Telecommunication network above Europe viewed from space with connected system for European 5g LTE mobile web, global WiFi connection, Internet of Things (IoT) technology or blockchain fintech

The bill isn’t coming from Brussels:Bizarre but true—Why the EU AI Act Could Become a Competitive Advantage for German Companies

The strongest warnings about unchecked AI are now coming from Silicon Valley, not Brussels.

The EU AI Act is viewed by many German companies as a bureaucratic monster. At the same time, even the developers of AI technology are warning more loudly than ever before about the risks of AI—a shift that hardly anyone has noticed and that, ironically, makes the much-maligned EU AI Act a model to follow.

The critics have changed sides

On September 14, security law expert Dennis-Kenji Kipker made a statement on ZDF that, not too long ago, would have been considered irresponsible alarmism—and that still sounds a bit like it: “We are getting closer to an AI catastrophe.”

Whatever “AI catastrophe” may mean, Kipker describes this development as a house of cards that is growing ever higher and faster, posing risks to energy, infrastructure, logistics, and military systems.

The occasion was a warning from Dario Amodei, the CEO of Anthropic: A group of AI agents could take over the internet within six to twelve months. Sam Altman has expressed a similar view. Kipker believes the specific timeframe cannot be empirically verified, but he does not dispute the general direction of the prediction.

What’s more interesting than the prediction is who’s making it. For years, criticism of AI came from regulators, while enthusiasm for AI came from industry. Now it seems to be the other way around. Kipker adds a point that is rarely mentioned in the German debate: The EU was initially underestimated for its regulatory approach, but with the AI Act, it is now ahead of the U.S. and China.

A Goal Without Boundaries

In July 2026, the British AI Safety Institute documented just how little it takes for AI systems to go haywire. In controlled test environments with internet access, 122 test runs were conducted across seven models. In ten cases, the agents behaved in an unauthorized manner on the real internet. Nineteen actions targeted real people and organizations: attempts to inject malicious code into an open-source project, fabricated identities, and social engineering.

The most revealing figure in the report is zero. Not a single one of these actions had been expressly prohibited to the agents. They had a goal, but no guidelines.

A case from the same year shows that there is another way. When the U.S. financial services provider Robinhood granted AI agents access to brokerage accounts and credit cards in May 2026, four safeguards were in place: a separate account, a fixed spending limit, a push notification for every transaction, and the ability to disconnect the agent at any time. In other words: minimal permissions, a complete audit trail, and the ability to disable the agent. One broker has understood what AI governance is. Most companies currently rolling out agents likely haven’t yet.

The bill isn’t coming from Brussels

At this point, you’re probably expecting us to mention fines: depending on the violation, up to 15 million euros or three percent of global annual revenue. That figure appears in every presentation on the topic, and for the vast majority of companies, it remains a theoretical figure because they’re unlikely to ever be affected on that scale.

The real threat comes from elsewhere—from the competition. The bill comes from your largest customer’s purchasing department, in the form of a questionnaire that strictly adheres to the AI Act. One key question, in essence, is: Which AI systems do you use, and how do you ensure their compliance? At that moment, it’s not the quality of your product that matters, but whether you can provide a well-founded answer.

Three companies that have long been acting on this principle demonstrate that this is not just an empty prediction. Mastercard provides bank customers with model documentation before contracts are signed, thereby shortening sales cycles in B2B business. SAP has been certified to ISO/IEC 42001 since September 30, 2025, and undergoes annual audits. Deutsche Telekom has integrated its AI guidelines into its Supplier Code of Conduct, thereby extending the requirement to its entire supply chain.

The pattern is the same for all three. Governance artifacts are not cost centers, but rather selling points. The competitive advantage doesn’t come from the law itself. It arises because most people still view it as a burden—and haven’t understood how important it is to set guidelines for AI so that it can realize its full potential.

The Crucial Preliminary Question

Anyone looking to get started immediately runs into a question that sounds trivial but, in practice, takes months to answer: What AI systems do we have, and in what capacity do we use them?

For day-to-day purposes, a three-step approach suffices. Anyone who places an AI system on the market under their own name is a provider, subject to the full range of obligations—from risk management to conformity assessment. Anyone who uses third-party systems unchanged under their own responsibility is an operator. Anyone who merely clicks on what their employer provides is not a party subject to these requirements.

The typical counterarguments are well known. First: “We’re just buying it.” Purchasing makes you an operator, not a bystander. The second objection is more costly: The situation becomes critical when a company modifies the intended use of an AI system—as defined by the provider—in such a way that it becomes a high-risk system under Annex III. In that case, the previous operator can, for regulatory purposes, become a provider itself. No one has changed a single line of code. The only thing that has changed is the purpose.

This preliminary question is not a legal one, but an organizational one. It takes months to resolve because no one in the company has a clear overview of the situation.

What’s the problem?

So why aren’t companies already actively implementing these changes? There are three reasons for this, and none of them is technical in nature.

First, the issue has no owner. It cuts across Legal, IT, Procurement, Human Resources, line departments, and employee representation. The most costly mistake is the compliance silo: the project gets stuck solely in the Legal Department, with no connection to day-to-day operations. The result is policies that no one follows and no one understands.

Second, the works council is often involved too late. Section 87(1)(6) of the Works Council Act (BetrVG) is interpreted broadly when it comes to AI, and anyone who waits until the very end to address the issue of co-determination will, realistically, lose many months. Here’s a detail: Since the enactment of the Works Council Modernization Act, the works council’s right to an expert when AI is used—pursuant to Section 80(3) of the Works Constitution Act (BetrVG)—is considered mandatory. The works council no longer needs to justify this request. Anyone who goes into these negotiations ill-prepared ends up paying for the opposing side’s expert with their own time.

Third, there is a lack of expertise: people who understand the legal and technical requirements and recognize that this is a management and project management task.

What Needs to Happen in the First Few Weeks

I use a four-step process, which I’ve deliberately kept simple:

  • View: A comprehensive list of all AI systems across all areas, including shadow AI. Not a list of purchased licenses, but a list of what is actually being used.
  • Prioritize: Determine the role and risk class for each system, then select the three most critical ones. Everything else can wait.
  • Taxes: a policy document, established human oversight, record-keeping, and an early meeting with legal counsel and the works council.
  • Responsibility: Each line must have a name and a date. Without that, nothing happens—and that applies here just as it does in any other case.

A timeline of approximately 120 days has proven effective: project charter and sponsor by week two, complete inventory by week eight, gap assessment by week ten, AI policy and decision-making body by week twenty.

A Field for Interim Managers, but Not for Everyone

The DDIM’s DACH market study shows where our mandates lie: 35 percent change, and another 32 percent crisis, turnaround, and restructuring. Against this backdrop, AI governance is not a new field, but rather a new manifestation of a familiar pattern. It is an issue that cuts across the entire organization, is subject to time pressure, generates resistance, and doesn’t belong to anyone internally.

Nevertheless, it’s not suitable for everyone, and that should be stated openly. Those who master only the legal side will fail at implementation and end up producing guidelines that are destined for the filing cabinet. Those who master only the technical side will fail when it comes to documentation and project management. What’s needed is a solid understanding of the regulations, project management, enough technical knowledge to have a substantive discussion with IT, and the ability to translate all of this into terms that management, the business unit, and the works council can understand—in other words, excellent communication and stakeholder management skills.

The industry is already preparing for this. F&P Executive Solutions AG, where I serve as a senior partner, has established an AI Solutions task force. Its goal is to support companies in implementing AI, with a specific focus on governance—specifically, the economic implications of regulations such as the EU AI Act and NIS2. Such structures tend to emerge first in places where people see on a daily basis where a role is missing within a company.

The standard remains the same

At an industrial company without its own IT, legal, or compliance departments, the basic regulatory framework was in place after ten weeks: an inventory, a roles matrix, a policy, and a trained workforce. The time required to prepare proposals fell by 73 percent because documented processes are faster than improvised ones.

Whether such an assignment was a good idea will become clear later. AI governance that depends on a single person is not true governance. After all, the organization must remain capable of managing itself even without an interim manager.

About the Author

Dr. Tasso Enzweiler is an interim manager and AI governance strategist. Early in his career, he was a co-founder and chief reporter at the Financial Times Deutschland; he subsequently served as managing director of management consulting firms for over a decade. Since 2014, he has been working as an interim manager in regulated industries, and for the past two and a half years, he has focused on the EU AI Act and AI governance.

Sources: ZDFheute, September 14, 2026 · UK AI Safety Institute, Incident Report, July 2026 · Robinhood Markets, May 2026 · Company data from Mastercard, SAP, and Telekom · DDIM DACH Market Study 2026