Baltimore, September 1960. Frances Oldham Kelsey has only a few weeks behind her as a pharmacologist at the American Food and Drug Administration (FDA) when she gets her first serious assignment: an application from the company Richardson-Merrell to approve for sale a drug called Kevadon, known in Europe as thalidomide. The preparation is already sold in more than forty countries as a mild sleeping pill, recommended also for pregnant women suffering from morning sickness. The documentation Kelsey receives mostly repeats the manufacturer's assurances of safety, without reliable studies of the substance's effect on the developing foetus.
Kelsey sends the application back for correction. Then she sends it back again. And again. Richardson-Merrell presses, phones her superiors and complains that a junior official is blocking, for no reason, a drug the entire continent has already judged safe. The company does not wait for formal approval, however: as part of a clinical research programme it hands out almost two and a half million tablets to twelve hundred American doctors, hoping that the experience of patients will settle the matter faster than a desk in Washington.
In November 1961 the German paediatrician Widukind Lenz, and independently British doctors, link the drug to a wave of newborns with severe limb defects. Western Europe alone sees tens of thousands of children affected by birth defects in this period. Grünenthal, the maker of thalidomide, withdraws the preparation from the German market within days. In the United States the drug never formally went on sale, although the samples handed out earlier had time to harm a dozen or so families.
A year later President John F. Kennedy presents Kelsey with the highest civilian honour of the country. Congress passes the Kefauver-Harris Amendment, which requires drug manufacturers to demonstrate both the safety and the efficacy of a preparation before it reaches its first pharmacy. The names of the officials who in forty European countries signed off thalidomide without asking further questions evaporated from memory long ago. What would have happened if any of them had asked a second time?
The same mechanics operate today with respect to artificial intelligence, only instead of tablets it is algorithms that reach the market, assessing job candidates, customers waiting for a loan or hotel guests lodging a complaint. In the summer of 2026 the European Union postponed the hardest obligations of its regulation on artificial intelligence, commonly known as the AI Act, giving companies more time to prepare. The real question is how much it will cost to sit out that time instead of using it, when something goes wrong.
What exactly the summer 2026 EU amendment changed
The regulation divides artificial intelligence systems into four risk levels: prohibited outright, for example scoring citizens in the style of Chinese social credit; high-risk, meaning among others systems used in recruitment, credit assessment, education or critical infrastructure; limited-risk, such as chatbots and content generators; and minimal-risk, which includes most everyday office tools. Since 2 August 2025 the rules for general-purpose models, so-called GPAI models, have applied: the systems on which popular chatbots run. Their providers must publish technical documentation and disclose what data was used for training. Since 2 August 2026, that is for less than two months now, Article 50 has also applied: every chatbot on a company website must clearly inform the interlocutor that they are talking to a machine, and material generated by artificial intelligence and concerning public affairs must be labelled as artificially produced.
The largest change concerns high-risk systems, however, meaning those that actually decide on someone's employment, pay or access to a service. In June 2026 the European Parliament adopted a package of amendments called the digital omnibus, approved by the Council of the European Union at the end of the same month. The package moved the full obligations for stand-alone high-risk systems listed in Annex III to the regulation from 2 August 2026 to 2 December 2027, and for systems embedded in products, for example in production lines, from 2 August 2027 to 2 August 2028. The reason for the delay is the unfinished technical standards that European standardisation bodies, the European Committee for Standardization and the European Committee for Electrotechnical Standardization, were supposed to prepare: without those standards companies have not yet received clear instructions on how to meet the regulation's requirements technically.
Why the HR department found itself on the front line of this regulation
Annex III names explicitly the systems that filter recruitment applications, direct job advertisements to selected audiences, assess employee performance or support decisions on promotion or dismissal. A hotel chain using an algorithm for preliminary selection of receptionists, a logistics company scanning the CVs of driver candidates, a retail chain assessing cashiers' work on the basis of data from checkout terminals and a bank checking customers' creditworthiness with a scoring model: all four cases fall today into the category the European Union considers high-risk. The deadline for full compliance has been moved to December 2027, which counting from today leaves less than fifteen months, and the scope of obligations is considerable.
For a system in this category the legislator has laid down a specific set of requirements:
- a risk assessment prepared before the system is deployed,
- technical documentation describing how the algorithm works,
- tests for errors and bias of the model towards individual groups of candidates,
- a mechanism of human oversight over every decision,
- an obligation to inform the candidate that artificial intelligence took part in the process.
The penalty for non-compliance is up to fifteen million euros or three percent of the company's global annual turnover, whichever amount is higher. The harshest penalty, reserved for explicitly prohibited practices, for example assessing employees' emotions from camera images, reaches thirty-five million euros or seven percent of turnover.
What the market for compliance tools shows
A market for tools supporting compliance with the regulation already exists, and it shows how much this topic really costs. Platforms such as Credo AI or Holistic AI, built for taking inventory of AI systems and preparing documentation compliant with the regulation, do not publish price lists. They sell access in a sales conversation, and rates for organisations with several dozen AI systems in use are usually between one hundred and five hundred thousand dollars a year. Microsoft Purview, a tool for auditing and tracking data in the Microsoft 365 ecosystem, is billed differently: fifteen dollars per million audit records and twenty dollars per gigabyte of data processed in legal discovery proceedings, known as eDiscovery.
For a mid-sized company in Poland that cannot yet afford, or does not need, a full enterprise-class platform, the starting point is often an ordinary legal audit. Law firms specialising in new technologies price a review of the compliance of AI systems used in a company at five to thirty thousand zloty, depending on the number of systems and the complexity of the processes they serve. That is little compared with a penalty counted in millions of euros, but enough for the board of a medium-sized hotel chain or a logistics company to keep putting the decision off.
What a compliance tool will do for you, and what nobody else will
A compliance management platform does one thing well: it organises documentation and watches review deadlines. That has value in itself, because in many companies nobody today knows how many AI tools are actually running in the organisation outside the knowledge of the IT department, in what is called shadow AI, meaning the use of AI applications without the company's consent and oversight. No platform will judge for the HR department, however, whether a particular recruitment algorithm really discriminates against pregnant candidates or people over fifty. That assessment must be made by a person who knows the data and the context of the work, and the tool will at best supply form templates and remind them of deadlines.
The greatest risk of this stage is the illusion that buying a tool means the topic has been dealt with, with the licence cost then receding into the background. Grünenthal's lawyers in the 1950s also had extensive documentation and positive opinions from doctors in forty countries: the paperwork added up, except that along the way nobody asked the question that the documentation could not answer by itself. The same trap awaits companies that treat a certificate of compliance with the regulation as a closed matter instead of as the starting point for regular review.
The first step worth taking on Monday
The first step requires no budget for any platform. It requires a spreadsheet and two hours of conversation with department heads who actually use AI tools, from the chatbot serving customers to the program sorting CVs. In the spreadsheet it is worth collecting four pieces of information about each system: what it is used for, who makes decisions about people on its basis, what data it processes and whether the vendor has made technical documentation available. Such an inventory costs one afternoon of work and answers the question that every auditor and every compliance platform will ask later anyway: how many high-risk systems are actually running in the company and who is responsible for them.
December 2027 seems distant today, exactly as in 1960 the question of what thalidomide does to a foetus in the first weeks of pregnancy seemed distant. Companies that start taking inventory of their systems now will reach that deadline with ready documentation and a calm head. Those that wait until autumn 2027 will be doing in a hurry what can today be done calmly, with a similar difference in consequences to the one shown sixty-odd years ago by two and a half million tablets handed out prematurely. Who in your company has the courage today to ask a second time, before a system that assesses people goes into use?