't lie, but historians sometimes do.


Sources:

1. Regulation (EU) 2024/1689 of the European Parliament — AI Act, official consolidated text

2. Stigler, G. (1971). "The Theory of Economic Regulation." Bell Journal of Economics and Management Science, 2(1), 3–21.

3. Kolko, G. (1963). The Triumph of Conservatism. Free Press — analysis of regulatory capture in Standard Oil and the railroads

4. Djankov, S. et al. (2002). "The Regulation of Entry." Quarterly Journal of Economics, 117(1) — empirical findings on regulation that institutionalizes incumbents

5. Zuboff, S. (2019). The Age of Surveillance Capitalism. PublicAffairs — power structure in data infrastructure