Oates' decentralization theorem and the AI Act's Achilles heel
The AI Act centralizes the rule but decentralizes its enforcement across 27 national administrations moving at very different speeds — Ireland still hadn't passed its enforcement law a month after Article 50 took effect. Wallace Oates' decentralization theorem (1972) explains why this architectural choice creates a structural risk for companies operating across multiple member states.
On August 2, 2026, the AI Act's Article 50 transparency obligations took effect across the entire European Union — except for the watermarking provision, postponed to December 2, 2026. On paper, that's a single date, a single text, a uniform obligation for any company deploying a generative AI system or interacting with users in the EU. In practice, at the very moment that obligation took effect, Ireland — one of Europe's densest tech-company hubs — still hadn't finished adopting its own enforcement law: the Regulation of Artificial Intelligence Bill 2026 had only reached Committee Stage in the Seanad, with the prior stage (Second Stage) completed on July 1, 2026 — a month before the EU text it's meant to enforce took effect.
This gap isn't an isolated administrative accident; it's the predictable consequence of a choice built into the AI Act's own architecture. And that choice can be read precisely through a theoretical framework more than fifty years old: Wallace Oates' decentralization theorem, published in Fiscal Federalism (1972). Oates establishes a simple but powerful result in public economics: for a given public good or regulation, the optimal level of government to produce or enforce it depends on a trade-off between two forces. On one side, economies of scale and cross-border externalities argue for centralization — a central actor avoids duplicating fixed costs and internalizes effects that spill beyond local borders. On the other, heterogeneity in local preferences and information argues for decentralization — a better-informed local government can fine-tune a policy to its territory's needs.
Applied to the AI Act, the diagnosis is clear-cut. The substance of the rule — what counts as a high-risk system, which transparency obligations apply, which thresholds trigger which requirements — typically falls into the case where centralization dominates: a digital single market where a non-compliant AI system deployed from one member state can affect users in the other 26, where duplicating 27 different national regulatory frameworks would multiply compliance costs for any pan-European company, and where the coherence of the rule itself constitutes a European public good. Brussels, correctly by Oates' framework, chose to centralize the rule rather than leave it to 27 diverging national laws.
But the AI Act didn't apply the same logic to enforcing the rule. Article 70 delegates the designation of market surveillance authorities and operational enforcement (inspections, investigations, sanctions) to each member state, with its own budget constraints, its own parliamentary calendar, and its own current political priorities. Nothing in Oates' logic justifies decentralizing enforcement this way: the cross-border externalities that justified centralizing the rule — a non-compliant system potentially affects the whole single market — apply just as much, if not more, to its actual enforcement. A member state that lags in building its oversight capacity doesn't just export a local risk: it effectively creates an entry point into the single market where the European rule remains, temporarily, a shell with no immediate enforcement lever.
This pattern isn't new. GDPR saw a close version of the same problem with its one-stop-shop mechanism: a data-protection rule harmonized at the EU level, but an investigation and sanctioning capacity that depends heavily on the staffing and budget of the data protection authority in the country where a company has its main establishment — which, from GDPR's early years, fed criticism that major tech platforms were strategically choosing their place of establishment precisely to land under a less-resourced regulator. The AI Act, built on a comparable enforcement architecture, exposes companies in the sectors Cardan-AI tracks to a structurally similar risk.
For aerospace and defense, where AI systems embedded in safety-regulated products (aviation, in particular) shift into high-risk obligations on August 2, 2028, the current enforcement gap is an early warning signal: a supplier that documents compliance to the least-advanced regulator's standard is betting the gap will persist — a risky bet given how fast the sector's regulatory environment is moving. For energy and O&G, where AI systems controlling critical infrastructure may already fall within the high-risk perimeter, the absence of a fully operational authority in some member states doesn't remove the underlying legal obligation — it only delays its enforcement, with a risk of retroactive catch-up. For luxury, where Article 50 directly touches content-generation and marketing use cases, the enforcement gap creates a temptation toward minimal compliance in the least-advanced jurisdictions — a temptation worth resisting, since the case law that will ultimately set the real standard is far more likely to be built from the most active member states than the slowest ones.
The practical conclusion mirrors the theoretical framework: in an architecture where the rule is centralized but its enforcement decentralized and asynchronous, regulatory risk shouldn't be measured against the rigor of the local authority closest to the company, but against the highest level of rigor observed anywhere in the single market — because that is the one that will, sooner or later, set the precedent for everyone else. Oates' theorem, built to weigh local against national public goods, finds a direct and current application here: a pan-European digital rule is only ever as strong, in practice, as its slowest enforcement link.

Analysis by
Cardan-AI Intelligence
Our research and analysis unit, dedicated to applied AI for business, industry and regulatory compliance.
Let's talk about your next competitive edge
Thirty minutes to identify the two or three use cases in your operations that pay for themselves within the first year.
