We are an Estonian legal firm that has experienced cryptocurrency regulation in practice: licences, supervision, tighter requirements and part of the market leaving the jurisdiction. At the same time, we work with AI tools every day and support AI projects. Therefore, we speak not from theory, but from experience.
Regulation for regulation’s sake slows progress
Regulation makes sense only when it addresses an objective, measurable risk. Such areas exist, but there are few of them: AI in transport management, medical devices, critical infrastructure, and systems that can physically or legally harm a person — by making decisions about liberty, access to employment or credit.
These are only a few areas. Everything else — a model that writes code, analyses documents, generates text and images, or assists researchers — does not pose a risk requiring a separate licensing regime. Moreover, leading models are already released with built-in safety mechanisms, and developers compete on this parameter as well.
When a regulator wants to “restrict something” without yet understanding exactly what or what harm it is preventing, this is not protecting society. It is fear of what one does not understand, formalised in a regulatory act. The cost of such fear is lost companies, lost jobs and lost leadership.
What is actually in force in the EU today
For this discussion to be specific, let us establish what is actually in force as of September 2026.
AI Act (AI Act, Regulation (EU) 2024/1689). The world’s first comprehensive horizontal AI law, it entered into force on 1 August 2024 and applies in stages across four risk levels: the higher the potential harm, the stricter the requirements.
What already applies:
- Prohibited practices (Article 5) — since February 2025. Social scoring, manipulative systems and certain types of biometric identification. From 2 December 2026, these will be joined by a prohibition on systems for creating intimate images without consent and child sexual abuse material.
- Obligations of providers of general-purpose AI models (GPAI) — Articles 51–55 have applied since August 2025. These include documentation, copyright compliance and, for models with systemic risk, risk assessment and mitigation.
- Transparency obligations (Article 50) — since 2 August 2026. Informing users about interaction with AI, and labelling generated content and deepfakes. For systems already placed on the market, labelling of synthetic content is postponed until 2 December 2026.
What has been postponed — and this is telling. On 27 July 2026, the Digital Omnibus on AI (Regulation (EU) 2026/1744) entered into force, postponing the most burdensome obligations:
- for stand-alone high-risk systems (Annex III — HR, lending, education, law enforcement, etc.) — from 2 August 2026 to 2 December 2027;
- for AI embedded in products subject to sectoral regulation (Annex I — medical devices, machinery, transport) — from 2 August 2027 to 2 August 2028;
- national regulatory sandboxes must become operational by 2 August 2027.
The reason for the postponement cited by the European Commission itself was that neither businesses, standardisation bodies (CEN/CENELEC), nor the conformity assessment infrastructure were ready. In other words, the law was written before it was understood how to implement it. This is the best illustration of our position: regulation that precedes understanding does not work even for the regulator itself.
National level. By August 2025, Member States were required to designate supervisory authorities and establish sanctions. As of spring 2026, only a few countries had done so. In Estonia, a separate implementing law has not yet been adopted; work is being carried out by the Ministry of Justice and Digital Affairs, while the Data Protection Inspectorate (AKI) retains its reputation as a pragmatic and proportionate regulator.
Our position
-
We support AI projects. In Estonia, Europe and beyond. We believe that AI development is the development of humanity, and we want the companies creating it to operate here rather than leave for jurisdictions with clearer rules.
-
We support regulation of objective risks — and only those risks. Transport, medicine, critical infrastructure and decisions affecting human rights. Requirements are justified here, and we help clients comply with them.
-
We oppose draconian regulation. We oppose “just in case” bans, licensing regimes for activities that cause no harm, and rules written without understanding the technology.
-
If regulation exists, we will help you comply with it. System classification by risk level, provider and deployer obligations, documentation, transparency, interaction with supervisory authorities, preparation for the 2027–2028 deadlines and regulatory sandboxes. Our experience with cryptocurrency regulation has taught us the key lesson: compliance is not an obstacle to business, but a way to keep operating when rules change.
Regulation should protect people, not protect the regulator from the need to understand what is new. We will work on the side of those who build.