There are two ways a board can read a new regulation, and the choice between them is worth far more than most boards realise. The first reading — the default, the one I hear in most rooms — is compliance as burden: a cost to be minimised, a risk to be survived, a box to be ticked as cheaply as possible so everyone can get back to the real work. The second reading is rarer and, I've come to believe, correct for this particular regulation at this particular moment: compliance as competitive edge — the recognition that a rule which forces everyone to do something hard, and which most will do grudgingly and badly, is an opportunity for the few who do it deliberately and well. The EU AI Act is now in force, its first hard prohibitions land within weeks, and I want to make the case to boards that the burden reading is not just gloomy but strategically wrong — that the Act is, for those willing to see it, one of the better competitive openings of the decade.
Why "burden" is the natural — and expensive — default
Let me be fair to the burden reading, because it isn't irrational. A new regulation genuinely does impose cost: work to understand it, work to comply, risk if you get it wrong. Boards are trained to see regulation as downside management, and for a great many rules that instinct is exactly right — you meet the requirement at the lowest defensible cost and move on, because there's no prize for elegant compliance with a parking bylaw.
But that instinct misfires badly on regulations that touch trust in a product, and the AI Act is precisely such a regulation. It isn't a bylaw about a peripheral obligation. It's a rule about whether the AI systems you build and use are safe, fair, transparent, and accountable — which is to say, it's a rule about whether people can trust the thing you're selling them. And when a regulation is about trust, treating it as a minimise-and-survive burden means treating your own trustworthiness as a cost to be minimised, which — the moment you say it that plainly — is obviously a strategic error. You don't get competitive edge from being barely trustworthy at the lowest possible cost. You get it from being demonstrably trustworthy while your competitors are still doing the minimum.
The burden reading, in other words, isn't wrong because it's pessimistic. It's wrong because it optimises the wrong variable — it treats the Act as being about cost avoidance when it's actually about trust production, and trust, in the AI market that's now arriving, is about to become the scarcest and most valuable thing there is.
Why trust is about to get scarce and valuable
Here's the market context that makes the competitive reading more than wishful thinking. We're at a moment where AI is being deployed everywhere, fast, and where public and customer trust in it is fragile and declining — every confident-wrong answer, every biased system, every opaque decision that can't be explained erodes it further. In that environment, "we use AI" is rapidly ceasing to be a differentiator, because everyone will say it. The differentiator becomes "you can trust the way we use AI" — and that's a claim most organisations won't be able to credibly make, because they've been treating trustworthiness as a cost to minimise.
This is where the Act quietly becomes a gift. It forces exactly the disciplines that produce demonstrable trust — knowing what your AI systems do, governing their data, ensuring human oversight, being transparent about limitations, being able to show your working to a regulator. An organisation that does that well doesn't just avoid penalties. It earns the right to make a claim its competitors can't: we can prove our AI is trustworthy, because we've built and documented it to a standard the law defines and most of our market is failing to meet. In a market where trust is scarce and getting scarcer, that's not compliance. That's positioning.
When trust becomes the scarce resource in a market, a regulation that forces you to produce trust is not a tax — it's a moat. Your competitors are being made to build the same thing you are; the edge goes to whoever treats it as a product feature instead of a compliance chore.
What the competitive reading actually looks like on a board agenda
This isn't merely a mindset flip; it changes what a board actually does. The burden reading and the competitive reading produce visibly different behaviour, and the difference compounds.
- Burden reading: comply as late and cheaply as possible. Wait for clarity, do the minimum the deadline forces, treat it as a legal project owned by legal, measure success by penalties avoided. This minimises short-term cost and forfeits every ounce of the strategic opportunity — you'll arrive at trustworthy last, having spent the money anyway.
- Competitive reading: build trustworthy AI deliberately, and make it visible. Move early, build the governance and oversight and transparency as genuine product qualities, own it at board level as strategy rather than parking it in legal as risk — and then tell the market you've done it. Turn the compliance work into a trust claim customers and partners can feel. Same underlying work; radically different return.
The competitive reading also changes who owns it. Treated as burden, the AI Act belongs to legal and compliance, far from strategy. Treated as edge, it belongs on the board's strategy agenda, because "how do we become the demonstrably-trustworthy option in our market" is a strategic question that happens to have a regulatory deadline attached. The organisations that will pull ahead are the ones whose boards make that ownership shift — from "how do we survive this" to "how do we win with this."
Two competitors, same rule, different year
Picture two companies in the same regulated market, both using AI in ways that land in the Act's high-risk tier, both facing the same obligations and the same deadline. Watch how the two readings play out over the two years the obligations phase in.
The first treats it as burden. It waits for maximum clarity, keeps the work in legal, scopes it to the minimum the deadline forces, and measures success by penalties avoided. It arrives at the deadline compliant — genuinely, adequately compliant — having spent real money and gained nothing it can point a customer at. Its compliance is invisible, because it was designed to be cheap, not to be seen. When a big prospective client asks, in a procurement process, "can you demonstrate your AI systems meet the Act's requirements for oversight, transparency, and data governance?", it can eventually assemble an answer, defensively, as a scramble.
The second treats it as edge. It moves early, owns the work at board level as strategy, and builds the oversight and transparency and documentation as genuine qualities of its product rather than a compliance veneer — and crucially, it builds them to be shown. When the same prospective client asks the same procurement question, the second company doesn't scramble; it has a clear, evidenced, already-prepared answer, and it wins the deal partly because of it, while the first company is still assembling its defence. Same regulation, same cost order of magnitude, same deadline. One company spent the money and got compliance. The other spent comparable money and got a reason for customers to choose it. That gap — invisible on the balance sheet, decisive in the market — is the entire argument, made concrete.
How trust actually becomes visible
The two-competitors story turns on one word I've been leaning on — demonstrable — and it deserves its own treatment, because "be trustworthy" is useless advice without "and here's how anyone can tell." Trust that only lives inside your own conviction is worth nothing competitively; it has to be made legible to the people whose decisions you want it to move. In practice that means a few concrete things:
- Evidence, not assertion. The difference between "we take AI ethics seriously" (which everyone says) and a documented, auditable account of how your high-risk systems are governed, overseen, and tested (which almost no one can produce) is the difference between a slogan and a moat. The Act, usefully, defines roughly what that evidence should contain — so it's doing some of the specification work for you.
- Trust your customers can procure against. Increasingly, the place trust gets tested is procurement — the questionnaire, the due-diligence request, the "show us your AI governance" clause. Being the vendor with a ready, credible, evidenced answer while competitors improvise is a concrete, repeated, winnable advantage, deal after deal.
- Trust the board can stand behind publicly. There's reputational value in a board being able to say, and mean, "we can account for how our AI behaves" — not as marketing, but as a claim that survives scrutiny. In a market bracing for AI failures and the headlines they bring, being visibly the careful operator is a position competitors treating this as a cost simply can't occupy.
The through-line is that none of the competitive value comes from the compliance being done — it comes from it being done well enough to show. A board that grasps this stops asking "have we met the requirement" and starts asking "can we prove it to someone who matters, better than our competitors can" — which is a strategy question wearing a compliance deadline, exactly as I've been arguing.
The honest caveats, because a pillar with none is a sales pitch
I'd undercut my own argument if I pretended the competitive reading is free or guaranteed, so here are the limits I'd want any board to hold alongside the optimism.
First, the edge is real but bounded — it's largest in markets where trust genuinely drives buying decisions (regulated sectors, sensitive data, high-consequence use, discerning customers) and smaller where it doesn't. A board should size the opportunity honestly for its market rather than assume it's enormous everywhere. In some commodity contexts, competent low-cost compliance really is the right call, and I won't pretend otherwise.
Second, the edge only exists if the trustworthiness is genuine and demonstrable. This is not a marketing exercise you can bolt on — claiming trustworthy AI while doing the minimum is worse than saying nothing, because it invites the exact exposure that destroys trust fastest. The competitive reading demands you actually do the hard work; it just insists that the hard work, done properly, is an investment rather than a cost.
Third, timing matters and the window is finite. The competitive edge from being demonstrably trustworthy is largest now, while most of the market is still treating the Act as a burden. As trustworthy-AI practices become table stakes — and they will — the differentiation erodes into a baseline everyone meets. So the strategic value is highest for boards that move early and shrinks for those that wait, which neatly inverts the burden reading's instinct to delay.
The reframe, and the job underneath it
I've spent a lot of this year translating AI risk into terms boards can actually govern, and this is the strategic capstone of that translation work. The AI Act reaches boards as dense law and arrives feeling like a threat. The job — and it's a communication job as much as a strategic one — is to help boards see past the burden framing to the opportunity underneath: that a regulation forcing the whole market to produce trust is a chance for the few who produce it best to be visibly, bankably ahead.
None of this dismisses the real cost or the genuine risk; both exist and a serious board holds them. But the board that sees only cost and risk will comply grudgingly, spend the money, and get nothing back but the absence of penalties. The board that also sees the opportunity will spend comparable money and get back a market position — the credible, provable status of being the trustworthy option while trust is scarce and dear. Same regulation. Same deadline. Same underlying work. Wildly different outcome, decided entirely by which of the two readings the board chose at the start. The Act is going to make everyone do this. The edge belongs to whoever decided to do it on purpose.