In 2026, it’s now clear that AI is becoming a core operational backbone of global enterprises and governments. Leaders across every sector imaginable are coming to grips with how they rapidly scale these systems without, at the same time, compromising safety and control.

A concerted effort by regulatory bodies worldwide to match this technological shift has forced both business leaders and public officials to fundamentally rethink their long-term approach to AI deployment with respect to risk mitigation. Despite what you might read in the press, the days of unbridled AI innovation in favour of rapid experimentation, it seems, are drawing to a close. 

The clearest signal of this shift is the EU AI Act, the world’s first comprehensive legal framework for artificial intelligence, which is now being rolled out in phases. As its formal requirements for transparency and risk classification slowly take effect, its primary mandate is clear: to restore trust and accountability to the full range of outputs and use cases of AI systems. 

Its introduction to the foundations of the European AI sector has prompted lingering criticism from the tech community, mostly characterised by widespread concerns over global competitiveness and operational inefficiencies from compliance burdens. 

It’s an important milestone and one to take note of; there’s no doubt about that. But I don’t believe regulation is the biggest barrier to AI adoption. 

Most organisations already know where AI can create value. The real challenge is deploying it in a way that is trusted, governed, and fit for real operational environments. This is the most common pitfall I’ve observed among AI companies. 

Some real weaknesses will get exposed

The capability to achieve something with AI means very little if the technology isn’t trusted enough to be applied in this way. That’s the simple fact that many overlook. 

We hear it all the time. AI is a technology with the potential to deliver enormous benefits across society, from improving public services to strengthening national security. It may be true, but to achieve this, the decision-makers in those sectors must be confident that AI is being developed and deployed responsibly. 

We can’t pretend there aren’t plenty of explanations for why the public lacks this confidence, whether that’s fears that it's all hype and won’t actually work in the real world, or fears that it will work too well and have unintended consequences for jobs and economic stability. Neither extreme position reflects the practical reality of this sector, but the sentiment is very real, and it’s the responsibility of AI innovators to build that trust. 

If, instead, AI leaders become hellbent on their speed to market or organisational deployment, they risk bypassing the structural foundation that keeps software systems secure and reliable. This will only continue to fuel the negative headlines that outweigh the positive impact AI can have. 

Earning institutional and public confidence demands moving away from opaque algorithms and towards bulletproof, resilient architectures. If regulators or end-users cannot trace how AI systems reached a specific conclusion, friction and scepticism are the natural results. 

Companies that rely on these opaque AI systems may indeed find regulation uncomfortable, but those building trusted, governed AI should not. 

How about an opportunity? 

Regulation inevitably introduces constraints, and for organisations focused on moving fast, that can feel like a barrier. But the alternative is a far greater risk. 

If AI is deployed without appropriate oversight, governance and accountability, and if anything catastrophic happened, the resulting loss of public confidence would create such an enormous backlash that any ‘innovation’ would be halted out of sheer public terror. This is a far greater risk to progress than sensible regulation could ever be.

Clearly defined parameters give technical teams the clarity and confidence to innovate within safe and reliable boundaries. Organisations proactively embed security controls into their software architecture to protect themselves against regulatory penalties - which we’ll soon see with the rollout of the EU AI Act. 

In defence, government and other highly regulated sectors, success is determined by resilience, safety, and human oversight, not by access to the latest AI model. 

It is this insider view that has ultimately reinforced the core principle for me that powerful AI is useless unless operators can trust it. But the competitive advantage of trust goes far beyond this industry: when operational teams possess absolute confidence in their intelligence tools, they are empowered to make faster, better-informed decisions in complex, high-stakes situations, whatever they might be. 

Lighter regulation doesn’t automatically equal maximum opportunity with AI; it can often spell the opposite. The companies continuing to operate successfully under this new regulatory framework will be those that see this as an opportunity to strengthen the foundations of AI development for better long-term commercial outcomes. Not as obstacles to innovation. 

This isn’t just an argument for a change of perspective. I truly believe the EU AI Act will not be a handicap for the technology sector, but a filter for greater success rates. As international standards mature and public scrutiny intensifies, the market will favour those who prioritise transparency and safety controls from day one. The end result is a more resilient and collaborative AI sector. 

Paul Jenkinson is CEO and Founder of Whitespace

Reply

Avatar

or to participate