Skip to main content
How the EU AI Act's Closed-Door Deal Became a Governance BlueprintEU AI Act & GPAI
5 min readFor AI Governance Leaders

How the EU AI Act's Closed-Door Deal Became a Governance Blueprint

The Challenge

On December 8, 2023, the European Union reached a political agreement on the EU AI Act. This moment was particularly challenging for AI governance teams worldwide because the regulation, which will dictate how you classify, document, and validate AI systems, was negotiated almost entirely behind closed doors.

The trilogue process involved private negotiations among the European Parliament, European Commission, and Council of the EU. This opacity posed a practical problem for organizations trying to prepare compliance frameworks. You couldn't predict which provisions would survive, how risk thresholds might shift, or how "high-risk" would be defined for your use cases. The regulation is risk-based and horizontal, applying different obligations based on risk tiers. But the details that determine your systems' tiering were decided in inaccessible meetings.

The Environment and Constraints

The closed nature of trilogue negotiations is standard EU legislative procedure, but AI governance teams faced unique constraints:

Timeline pressure: You needed to start building compliance infrastructure before the final text was available. Waiting for publication meant falling behind on Technical Documentation (Annex IV) preparation, risk tiering exercises, and AI Management System updates aligned with ISO/IEC 42001.

Regulatory precedent: The EU AI Act is the first comprehensive AI regulation globally. Its outcomes will likely influence regulatory approaches in other jurisdictions. Your compliance architecture needed to be EU-specific yet adaptable to future frameworks.

Information asymmetry: Despite reporting that provided visibility into negotiation dynamics, you couldn't get definitive answers to operational questions. Which foundation models would qualify as General-Purpose AI Models? How would the risk-based approach treat AI systems spanning multiple use cases? What validation evidence would satisfy conformity assessment bodies?

Cross-functional coordination: Legal teams needed to understand technical risk controls. Engineering teams needed to grasp regulatory thresholds. Model risk management teams needed to map existing SR 11-7 practices to EU requirements. But you were coordinating around a moving target.

The Approach Organizations Actually Took

Smart governance teams didn't wait for perfect information. They built frameworks around what they could control:

Risk tiering dry runs: Even without final text, you could inventory your AI systems and practice the risk classification exercise. Running classification workshops with product and legal teams before the regulation dropped meant you'd execute faster once it did.

Documentation infrastructure: Technical Documentation requirements likely included training data characteristics, model architecture decisions, validation results, and ongoing monitoring. Organizations started building documentation pipelines to support these requirements regardless of final wording. If you already capture annotation quality metrics, model lineage, and robustness testing results in structured formats, you're adapting to new requirements, not building from scratch.

Monitoring what could be monitored: Tracking coverage of the negotiations allowed organizations to spot emerging consensus on provisions, understand which parties were pushing for stricter requirements, and identify areas of likely compromise. This wasn't perfect visibility, but it was actionable intelligence.

Parallel framework mapping: Teams mapped draft EU AI Act requirements against ISO/IEC 42001, NIST AI RMF 1.0, and existing model risk management practices. Where requirements overlapped, you could build once and satisfy multiple frameworks. Where they diverged, you identified gaps early.

Results: What the Agreement Revealed

The political agreement confirmed the regulation's fundamental architecture: risk-based, horizontal, with differentiated obligations. For governance teams, this validated the tiering exercises you'd already run. Systems you'd flagged as potentially high-risk would indeed face conformity assessment. Lower-risk systems would face lighter transparency requirements.

The agreement also clarified that this regulation would have global reach. If you deploy AI systems that affect EU persons, you're in scope. That meant governance frameworks built for EU compliance would become de facto global standards for many organizations.

What Would Work Differently Next Time

The trilogue opacity revealed a structural challenge in AI governance: you're often building compliance infrastructure before you have complete requirements. Here's what that experience suggests for future regulatory cycles:

Don't optimize for the draft: Early draft language rarely survives negotiation intact. Build flexible documentation and validation pipelines that can accommodate requirement variations, not rigid checklists tied to specific draft provisions.

Invest in regulatory intelligence: Organizations that tracked negotiation coverage had weeks of advance notice on likely outcomes. That's weeks you could use to brief executives, update risk assessments, and prepare implementation teams. Regulatory intelligence is a competitive advantage in compliance readiness.

Build for the principle, not the letter: The risk-based approach was consistent across drafts, even as specific thresholds shifted. If you built validation practices around the principle of risk-proportionate controls, you adapted faster than teams that optimized for draft-specific requirements.

Create regulatory translation layers: Your engineering teams shouldn't need to parse EU legislative text. Your governance function should translate regulatory requirements into technical specifications, validation protocols, and documentation standards. That translation layer becomes reusable as new frameworks emerge.

Takeaways for Your Team

The EU AI Act's closed-door negotiation process won't be the last time you build governance frameworks with incomplete information. Here's how to operate in that environment:

Start your risk tiering exercise now, even if you're uncertain about final thresholds. The practice of systematic AI system inventory and risk classification has value independent of any single regulation.

Build documentation infrastructure that supports multiple frameworks simultaneously. Technical Documentation (Annex IV), Model Cards, and validation evidence requirements overlap substantially across regulations. Capture once, report many ways.

Establish regulatory monitoring as a formal governance function. Someone on your team should own tracking emerging requirements, translating them for technical audiences, and updating your compliance roadmap.

Don't wait for perfect clarity. The EU AI Act's political agreement came after marathon sessions and closed-door negotiations. Your compliance timeline doesn't pause for legislative process. Build what you can control, stay close to reliable regulatory intelligence, and design for adaptability.

The regulation is now moving toward final publication and implementation timelines. Organizations that used the trilogue period to build foundational capabilities are adapting. Those that waited for perfect information are starting from scratch.

You Might Also Like