The EU AI Act’s prohibited practices ban, effective February 2025, frames itself as a structural barrier against biometric surveillance, but enforcement reveals significant gaps. Law enforcement carve-outs negotiated by France permit real-time facial recognition for kidnapping searches, terror threat prevention, and serious crime tracking, with judicial authorization requirements that allow deployment before approval is secured.

Beyond civil liberties concerns, the Act imposes compliance burdens on European startups while doing nothing to address the continent’s dependence on US-owned cloud infrastructure. European AI models run inference on server clusters owned by American corporations, meaning regulatory sovereignty over model weights and training data does not extend to the physical compute layer underpinning those systems.

The EU AI Act represents a massive gap between Brussels’ regulatory ambitions and Europe’s physical hardware footprint. As I have argued since the framework’s inception, the prohibited practices ban that went into effect in February 2025 was framed as a structural barrier against biometric surveillance. But look beneath the regulatory rhetoric, and the enforcement reality is much messier. The framework creates massive compliance hurdles for local software startups while leaving the continent entirely dependent on US cloud computing clusters.

The biometric loopholes France left behind

The ban on real-time public facial recognition was celebrated as an absolute victory for civil liberties. It was not. During the draft negotiations back in 2024, France successfully lobbied for critical law enforcement carve-outs. These exemptions allow police to deploy real-time biometric tracking for targeted searches of kidnapping victims, prevention of imminent terror threats, and tracking suspects of specific serious crimes.

The requirement for judicial pre-authorization was supposed to prevent abuse, but to my eye, the operational templates are highly permissive. In practice, a local authority facing an active threat can deploy the technology first and seek judicial sign-off hours later. This is not governance without exceptions; it is a framework that codifies state surveillance capabilities under the guise of citizen protection.

The infrastructure friction nobody is solving

The compliance overhead is choking the European startup ecosystem. While the European Union drafts compliance forms, I see local firms like Mistral facing a stark reality: they cannot run their models on sovereign silicon. The physical hardware clusters are owned by US hyperscalers. The Fable 5 shutdown last week proved that reliance on US cloud infrastructure is a single point of failure.

This is the structural contradiction of the EU AI Act. It attempts to regulate the model weights and training datasets while ignoring the physical compute layer. As I laid out in my Mistral vs Cerebras breakdown, a model is only as sovereign as the silicon it runs on. When a European enterprise deploys an AI agent, the inference runs on server racks in Ireland or Germany that are owned and managed by American corporations under US jurisdiction.

Personally, I keep coming back to the hardware packaging gap. Europe has built a massive compliance apparatus, but it has failed to build the foundry capacity or the server clusters to support it. The result is a vassal-state economy where Brussels regulates the interface while Washington controls the glass. Until European enterprises can run their inference on physical clusters they own and operate locally, the EU AI Act is just governance theater for a technology they can only borrow.