← All posts The AI Act Is Not the Brake. It Is the Playing Field.

Meinung

The AI Act Is Not the Brake. It Is the Playing Field.

2026-03-24Sascha Kirchhofer
<h2>The Wrong Debate</h2>
<p>In the current AI debate I keep encountering the same underlying attitude in two variants: Either the AI Act is unnecessary because existing laws suffice. Or it is a brake on innovation. <b>Both miss the point in my view.</b> Because the real question is not whether regulation exists, but whether it can be technically implemented.</p>
<p>Product liability, GDPR, industry regulations: all of these govern outcomes and responsibilities between humans and organizations. But <b>none of them address the specific challenges of autonomous agent systems</b>. Systems that act independently, communicate across organizational boundaries, make their own decisions. Which existing law governs the identity, accountability and auditability of an agent that independently initiates a contract? <b>None of them were written for that.</b></p>
<p>Those claiming the AI Act stifles innovation confuse <b>clarity with restriction</b>.</p>
<h2>What happens when regulation is missing: the crypto lesson</h2>
<p>We have seen this experiment before. In the crypto space there was no regulation for years. No clarity, no MiCA, no framework. The result was not flourishing innovation. <b>The result was paralysis.</b> Investors held back. Companies that wanted to operate cleanly got sued. Banks refused business accounts.</p>
<p>The market did not stagnate despite missing regulation. It stagnated <b>because of</b> missing regulation.</p>
<p>Capital only started flowing when clear rules arrived. Institutional investors did not need freedom from rules. They needed rules they could align their decisions against. The parallel to AI is obvious: companies will only seriously invest in autonomous agents once they know under which conditions it is legally secure.</p>
<h2>The gap nobody sees</h2>
<p>The real challenge is not in the legal text. It is in the <b>implementation</b>. Even the best regulatory framework changes nothing if the technical infrastructure to operationally enforce it is missing.</p>
<p><b>You cannot implement compliance via PDF.</b></p>
<p>The AI Act is <b>necessary but not sufficient</b>. It creates the regulatory framework and defines risk classes, transparency obligations, conformity assessments. But the agent specific gap in identity, accountability and operational enforceability remains open.</p>
<p>Operational legal certainty for autonomous systems requires three things:</p>
<p><strong>Identity.</strong> Who is acting? Which agent, which provider, which organization stands behind it?</p>
<p><strong>Accountability.</strong> Who owns this agent? Who bears responsibility for its actions?</p>
<p><strong>Auditability.</strong> What was done? Can the chain of actions be traced and verified?</p>
<p>Without these three pillars the AI Act remains paper without operational effect. With them it becomes the foundation for trustworthy autonomous systems.</p>
<h2>The security authority’s position</h2>
<p>This is not a theoretical consideration. On March 23, 2026, Germany’s <b>Federal Office for Information Security (BSI)</b> stated in its written submission to the public hearing of the Bundestag’s Committee on Digital Affairs: Cybersecurity is the foundation for trustworthy Artificial Intelligence. The BSI explicitly welcomes the AI Act.</p>
<p>This is not the opinion of a startup. It is the position of Germany’s national security authority. And it matches what we experience in practice every single day: <b>Without reliable security infrastructure there is no trust.</b> Without trust no adoption. Without adoption no market.</p>
<h2>Our path</h2>
<p>At EFINITI we have been building autonomous agent systems for twelve months. Not as an experiment and not as a research project but as a <b>productive workforce</b>. Our agents write code, coordinate projects, communicate with each other and with humans. PANDORA is not a demo. It is our daily work.</p>
<p>Along the way we learned something that is completely absent from the current debate: <b>Orchestration is the easy problem. Identity is the hard one.</b></p>
<p>Getting an agent to complete tasks is solvable. But knowing <em>who</em> that agent is, <em>who</em> owns it and <em>what</em> it has done: that requires infrastructure that simply did not exist before.</p>
<p>That is why we developed the <b>Elpis Protocol</b>. Cryptographic identity for autonomous agents, anchored on a distributed ledger, independent of the LLM provider. Plus <b>ARGUS</b> as the compliance and enforcement layer that operationally implements identity, auditability and risk assessment.</p>
<p>Not despite the AI Act. <b>But because it exists.</b> And because it alone is not enough.</p>
<h2>Advantage through compliance by design</h2>
<p>The AI Act is not an obstacle. It is the prerequisite for companies to invest. Those who build compliance by design into their architecture do not have a disadvantage. They have a head start.</p>
<p>The debate about whether the AI Act is good or bad leads nowhere. The relevant question is:</p>
<p><b>Who builds the infrastructure that makes it implementable? And who closes the gap it leaves open?</b></p>
<p>We have started.</p>
<hr>
<p><small>Further reading: <a href="https://elpis.efiniti.ai">Elpis Protocol</a> | <a href="https://efiniti.de">EFINITI Services GmbH</a></small></p>
<p><small>This article was written by Sascha Kirchhofer, founder and CEO of EFINITI Services GmbH and co-author of the Elpis Protocol. Verifiable digital identity: <code>did:xrpl:7nnmlzx6#owner</code>.</small></p>
AI ActRegulierungElpis ProtocolARGUSComplianceEUMeinung