Writing for Guardian Europe on 1 September, Alexander Hurst made an argument that has been circling policy circles for two years and rarely gets stated this plainly: if anyone can slow the AI race, it is Europe, and the tool is ASML. His column puts the price of a single extreme ultraviolet lithography system at roughly $400m, and the global data centre build-out it feeds at around $7tn by 2030. Choke the machines, and the exponential stops. For UK organisations, the interesting question is not whether he is right about the physics. It is that the two institutions capable of acting on his argument are ones Britain sits outside, and both have just moved in directions his column does not account for.

Strategic Insight: The case for a European brake rests on two assumptions — that Brussels controls the chokepoint, and that Brussels is the regulator that follows through. Neither held in the summer of 2026. UK planning should be built on what those institutions actually did, not on what the argument requires them to do.

Who actually holds the lever?

Hurst treats ASML’s dominance as a card the EU can decide to play. The company’s position is real enough: no other firm builds the machines that pattern silicon at the leading edge, which makes it one of the few genuine constraints on how fast the industry can grow. But the authority to stop those machines leaving Europe does not sit in Brussels.

It sits in The Hague, under what the Dutch government calls its national export control measure for advanced semiconductor manufacturing equipment. That measure took effect on 1 September 2023, obliging ASML to seek Dutch licences for its most advanced immersion systems; ASML noted at the time that sales of its EUV systems were already restricted. Two more tools were added on 7 September 2024, moving their licensing from Washington to The Hague, and a further tranche including specific measuring and inspection equipment followed on 1 April 2025. Authorisations are decided case by case, apply to exports leaving the Netherlands for any destination outside the EU, and — in the government’s own words — do “not constitute an export ban”.

That is not a technicality. It changes the actor from a 27-member bloc with a legislative machine to a single national licensing desk operating under sustained American pressure — the same pressure that has already produced restrictions the Dutch government did not originate. Hurst’s claim that “the EU holds such a card” describes where the machines are built, not who signs the paperwork.

Critical Context: A European decision to close this chokepoint would require the Netherlands to move from case-by-case authorisation to the outright ban it has so far declined to impose, against its most strategically important exporter, in the face of US retaliation Hurst himself concedes is the likely response. The obstacle is not political will in Brussels. It is that Brussels is not the venue.

What the argument assumesWhat is actually the caseWhy it matters to UK organisations
The EU can restrict ASML exportsLicensing is a Dutch national measure, decided case by case, and explicitly not a banCompute supply risk tracks one government’s licensing posture, not EU politics
The EU is the regulator that follows throughCore high-risk obligations were deferred by Regulation (EU) 2026/1744 in July 2026The EU compliance calendar has already moved once and can move again
Slowing AI buys everyone time to catch upThe UK’s declared direction is sandboxes and a growth duty, not a pauseA European brake widens UK–EU divergence rather than creating breathing space
Britain sits outside the decisionTrue — but not outside its effectsReach without representation is the UK’s actual position

Brussels applied its own brake to its own rules

The column describes the EU as “the only player that has shown it will regulate AI extensively”. That was a defensible reading a year ago. It is harder to sustain now.

The Digital Omnibus on AI was adopted at Strasbourg on 8 July 2026, appeared in the Official Journal on the 24th of that month, and took effect on the third day after that — deliberately fast-tracked so the changes landed before the AI Act’s own enforcement date of 2 August 2026 arrived. Most of the duties on high-risk systems now bite on 2 December 2027 for the standalone category listed under Annex III, and on 2 August 2028 for systems embedded as safety components under Annex I. The regulation’s own recitals give the reason plainly: the standards providers need were late, national governance and conformity assessment structures were slow to appear, and the resulting compliance burden turned out heavier than anyone had planned for.

Read against Hurst’s argument, the timing is awkward. The case for handing Europe the brake pedal is that Europe will use it. Five weeks before the column ran, the EU eased its own by sixteen months and more.

Reality Check: Deferral is not repeal, and not everything moved. Transparency duties under Article 50 are live from 2 August 2026, and generative systems already on sale before that date must meet the watermarking requirement by 2 December 2026. Teams that read “delay” as “stand down” have mis-scoped what changed.

The things a UK team should take from this

  • The EU’s willingness to regulate is real but conditional. It is bounded by industrial competitiveness pressure, and that pressure is rising, not falling.
  • Deadlines are now a live variable. Any UK programme that hard-codes an EU compliance date should hold it as an assumption to be re-checked, not a fixed constraint.
  • Deferral shifts cost, it does not remove it. The work required to comply with the high-risk regime did not shrink; the runway lengthened.
  • The transparency layer is where the near-term exposure sits. Labelling and watermarking obligations are live now, and they land on customer-facing systems most UK firms already run.

Reach without representation: the UK’s real position

The adjacent question — where the UK stands between Washington and Beijing — has been well covered. The Europe-as-brake argument raises a different one, and a sharper one. Britain is not merely absent from the room. It is bound by what happens in it.

Article 2 of the AI Act attaches to providers who place AI systems or general-purpose models on the Union market “irrespective of whether those providers are established or located within the Union or in a third country”, and to third-country providers and deployers “where the output produced by the AI system is used in the Union”. A London software firm selling into Frankfurt is inside the regime. So is one whose model output reaches EU users through a partner. Brexit removed the vote, not the reach.

That produces an asymmetry worth naming precisely. When Brussels tightens, UK firms serving EU customers absorb the tightening. When Brussels defers — as it did in July — UK firms absorb the deferral, including the planning disruption of a compliance programme whose deadline just moved by sixteen months. Britain experiences the full volatility of EU rule-making and contributes nothing to its timing.

Meanwhile the domestic direction runs the other way. The King’s Speech 2026 contained no standalone AI bill; the 2024 commitment to legislate on the most powerful model developers has been shelved. What was announced instead is a Regulating for Growth Bill, expected to create cross-economy sandbox powers to temporarily switch off or modify specific rules, alongside a strengthened growth duty and a new ministerial power to direct regulators through strategic steers. AI regulation in the UK is arriving incrementally through existing statutes — the Crime and Policing Act 2026, for instance, extends the reach of the Online Safety Act 2023 further into AI chatbots.

Strategic Reality: If Europe ever does apply a brake, Britain’s declared strategy is to be the jurisdiction where that brake bites least. That is a coherent bet. It is also a bet that only pays if EU-facing revenue is small, and Article 2 means most UK firms of any scale cannot make that claim honestly.

Stakeholder groupPrimary impactWhat they needHow to measure it
Legal and complianceTwo rulebooks on different clocks, one of which just movedA revenue map by jurisdiction of output use, not entity domicilePercentage of AI systems with a confirmed in-scope determination
Infrastructure and procurementCompute pricing exposed to a licensing decision made in The HagueContract terms that survive a supply shock; more than one supply pathShare of AI spend locked into single-source multi-year terms
Product and engineeringTransparency and labelling duties live now, high-risk work deferredA clear split between what is due in 2026 and what is due in 2027–28Coverage of watermarking and disclosure across shipped features
Board and strategyA divergence bet being made on their behalf by defaultAn explicit position on whether the firm follows UK or EU standardsDocumented rationale, reviewed each time either regime moves

What UK organisations should actually plan around

The practical translation of all this is that UK organisations should stop planning against one regulatory clock and start planning against two, neither of which they set.

💡 Implementation Framework: Two-clock planning

Phase 1: Establish scope (2–4 weeks)

  • Map every AI system by where its output is used, not where the company is registered
  • Flag which systems would fall into the EU high-risk categories if assessed today
  • Separate obligations already live in 2026 from those deferred to 2027–28

Phase 2: Decouple the clocks (one quarter)

  • Build the EU compliance workstream against 2 December 2027, with a documented assumption that the date may move again
  • Run the UK workstream against sector regulator expectations and existing statutes, not against a future AI bill
  • Review compute and model contracts for what happens if supply tightens or pricing shifts mid-term

Phase 3: Hold a position (ongoing)

  • Decide explicitly whether the organisation builds to the stricter standard everywhere or maintains two configurations
  • Re-examine that decision whenever either regime changes, rather than on an annual cycle
  • Keep a named owner for each clock, so a movement in Brussels or Whitehall reaches the right desk quickly

Priority actions by starting position

For organisations at the beginning:

  1. Determine EU scope honestly. The test is where output is used, and most firms discover more in-scope systems than they expected.
  2. Inventory what is already live. Transparency and labelling duties apply now; that is the near-term exposure, not the high-risk regime.
  3. Name an owner. A regulatory change with no named recipient becomes a discovery during an audit.

For organisations already underway:

  1. Rebaseline against the new dates. A programme built to 2 August 2026 is now running against a different deadline and probably a different resourcing profile.
  2. Do not release the deferred work. Sixteen extra months is a scheduling change, not a reduction in scope, and the standards it waits on are still being written.
  3. Stress-test compute assumptions. Model what a tightening in export licensing would do to your pricing and lead times over eighteen months.

For organisations with mature programmes:

  1. Formalise the divergence position. Build once to the stricter standard, or maintain two builds deliberately — the expensive outcome is doing it accidentally.
  2. Engage the UK sandbox route with open eyes. Temporary relief obtained through a sandbox is not a durable regulatory position, and may be made permanent by secondary legislation with limited parliamentary scrutiny.
  3. Track the Dutch licensing posture as a supply signal. It is a better predictor of compute availability than any statement out of Brussels.

Resource Reality: Two-clock planning is roughly two to three weeks of concentrated legal and technical work to establish, then a standing review each quarter. That is manageable for a mid-sized organisation. What is not manageable is discovering the scoping question during a customer’s due diligence process.

The challenges that will not appear on a roadmap

The chokepoint has a national owner, not a European one

Scenario planning that models “Europe restricting ASML” is modelling the wrong actor. The decision belongs to a Dutch licensing authority operating case by case, under American pressure, in respect of the country’s most valuable company. That is a much narrower and less predictable decision surface than EU policy.

Mitigation: Track Dutch export licensing decisions and ASML’s own disclosures as the leading indicator. Treat EU-level rhetoric about strategic autonomy as commentary, not as a signal about supply.

The divergence bet is only ever partial

A UK firm can operate under lighter domestic rules and still be fully inside the EU regime for the portion of its business whose output reaches EU users. The lighter-touch advantage applies to a subset of activity, and firms routinely overestimate how large that subset is.

Mitigation: Quantify the split. Express in-scope revenue as a percentage before making any strategic claim about the benefit of UK divergence, and revisit it whenever the customer base shifts.

Deferral produces whiplash, not relief

Programmes stood down after July 2026 will need to restart in 2027 with dispersed staff, stale documentation, and standards that changed while the work was paused. The restart is usually more expensive than continuous slow progress would have been.

Mitigation: Reduce the pace rather than stopping. Keep documentation current and the assessment work warm, so the 2027 ramp is a resumption rather than a rebuild.

A lighter regime is also a less stable one

The UK’s sandbox approach means specific rules may be switched off temporarily and, if a pilot succeeds, disapplied permanently through secondary legislation. For a business trying to plan, a rulebook that can change quickly in either direction is not obviously easier to operate under than a slow, prescriptive one.

Mitigation: Build to the stable floor — data protection obligations and sector regulator expectations that are unlikely to move — and treat sandbox relief as an opportunity to exploit rather than a foundation to build on.

⚠️ Warning: The most expensive position is an implicit one. Firms that have never decided whether they follow UK or EU standards usually end up meeting neither properly, and finding out during a customer security review.

The takeaway for UK business

Hurst’s column is a serious argument and worth reading in full. The instinct behind it — that the race is dangerous, that industry self-restraint has failed, and that a brake must be external — is now shared across a strikingly wide range of people, spanning Bernie Sanders and Bill Gates. Where it does not survive contact with the UK’s position is in the mechanics. The chokepoint is Dutch, not European. The regulator held up as the one that follows through has just given itself sixteen more months. And Britain, which appears nowhere in the argument, is bound by the output of both processes while participating in neither.

Three things follow for anyone running AI systems in a UK organisation:

  1. Plan against decisions, not intentions. What the EU deferred in July matters more to your 2027 budget than what any column argues Europe ought to do.
  2. Scope by output, not by domicile. The AI Act reaches UK providers whose systems touch the Union market, and that is the single most under-assessed exposure in UK AI programmes.
  3. Treat compute supply as a policy variable. Its availability and price depend on export licensing decisions made in a capital where Britain has no standing.

Strategic Insight: The useful reframe is that Britain’s AI risk is now largely exogenous. Compliance timing is set in Brussels, compute supply is gated in The Hague, and the frontier is built in California and Shenzhen. The only variable genuinely under UK control is how well organisations prepare for decisions taken elsewhere — which makes preparation, not positioning, the thing worth investing in.

Immediate actions (this week):

  • List every AI system and record where its output is consumed
  • Confirm which transparency and labelling duties are live for you now
  • Identify who owns the EU clock and who owns the UK clock

Strategic priorities (this quarter):

  • Rebaseline any AI Act workstream against the revised 2027–28 dates
  • Quantify EU-facing revenue as a share of total AI-supported revenue
  • Review compute and model contracts for supply-shock and repricing terms

Longer-term considerations (this year):

  • Decide and document a single divergence position at board level
  • Establish a standing review triggered by regulatory movement, not by the calendar
  • Build an internal control baseline that holds regardless of which way either regime moves

Source: From Bill Gates to Bernie Sanders, most agree the AI arms race is disastrous. Only Europe can make it stop by Alexander Hurst (The Guardian, 2026). Regulatory dates verified against the Official Journal text of Regulation (EU) 2026/1744 and Article 2 of the AI Act.

This strategic analysis was written by Resultsense, a UK-focused AI news and analysis publication. We will be watching whether the Regulating for Growth Bill reaches Parliament on schedule, and whether the EU’s deferred high-risk deadlines hold at 2027. Read more analysis at Insights, or get in touch.