Say an AI system denies your mortgage, misreads your scan, or flags you at a border, and you want to sue. In Europe, as of this year, there is no law written for your problem. Say instead you are the company that built the system and you want to prove it complies with the AI Act’s high-risk rules. There is no standard published for you to comply against. Two holes, opposite ends of the same law, and they rhyme: the citizen cannot prove harm, and the company cannot prove conformity, because the machinery that was supposed to let either of them do it was quietly withdrawn or never finished. I parked both of these threads when I wrote up the Act itself, calling them the standardization weeds and the liability rabbit hole. They turn out to be the whole load-bearing structure, and both are missing.
Start with the one that got killed outright. The AI Liability Directive was never the famous part of Europe’s AI push, but it was the part meant to make the rest mean something to an ordinary person. The Commission tabled it on September 28, 2022, as one half of a pair, the AILD alongside a rewritten Product Liability Directive, and its entire reason for existing was the black-box problem. Traditional liability law asks a victim to show that an identifiable someone did an identifiable wrong that caused the harm. That test has worked for centuries and it falls apart the moment the defendant is a model whose own builders cannot fully explain why it did what it did. The AILD’s fix was procedural and clever: give claimants a right to disclosure of evidence about a high-risk system, and a rebuttable presumption of causation so they did not have to reverse-engineer a neural network to get through the courtroom door. It shifted the burden off the person least able to carry it.
It is gone. On February 11, 2025, the Commission listed the AILD for withdrawal in its 2025 work program, citing “no foreseeable agreement” among the member states, and made it official in the Official Journal on October 6 after a July meeting confirmed it. The reasoning was that consensus had collapsed and the Commission would “assess whether another proposal” was needed, which is Brussels for we are not touching this again soon. What annoys me about the framing is how it was sold as simplification, a bit of deregulatory housekeeping to lighten the load on European industry, when the practical effect is to hand the black-box problem straight back to twenty-seven national court systems. The exact fragmentation the single market exists to prevent is now the default setting for AI harm.
What actually survived, and why it is not the same thing
The honest version has a wrinkle the deregulation-versus-victims story leaves out. The other half of that 2022 pair, the revised Product Liability Directive, lived. It was adopted in 2024, applies from late 2026, and it was explicitly rewritten to cover software and AI systems as products, with strict liability on the manufacturer and some of the same disclosure and presumption ideas the AILD carried. So it is not true that a victim has nothing. It is true that they have the harder road. The PLD is a product-defect regime: you are suing over a defective thing, on strict-liability terms that fit a faulty brake better than a biased hiring model. The AILD was the fault-based companion built for the cases the PLD does not reach cleanly, the service that discriminates, the decision that harms without a defective “product” in the classical sense. Killing it does not leave a void so much as a gap with awkward edges, and which claims fall into that gap will now be litigated country by country for years.
Parliament, for its part, did not love the burial. The JURI committee held an exchange of views in December 2024 where members split openly on whether the AILD should die, and the Parliament’s own research service had floated turning it into a full software liability regulation rather than a directive, a stronger instrument, not a weaker one. That is the tell that this was not a tidy technical retreat. It was a contested political choice to drop the harder, more citizen-facing law and keep the one industry could live with, made under the same deregulatory banner that softened the rest of the Act.
The standard that does not exist yet
The other hole is quieter and, for anyone actually trying to ship a high-risk system, more immediately paralyzing. The AI Act does not tell a company how to comply. By design, it delegates the technical detail to harmonized standards written by CEN and CENELEC, the European standards bodies, through a joint technical committee called JTC 21. The deal is the one that runs through all of EU product law: meet the harmonized standard, and you get a “presumption of conformity,” a legal safe harbor that says you have satisfied the law’s requirements. It is the single most important compliance mechanism in the entire Act, and here is the problem. The standards are not done.
JTC 21 was established in June 2021, and it is not a small operation, with more than 300 experts working under a Commission mandate. The original request, M/593, asked for the standards by April 2025. That deadline came and went. CEN-CENELEC flagged publicly in April 2025 that the work would eat much of 2025 and spill into 2026; the mandate got amended and reissued as M/613, and in October the boards agreed to accelerate to get the prioritized deliverables out by the fourth quarter of 2026 at the earliest, with the amended request running all the way to February 2027. As of the last public snapshot, the furthest-along document, the quality-management standard for Article 17, had only reached the formal-vote stage. Not one of them has the thing that actually matters, a citation in the Official Journal, which is the step that switches on the presumption of conformity under Article 40. Until that happens, there is no safe harbor to build to. Companies are being asked to comply with a law whose compliance manual is still in committee.
This is not a footnote. It is the reason the Act’s teeth moved. When the Commission published its Digital Omnibus in November 2025 and pushed the standalone high-risk obligations from this August all the way to December 2027, and the product-embedded ones to August 2028, the justification it reached for first was the missing standards and the slow build-out of national authorities and conformity-assessment bodies. The standards gap did not just inconvenience the rollout. It rewrote the timeline. A Commission spokesperson spent late 2025 insisting this was not a “stop the clock”; it was “common sense,” which is a distinction that will comfort exactly nobody who structured a compliance program around the original dates.
The case for the retreat, and where it stops convincing me
I want to be fair to the defensible version, because there is one. Forcing a legal deadline in front of standards that do not exist produces compliance theater, not safety. A company cannot build to a document nobody has finished, and pretending otherwise would just generate a paperwork ritual that protects no one. On the standards side, waiting to get it right is far better than shipping a half-baked safe harbor that has to be redone. I made a version of this argument about the Act as a whole, and it holds here too. The withdrawal of the AILD has a coherent defense as well: a fault-based AI liability regime is brutally hard to draft well, the PLD already reaches a lot of the territory, and a badly written directive layered on top could have created more legal uncertainty than it resolved, which lands hardest on the European startups the continent is trying not to strangle.
Where it stops convincing me is the pattern. This is the same flinch, twice. The Act’s core high-risk obligations slip sixteen months the first time industry pushes hard, and the citizen-facing liability law gets dropped under the same deregulatory banner, and in both cases the thing that survives is the version that asks the least of the largest companies. A regulator that moves its own goalposts the moment the lobbying gets loud has taught every future lobby precisely how to win, and that is a worse long-run outcome than either shipping on time or admitting the law was too ambitious and rewriting it in the open. The charitable reading of any single move here is real. The charitable reading of all of them together is a lot harder to hold.
What happens next
The near-term calendar is easier to state than to trust. The prioritized harmonized standards are targeted for late 2026, with the amended mandate running into February 2027, and only once they clear an Official Journal citation does the presumption of conformity actually exist. The high-risk obligations they underpin now land in December 2027 and August 2028. On liability, the Commission has left itself the option to “assess whether another proposal” is needed, which on current form means nothing concrete before the political weather changes, while the revised Product Liability Directive quietly becomes the main event by default when it starts applying at the end of this year. So the real answer to who is liable when an AI harms you in Europe is, for now, your member state’s courts and a product-liability regime that was not built for the messiest AI cases.
I am not getting into the interplay with the international standards here, the ISO/IEC 42001 management-system norm and how it maps onto the European ENs, because that overlap is its own tangle and this is already the deep end. What I will say is that the Act I keep seeing described as the toughest AI law on the planet is, underneath the headline, a compliance regime with no finished compliance manual and a harm regime with its sharpest instrument withdrawn. The off switch I keep arguing sovereignty comes down to is only as real as the plumbing behind it, and right now the plumbing is a standard stuck in formal vote and a liability directive in the Official Journal’s dead-letter file. Ask me at the end of 2026 whether the standards actually landed on schedule. Given the last two years, I would not build a compliance program around the answer being yes.
Sources
- AI Act Blog, “AI Liability Directive withdrawn: what applies in 2026” (AILD purpose, black-box problem, national-fragmentation effect)
- EAPIL, “European Commission Withdraws Two Proposals” (Official Journal withdrawal, 6 October 2025)
- IAPP, “European Commission withdraws AI Liability Directive from consideration” (“no foreseeable agreement” language)
- European Parliament Legislative Train, “AI liability directive” (JURI exchange of views, December 2024)
- Gibson Dunn, “EU Product Liability Directive: Responding to Software, AI and Complex Supply Chains”, March 2026 (revised PLD covers software and AI)
- KLA, “JTC 21 Standards Tracker: CEN-CENELEC AI Act Deliverables”, June 2026 (M/593 to M/613, Q4 2026 target, EN 18286 at formal vote, Article 40 citation)
- CEN-CENELEC, “Update on CEN and CENELEC’s Decision to Accelerate the Development of Standards for AI”, 23 October 2025
- Freshfields, “EU AI Act unpacked #34: The final Digital Omnibus on AI” (standards gap cited as reason for high-risk deferral)
- EU AI Act (independent tracker), “Standard Setting” (April 2025 missed deadline, delivery timeline)