Regulation vs Innovation: Is the EU AI Framework Constraining AI Development in Central and Eastern Europe?
How the EU AI Act may shape innovation capacity, compliance costs, and technological competitiveness in Central and Eastern Europe

This policy insight examines how the EU Artificial Intelligence Act affects innovation in Central and Eastern Europe. It explores regulatory readiness gaps, compliance burdens for SMEs, and the risk of innovation concentration in more mature markets, while highlighting policy solutions such as regulatory sandboxes, SME support, and AI literacy investment.
Authors
Topics
Article Content
Regulation vs Innovation: Is the EU AI Framework Constraining AI Development in Central and Eastern Europe?
Introduction
Central and Eastern Europe is entering the current phase of artificial intelligence development under conditions that differ materially from those of more established European innovation ecosystems.
Across the region, firms are increasingly integrating AI tools into their operations, experimenting with use cases in areas such as customer service, risk assessment and process automation. At the same time, they are operating within a regulatory environment that has rapidly expanded in scope and complexity. The EU’s Artificial Intelligence Act (Regulation (EU) 2024/1689), which entered into force on 1 August 2024 with obligations phased through to 2027, introduces a comprehensive, risk-based framework that applies uniformly across all Member States.
This convergence of growing adoption and tightening regulatory requirements is taking place against a backdrop of uneven institutional capacity, investment levels and technical expertise across the Union. As a result, the issue is no longer whether regulation will influence the development of AI in Central and Eastern Europe, but how its implementation interacts with these structural differences, and whether it enables convergence with more mature markets or contributes to their persistence.
A global race that Europe cannot ignore
Artificial intelligence is developing within a competitive global landscape shaped by fundamentally different approaches.
The United States continues to rely on a market-driven model, where private-sector innovation, access to capital and speed of execution define technological progress. China, by contrast, treats AI as a strategic priority, combining state coordination with long-term investment and industrial policy.
The European Union has chosen a third path. Its model places trust, accountability and risk management at the centre of AI development.
The risk for Central and Eastern Europe is that regulation does not simply guide innovation, but determines where it takes place.
A regulatory model built for maturity, applied to uneven ground
The EU’s regulatory architecture for artificial intelligence is ambitious and internally coherent. The AI Act, together with GDPR, the Data Act, the Digital Services Act (DSA) and the Digital Markets Act (DMA), creates a layered system governing not only AI systems, but also the data they rely on and the platforms through which they operate.
The framework rests on an implicit assumption: that firms, regulators and institutions across the Union are broadly comparable in terms of capacity, expertise and readiness.
Central and Eastern Europe is not a homogeneous region, but many countries share structural characteristics that distinguish them from more mature ecosystems. These include lower levels of investment, less developed innovation infrastructure and, in some cases, limited administrative capacity to implement complex regulatory frameworks.
In this context, the application of a uniform regulatory model produces asymmetric effects. Firms in the region are required to meet the same standards as those operating in more advanced markets, but without the same resources or institutional support.
Consider a high-risk AI system for credit scoring. A bank in Germany has in-house legal teams, compliance officers and established relationships with regulators. A similar bank in Bulgaria faces the same documentation requirements, the same conformity assessments and the same potential fines — but with a compliance team of two people and limited experience with AI-specific conformity assessment procedures.
This does not make compliance impossible. But it changes its cost, its complexity and, ultimately, its strategic impact.
The readiness gap
Recent data illustrates the imbalance. Around 59% of individuals in Central and Eastern Europe report using AI regularly, compared to 66% globally (IPSOS, AI Monitor 2024). However, Eurostat data from January 2025 paints a starker picture at the enterprise level: AI adoption among firms stands at just 3.1% in Romania, 5.9% in Poland and 6.5% in Bulgaria, compared to an EU average of 13.5%.
The more critical gap lies in understanding and governance. Approximately 89% of respondents report that they are not familiar with existing AI-related regulations (IPSOS, AI Monitor 2024).
This combination creates a pattern of usage without understanding. AI is already embedded in daily workflows, but the structures required to ensure responsible and compliant use are not keeping pace.
In practice, this means that many organisations are exposed not only to regulatory risk, but also to operational and reputational vulnerabilities.
The disproportionate weight of compliance
The AI Act introduces a risk-based model that is, in principle, proportionate. Systems are classified according to their potential impact, with stricter requirements applied to higher-risk applications.
In practice, however, the burden of compliance is not evenly distributed.
Large technology companies have the legal, technical and financial capacity to absorb regulatory requirements. For them, compliance is an extension of existing structures.
For small and medium-sized enterprises, which form the backbone of most CEE economies, the situation is different. Compliance is not only a question of cost, but of uncertainty.
“We are not particularly concerned about fines,” notes the founder of a fintech startup in Sofia. “The real issue is the uncertainty — whether our system qualifies as ‘high-risk’ and what exactly we are expected to demonstrate.”
This uncertainty influences whether firms choose to develop certain products, how quickly they bring them to market and how much risk they are willing to take.
Regulation, trust and the gap in understanding
Across Central and Eastern Europe, international regulatory frameworks are often seen as the most reliable mechanism for governing AI. At the same time, trust in national institutions tends to be more limited.
This creates a gap between regulatory intent and practical application. Compliance risks becoming formal rather than substantive — present in documentation, but not fully embedded in everyday decision-making.
Constraining or enabling: a question of alignment
The European approach offers clear long-term advantages. It builds trust, reduces systemic risks and creates a predictable framework for AI development.
At the same time, in the short to medium term, it can act as a constraint in regions where the underlying conditions for innovation are still developing.
In Central and Eastern Europe, the issue is not regulation itself, but the alignment between regulatory expectations and market readiness. When the two move at different speeds, the result is regulatory misalignment.
Towards a more adaptive approach
The challenge is not to weaken the regulatory framework, but to adapt its implementation.
Regulatory sandboxes, already mandated under Article 57 of the AI Act — which requires each Member State to establish at least one by August 2026 — can provide controlled environments for experimentation and reduce uncertainty for firms operating at an early stage.
Targeted support for SMEs is equally important. The AI Act itself acknowledges this through Article 62, which provides for reduced conformity assessment fees, priority sandbox access, simplified documentation templates and tailored training for smaller operators.
At a more fundamental level, investment in AI literacy and workforce development remains essential.
Conclusion
The European Union’s approach to artificial intelligence reflects a deliberate effort to shape technological development through a structured, risk-based regulatory framework.
In Central and Eastern Europe, the challenge is therefore not the presence of regulation as such, but the conditions under which it is implemented.
Ultimately, the question is not whether the EU’s regulatory framework will shape AI development in Central and Eastern Europe, but how. Its impact will depend on whether it is accompanied by the necessary capacity-building measures to ensure that compliance does not become a structural barrier to participation in the emerging AI economy.
Article Content
Regulation vs Innovation: Is the EU AI Framework Constraining AI Development in Central and Eastern Europe?
Introduction
Central and Eastern Europe is entering the current phase of artificial intelligence development under conditions that differ materially from those of more established European innovation ecosystems.
Across the region, firms are increasingly integrating AI tools into their operations, experimenting with use cases in areas such as customer service, risk assessment and process automation. At the same time, they are operating within a regulatory environment that has rapidly expanded in scope and complexity. The EU’s Artificial Intelligence Act (Regulation (EU) 2024/1689), which entered into force on 1 August 2024 with obligations phased through to 2027, introduces a comprehensive, risk-based framework that applies uniformly across all Member States.
This convergence of growing adoption and tightening regulatory requirements is taking place against a backdrop of uneven institutional capacity, investment levels and technical expertise across the Union. As a result, the issue is no longer whether regulation will influence the development of AI in Central and Eastern Europe, but how its implementation interacts with these structural differences, and whether it enables convergence with more mature markets or contributes to their persistence.
A global race that Europe cannot ignore
Artificial intelligence is developing within a competitive global landscape shaped by fundamentally different approaches.
The United States continues to rely on a market-driven model, where private-sector innovation, access to capital and speed of execution define technological progress. China, by contrast, treats AI as a strategic priority, combining state coordination with long-term investment and industrial policy.
The European Union has chosen a third path. Its model places trust, accountability and risk management at the centre of AI development.
The risk for Central and Eastern Europe is that regulation does not simply guide innovation, but determines where it takes place.
A regulatory model built for maturity, applied to uneven ground
The EU’s regulatory architecture for artificial intelligence is ambitious and internally coherent. The AI Act, together with GDPR, the Data Act, the Digital Services Act (DSA) and the Digital Markets Act (DMA), creates a layered system governing not only AI systems, but also the data they rely on and the platforms through which they operate.
The framework rests on an implicit assumption: that firms, regulators and institutions across the Union are broadly comparable in terms of capacity, expertise and readiness.
Central and Eastern Europe is not a homogeneous region, but many countries share structural characteristics that distinguish them from more mature ecosystems. These include lower levels of investment, less developed innovation infrastructure and, in some cases, limited administrative capacity to implement complex regulatory frameworks.
In this context, the application of a uniform regulatory model produces asymmetric effects. Firms in the region are required to meet the same standards as those operating in more advanced markets, but without the same resources or institutional support.
Consider a high-risk AI system for credit scoring. A bank in Germany has in-house legal teams, compliance officers and established relationships with regulators. A similar bank in Bulgaria faces the same documentation requirements, the same conformity assessments and the same potential fines — but with a compliance team of two people and limited experience with AI-specific conformity assessment procedures.
This does not make compliance impossible. But it changes its cost, its complexity and, ultimately, its strategic impact.
The readiness gap
Recent data illustrates the imbalance. Around 59% of individuals in Central and Eastern Europe report using AI regularly, compared to 66% globally (IPSOS, AI Monitor 2024). However, Eurostat data from January 2025 paints a starker picture at the enterprise level: AI adoption among firms stands at just 3.1% in Romania, 5.9% in Poland and 6.5% in Bulgaria, compared to an EU average of 13.5%.
The more critical gap lies in understanding and governance. Approximately 89% of respondents report that they are not familiar with existing AI-related regulations (IPSOS, AI Monitor 2024).
This combination creates a pattern of usage without understanding. AI is already embedded in daily workflows, but the structures required to ensure responsible and compliant use are not keeping pace.
In practice, this means that many organisations are exposed not only to regulatory risk, but also to operational and reputational vulnerabilities.
The disproportionate weight of compliance
The AI Act introduces a risk-based model that is, in principle, proportionate. Systems are classified according to their potential impact, with stricter requirements applied to higher-risk applications.
In practice, however, the burden of compliance is not evenly distributed.
Large technology companies have the legal, technical and financial capacity to absorb regulatory requirements. For them, compliance is an extension of existing structures.
For small and medium-sized enterprises, which form the backbone of most CEE economies, the situation is different. Compliance is not only a question of cost, but of uncertainty.
“We are not particularly concerned about fines,” notes the founder of a fintech startup in Sofia. “The real issue is the uncertainty — whether our system qualifies as ‘high-risk’ and what exactly we are expected to demonstrate.”
This uncertainty influences whether firms choose to develop certain products, how quickly they bring them to market and how much risk they are willing to take.
Regulation, trust and the gap in understanding
Across Central and Eastern Europe, international regulatory frameworks are often seen as the most reliable mechanism for governing AI. At the same time, trust in national institutions tends to be more limited.
This creates a gap between regulatory intent and practical application. Compliance risks becoming formal rather than substantive — present in documentation, but not fully embedded in everyday decision-making.
Constraining or enabling: a question of alignment
The European approach offers clear long-term advantages. It builds trust, reduces systemic risks and creates a predictable framework for AI development.
At the same time, in the short to medium term, it can act as a constraint in regions where the underlying conditions for innovation are still developing.
In Central and Eastern Europe, the issue is not regulation itself, but the alignment between regulatory expectations and market readiness. When the two move at different speeds, the result is regulatory misalignment.
Towards a more adaptive approach
The challenge is not to weaken the regulatory framework, but to adapt its implementation.
Regulatory sandboxes, already mandated under Article 57 of the AI Act — which requires each Member State to establish at least one by August 2026 — can provide controlled environments for experimentation and reduce uncertainty for firms operating at an early stage.
Targeted support for SMEs is equally important. The AI Act itself acknowledges this through Article 62, which provides for reduced conformity assessment fees, priority sandbox access, simplified documentation templates and tailored training for smaller operators.
At a more fundamental level, investment in AI literacy and workforce development remains essential.
Conclusion
The European Union’s approach to artificial intelligence reflects a deliberate effort to shape technological development through a structured, risk-based regulatory framework.
In Central and Eastern Europe, the challenge is therefore not the presence of regulation as such, but the conditions under which it is implemented.
Ultimately, the question is not whether the EU’s regulatory framework will shape AI development in Central and Eastern Europe, but how. Its impact will depend on whether it is accompanied by the necessary capacity-building measures to ensure that compliance does not become a structural barrier to participation in the emerging AI economy.
