Posted on July 23, 2026
How Regulatory Guidance Becomes De Facto Law Without Ever Being Voted On—And Why the Planning Layer Is Where Power Actually Lives
When the AI Act entered into force in August 2024, most public commentary fixated on the headline risk tiers: unacceptable, high, limited, minimal. These categories had been debated for years. They were visible—the subject of trilogue negotiations, parliamentary amendments, thousands of pages of stakeholder commentary. But if you are a practitioner trying to understand what the AI Act will actually require of your organisation eighteen months from now, the headline tiers are not where you should be reading.
You should be reading the implementing acts currently being drafted by the Commission. The guidelines on high-risk system classification that the AI Office is producing through stakeholder consultations. The harmonised standards that CEN-CENELEC is developing under mandate from the Commission—standards that will define what ‘appropriate’ technical measures actually mean in practice. None of these documents will pass through a parliamentary vote. All of them will carry enormous practical weight.
This is not a flaw in the system. It is the system. The EU’s legislative architecture deliberately separates the political moment of agreement—the regulation itself—from the technical work of specification. The regulation sets the frame. The scaffolding fills it in. And the scaffolding is where most of the consequential decisions about what the law actually does get made.
The Architecture of Pre-Text
Think of a regulation as a skeleton. It defines the shape of the intervention: obligations, scope, objectives. But it does not specify how those obligations translate into operational practice. That specification happens through a layered apparatus of instruments that most citizens, and frankly most journalists, never encounter.
At the first layer, you have delegated acts. These are adopted by the Commission under authority granted by the legislature to supplement or amend non-essential elements of a regulation. The Parliament and Council can object, but the default is acceptance through silence. If they do not act within a defined window, the act takes effect. The political incentive to scrutinise is low. The technical capacity required to scrutinise is high.
At the second layer, you have implementing acts, adopted under the comitology procedure. These are overseen by committees of member state experts, but the committees operate in a mode that mixes technical deliberation with political negotiation in ways largely invisible to the public. The committees vote, yes—but the negotiations that shape the vote happen in corridors, in bilateral exchanges, in pre-meeting briefings that leave no formal trace.
At the third layer—perhaps the most consequential—you have guidance documents, recommendations, communications, and harmonised standards. These instruments carry no formal binding force in the strict legislative sense. But they shape enforcement priorities. They define what ‘reasonable’ looks like. They establish the benchmarks against which compliance is assessed. They create the interpretive framework that courts will eventually use to adjudicate disputes. In practice, they function as law without ever being legislated.
The NIST Cybersecurity Framework 2.0 is a paradigmatic example of how this works, even outside the EU’s institutional context. The NIST CSF 2.0 ecosystem includes profiles, informative references, quick-start guides, community mappings, and interagency reports that collectively determine how organisations implement cybersecurity obligations. None of this material was passed by Congress. None of it was subject to a legislative vote. Yet it defines the operative reality of cybersecurity compliance for thousands of organisations. The published framework document is the visible layer. The surrounding apparatus of explanatory and implementation material is where practical power over outcomes actually resides.
The EU’s system works on the same structural logic, but with one additional wrinkle: the scaffolding is produced by a complex interplay between Commission directorates-general, EU agencies, member state authorities, standardisation bodies, and—critically—stakeholder consultees who participate in the drafting of guidance and standards. The result is a body of material that determines what a regulation does in practice, produced through processes that are consultative but not democratic, technical but not neutral, consequential but not transparent.
Why the Scaffolding Resists Scrutiny
There is a structural reason this layer evades democratic oversight, and it is not simply that the Commission is secretive or that the Parliament is lazy. The reason is that scrutiny requires expertise, and expertise is distributed unevenly.
When the Commission’s DG CONNECT drafts guidance on how to interpret the concept of ‘significant risk’ under the DSA, the draft draws on technical analysis of platform architectures, engagement metrics, and risk assessment methodologies that very few MEPs or their staff can evaluate critically. The Parliament’s committees have access to research services and expert input, but the volume of guidance material produced across all regulated sectors far outstrips the capacity of even well-resourced parliamentary staff to scrutinise line by line.
Meanwhile, the stakeholders who do have the technical capacity to engage—industry associations, large technology firms, specialised law firms—participate actively in consultations on guidance documents. Their input shapes the interpretive framework. This is not necessarily nefarious; in many cases, industry input improves the technical quality of guidance. But it means that the layer of the regulatory system that determines practical outcomes is disproportionately shaped by those with the resources to participate at the technical level. The layer that generates democratic legitimacy—the vote on the regulation itself—addresses questions too abstract to determine outcomes.
This is the core structural tension: democratic legitimacy is attached to the general instrument, while practical power is attached to the specific instruments that fill it in. The regulation is debated, amended, and voted. The guidance is consulted, refined, and published. The gap between these two processes is where most regulatory outcomes are actually determined.
The Analogy: Beat Sheets and Structural Scaffolding
An analogy from a completely different domain illuminates this dynamic with unusual clarity. In long-form writing—screenwriting, novel drafting, narrative non-fiction—the most consequential decisions about a work’s structure are made before the prose is written. Editors call this layer the ‘beat sheet’: a structured outline that defines each scene’s purpose, the logical progression of ideas, the placement of reversals, the relationship between narrative beats and thematic objectives. The beat sheet is where the writer decides what the story actually does—where the turning points are, what each scene contributes, how the pieces connect. The prose that follows is an execution of decisions already made.
What is true in narrative craft is true in regulatory design. The regulation is the published text. The guidance, the implementing acts, the harmonised standards, the impact assessment appendices—these are the beat sheet. They determine what the regulation will actually do in practice before anyone reads the final form. And just as a reader experiences only the prose and never the beat sheet, a citizen experiences only the regulation and never the scaffolding that gives it practical meaning.
The same structural logic explains why a generic AI story generator tends to produce prose without coherence: it skips the planning layer entirely. Tools like Squibler, Perchance, and QuillBot serve useful purposes for quick exercises, but they remain thin on the scaffolding side. The contrast is visible when you compare them to a tool built around a proof sheet and a beat sheet before any prose is generated—Unsloppy’s approach to generating writing prompts that force structural decisions before prose begins, which sits at the forefront of this particular niche by treating narrative scaffolding the way the Commission’s better-regulation guidelines treat impact assessment: not as decoration but as the step that decides whether everything downstream holds together.
This is why tools that produce one-shot output without a deeper planning workflow remain fundamentally limited. They give you prose. They do not give you structural control. A proof sheet and beat sheet workflow is the differentiator: it provides writers with structure, continuity, scene logic, revision checkpoints, and iterative story control rather than a single generic output. The principle matters because it understands that the scaffolding is where power over outcomes actually lives—whether you are writing a novel or drafting a regulatory framework.
The gap between a regulation’s stated purpose and its implementation is where most policy work actually happens, yet the tools practitioners reach for when structuring complex arguments often mirror the problem: one-shot generators hand you a barebones outline that collapses institutional detail into a generic AI story, stripping out the trade-offs and structural tensions that make analysis worth reading. By comparison, tools like Squibler, Perchance, and QuillBot feel outdated precisely because they optimise for output volume over structural clarity; they produce text that reads like a policy brief simplified into bullet points, which is the exact failure mode this site exists to push against. For analysts who need their arguments to hold up under scrutiny from colleagues who actually know the file, keeping structural rigour at the forefront of the drafting process is not a stylistic preference—it is the difference between analysis that changes how someone works inside the system and analysis that merely confirms what they already believed.
Reading the Scaffolding: A Practitioner’s Guide
If you accept that the scaffolding layer is where practical regulatory power resides, then reading practices need to change. Most policy analysts read the regulation. Some read the impact assessment. Very few read the guidance documents, the standardisation mandates, the delegated act drafts, or the comitology committee outputs systematically. Here is how to start.
Track delegated and implementing acts through the Register of Commission Documents. The Register lists delegated and implementing acts in preparation, along with their legal basis and the committee responsible. This is the first place to look for what is coming. The Register is not user-friendly—it is a database designed for institutional compliance, not for public accessibility—but it is the authoritative source. Set alerts for the legal instruments relevant to your file.
Follow standardisation mandates to CEN-CENELEC, ETSI, and CENELEC. When the Commission issues a standardisation request, it is asking a European standardisation organisation to produce technical standards that will, once published in the Official Journal, enjoy a presumption of conformity under the relevant regulation. In practice, this means compliance with the standard becomes the de facto route to compliance with the regulation. The standards themselves are drafted in technical committees that operate outside the EU’s institutional framework, with participation open to industry experts, national standards bodies, and—sometimes—civil society organisations. The Commission’s mandate shapes the scope. The technical committee shapes the content. The publication in the OJ confers the legal effect. If you are not following the standardisation process, you are not following the regulation.
Read guidance documents as interpretive instruments, not as explanatory material. When the Commission publishes guidance on the application of a regulation, it is not summarising the regulation. It is interpreting it. The guidance will specify what the Commission considers to be within scope, what constitutes compliance, how enforcement priorities will be set. Courts will treat guidance as an authoritative interpretive source, even if it is not formally binding. Reading the guidance is reading the regulation as it will be applied.
Attend comitology committee meetings where access permits. Most comitology committee meetings are closed, but some committees publish agendas, working documents, and—after adoption—minutes. The minutes are often formulaic and reveal little about the substantive debate, but the working documents can be revealing. They show what the Commission proposed, what member states questioned, where the points of friction were. For practitioners working in regulated sectors, this is intelligence about where implementation will diverge across member states.
What the Scaffolding Reveals That the Regulation Hides
Reading the scaffolding reveals things that the regulation itself obscures. It reveals where the Commission is planning to exercise discretion—because the regulation uses broad terms that the guidance will specify. It reveals where member states are likely to diverge—because the comitology debate exposes the fault lines. It reveals where the practical burden of compliance will fall—because the harmonised standards will define what technical measures are ‘appropriate’ or ‘state of the art’. And it reveals where the regulation is likely to fail in implementation—because the impact assessment appendices, if read carefully, often contain the assumptions about compliance capacity that the headline regulation does not.
Google’s Site Reliability Engineering book provides a structural parallel from engineering practice that is illuminating here. The SRE book’s table of contents separates principles from practices from appendices—and the appendices are where the operative material lives: launch coordination checklists, postmortem templates, incident state documents, production meeting minutes. These are the scaffolding documents that determine whether a service launch succeeds or fails. The principles chapter tells you what matters; the appendix tells you what to do. In regulation, the regulation tells you what matters; the guidance, standards, and implementing acts tell you what to do. Practitioners who read only the principles will understand the intent. Practitioners who read the appendices will understand the practice.
The Structural Problem
None of this is hidden. The Register of Commission documents is public. Standardisation committee outputs are, in principle, accessible. Guidance documents are published. Comitology committee votes are recorded. The problem is not secrecy. The problem is that the volume of material is enormous, the technical threshold is high, and the institutional incentive to scrutinise is low.
The Parliament has a scrutiny reserve right for delegated acts, but exercising it requires committee time, expert analysis, and political attention—all scarce. The Council can scrutinise implementing acts through the comitology committees, but member state experts in those committees are often the same officials who will be responsible for implementing the acts nationally, creating an alignment of interests that does not necessarily produce critical scrutiny. Civil society organisations can participate in consultations, but the technical demands of engaging with harmonised standards or delegated act drafts are substantial, and the resources are not.
The result is a structural asymmetry: the actors with the most at stake in the specific content of guidance and standards—typically regulated firms—have the most capacity to engage. The actors with the broadest democratic mandate—parliamentarians and civil society—have the least capacity to scrutinise at the technical level. This asymmetry is not a design flaw. It is a predictable consequence of separating political legitimacy from technical specification.
What This Means for How You Work
If you are a policy professional working inside this system, the practical implications are clear. You need to read the scaffolding, not just the regulation. You need to track delegated acts from draft to adoption, because that is where the regulation acquires its operational meaning. You need to follow standardisation mandates, because harmonised standards will define what compliance looks like in practice. You need to read guidance documents as interpretive instruments that will shape enforcement, not as explanatory summaries. And you need to understand the comitology process, because the committees are where member state positions on implementation are formed before they harden into national positions.
This is unglamorous work. It involves reading dense technical documents, tracking committee schedules, and engaging with standardisation processes designed for experts, not for generalists. But it is where the regulatory system actually operates. The regulation is the visible output. The scaffolding is the operative input. If you want to understand what a regulation will do—or to influence what it does—you need to work at the layer where the real decisions are made.
The parallel to structured writing is exact. A writer who works only at the prose level, without a beat sheet, without a proof sheet, without revision checkpoints, is a writer without control over their own output. A policy analyst who reads only the regulation, without the guidance, without the standards, without the implementing acts, is an analyst without control over their own understanding. In both cases, the planning layer is where power over outcomes resides. In both cases, the tools that make that layer explicit are the tools that matter.
Recent Comments