{"id":21233,"date":"2026-05-28T10:18:00","date_gmt":"2026-05-28T10:18:00","guid":{"rendered":"https:\/\/wearekemb.com\/eu-ai-act\/"},"modified":"2026-08-18T07:33:52","modified_gmt":"2026-08-18T07:33:52","slug":"eu-ai-act","status":"publish","type":"post","link":"https:\/\/wearekemb.com\/en\/eu-ai-act\/","title":{"rendered":"The EU AI Act Is Already in Effect \u2013 And Most Companies Aren\u2019t Ready"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Your employees are using AI right now \u2013 many with tools you haven\u2019t approved. Some paste customer data into ChatGPT, upload strategy documents to AI summarizers, or run browser extensions that silently send session data to third-party servers. In most organizations, no one is tracking any of it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is the reality the EU AI Act was designed to address. And unlike most regulations, parts of it are already law.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">AI Adoption Is Outpacing Governance \u2013 By a Wide Margin<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Generative AI tools have moved from occasional experiments to core workflow components faster than most companies could respond. From 2023 to 2024, enterprise employee adoption of generative AI grew from 74% to 96%. The challenge isn\u2019t adoption \u2013 it\u2019s accountability.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to an IDC 2025 survey, 56% of employees use unauthorized AI tools at work, while only 23% use AI tools their organization provides and governs. Put simply: the majority of AI activity in most enterprises already operates outside security controls, compliance frameworks, and visibility systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This phenomenon has a name:&nbsp;<strong>Shadow AI<\/strong>. Its scale in the DACH market mirrors global trends. 63% of organizations lacked AI governance policies, even as employees actively used generative AI in daily work. Shadow AI-related data breaches added an average of $670,000 to breach costs \u2013 a 16% increase compared to organizations with low or no Shadow AI.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The governance gap isn\u2019t a future problem. It\u2019s already costing companies through security incidents, data leakage, and regulatory exposure.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why the EU AI Act Matters Right Now<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The EU AI Act is the first comprehensive legal framework for AI worldwide, addressing AI risks and positioning Europe as a regulatory benchmark. For Mittelstand companies and multinationals operating in the DACH region, this isn\u2019t a distant event \u2013 it\u2019s a phased reality with active obligations already in force.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>EU AI Act: Key Milestones for Companies Using Generative AI<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><th>Date<\/th><th>What Applies<\/th><th>Impact on Your Business<\/th><\/tr><tr><td>Feb 2, 2025<\/td><td>Prohibited AI practices banned + AI Literacy obligation active<\/td><td>Employees must have adequate AI literacy; certain AI uses (e.g., social scoring) are now illegal<\/td><\/tr><tr><td>Aug 2, 2025<\/td><td>Governance rules + GPAI model obligations active<\/td><td>Transparency and documentation requirements for General Purpose AI models take effect<\/td><\/tr><tr><td>Aug 2, 2026 \ud83d\udd1c<\/td><td>Full enforcement for most operators (incl. Article 50 transparency)<\/td><td>AI-generated content must be labeled; deployers responsible for how AI outputs are used; fines up to \u20ac35M or 7% global turnover for violations<\/td><\/tr><tr><td>Dec 2, 2027<\/td><td>High-risk AI systems (Annex III) fully apply<\/td><td>Biometrics, employment, education, critical infrastructure AI subject to full compliance requirements<\/td><\/tr><tr><td>Aug 2, 2028<\/td><td>Product-embedded high-risk AI systems<\/td><td>AI integrated into regulated products (e.g., medical devices, industrial machinery) must comply<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The key insight for business leaders:&nbsp;<strong>the EU AI Act distinguishes between AI providers (who build models) and deployers (companies that use AI tools)<\/strong>. If your business uses or integrates generative AI, assessing the associated risks is mandatory. Even if a model provider assumes certain obligations, deployers remain responsible for how AI results are used. Contractual clarity and supplier due diligence are essential components of compliance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Using ChatGPT, Copilot, or AI-powered analytics tools makes your organization a deployer. That comes with accountability.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Real Problem: You Can\u2019t Govern What You Can\u2019t See<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Most companies know the EU AI Act is here. Fewer understand the actual gap between where they stand today and what the regulation requires operationally.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The problem isn\u2019t irresponsible AI use \u2013 it\u2019s that companies have&nbsp;<strong>no visibility<\/strong>&nbsp;into how AI is being used at all.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Consider what\u2019s typically missing:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>No AI tool inventory:<\/strong>\u00a0Most organizations don\u2019t know which AI tools are actually in use across teams.<\/li>\n\n\n\n<li><strong>No usage policies:<\/strong>\u00a0More than half of surveyed employees said their company has no official AI policy (23%), they\u2019re unaware whether one exists (16%), or that unauthorized AI use is actively encouraged (16%).<\/li>\n\n\n\n<li><strong>No data controls:<\/strong>\u00a0According to Cisco\u2019s 2025 study, 46% of organizations reported internal data leaks through generative AI \u2013 data that flowed out via employee prompts rather than traditional exfiltration.<\/li>\n\n\n\n<li><strong>No accountability structure:<\/strong>\u00a0Without assigned ownership, AI governance doesn\u2019t happen \u2013 it gets deferred.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">A key element of AI governance: ensuring adequate AI literacy among employees and contractors who operate AI systems on your organization\u2019s behalf. This is a legal obligation under the EU AI Act, effective since February 2025.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Important<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The EU AI Act\u2019s AI Literacy obligation has been active since February 2, 2025.<\/strong>&nbsp;Organizations operating in the EU market are already required to ensure that employees involved in AI use and deployment have adequate AI literacy. This is not a future requirement \u2013 it applies right now.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The most exposed companies aren\u2019t the ones experimenting aggressively with AI \u2013 they\u2019re the ones that let adoption happen organically, without structure, documentation, or ownership.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why Data Governance Is the Foundation of AI Governance<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Here\u2019s the angle often missed in compliance discussions:&nbsp;<strong>AI governance cannot be separated from data governance<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The EU AI Act demands accountability and traceability. It requires organizations to know what data AI systems process, how AI outputs influence decisions, and who is responsible when things go wrong. None of that is achievable without a solid data governance foundation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At KEMB, this is the connection we make with every client navigating AI adoption. The questions regulators will ask \u2013&nbsp;<em>What data did this AI system use? Who authorized it? How was the output verified?<\/em>&nbsp;\u2013 are the same questions a well-structured&nbsp;<strong><a href=\"https:\/\/wearekemb.com\/en\/modern-data-governance-frameworks\/\" target=\"_blank\" rel=\"noreferrer noopener\">data governance framework<\/a><\/strong>&nbsp;should already answer.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Companies with clean, documented, and lineage-tracked BI infrastructure are significantly better positioned for EU AI Act compliance than those operating on fragmented data landscapes. If your reporting data is already transparent, governed, and auditable \u2013 as part of a strong&nbsp;<a href=\"https:\/\/wearekemb.com\/en\/data-strategy-roadmap\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>data strategy roadmap<\/strong><\/a>&nbsp;\u2013 applying those principles to AI usage is a natural extension.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Conversely, companies that can\u2019t answer basic questions like&nbsp;<em>\u201cWhich teams use which AI tools?\u201d<\/em>&nbsp;or&nbsp;<em>\u201cWhat customer data has been shared with external AI services?\u201d<\/em>&nbsp;are starting from zero \u2013 operationally and in regulatory terms.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Companies Should Do Now: A Practical Governance Roadmap<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The EU AI Act isn\u2019t a legal project to delegate to a compliance team. It\u2019s an operational challenge that touches marketing, BI, data, IT, HR, and leadership. The good news: the steps are practical, sequential, and directly beneficial beyond compliance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>1. Audit Your AI Tool Landscape<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Identify every AI tool currently in use across your organization \u2013 including tools employees use independently (Shadow AI). This includes ChatGPT, Copilot, Gemini, browser extensions, AI features embedded in SaaS tools, and any internal AI models. You cannot govern what you cannot see.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2. Define and Communicate an AI Usage Policy<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Create a clear, written policy that covers: which tools are approved, what data may and may not be shared with AI systems, who is accountable for AI outputs, and how violations are handled. Keep it practical \u2013 policies with vague wording change nothing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>3. Assign Ownership and Accountability<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Designate an AI owner or responsible function (could be in IT, Data, Legal, or Operations). Define who is accountable for AI risk management, documentation, and ongoing compliance reviews. Without ownership, governance stalls.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>4. Build AI Literacy Across the Organization<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The EU AI Act requires organizations to ensure employees have adequate AI literacy \u2013 an obligation that has been active since February 2025. Run awareness training covering AI risks, responsible usage, data handling, and your internal policies. This applies to all staff interacting with AI tools, not just technical teams.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>5. Strengthen Your Data Governance Foundation<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">AI governance starts with data governance. Classify your data by sensitivity, document what data flows into AI tools, and ensure your BI and reporting infrastructure has clear lineage and access controls. This foundation makes AI usage auditable, transparent, and defensible under the EU AI Act.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>6. Review and Iterate Regularly<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">AI tools and regulations evolve rapidly. Schedule quarterly reviews of your AI tool inventory, policy updates, and literacy programs. Align your compliance roadmap with EU AI Act deadlines \u2013 particularly the full enforcement date of August 2, 2026.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Test your organization\u2019s readiness with our assessment:<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>AI Inventory<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Do you have a complete inventory of all AI systems used in your organization?<\/li>\n\n\n\n<li>Are your AI systems categorized by risk level (high\/limited\/minimal)?<\/li>\n\n\n\n<li>Do you document the purpose and impact of each AI system?<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Policies<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Have you established internal policies for AI usage?<\/li>\n\n\n\n<li>Are these policies aligned with EU AI Act requirements?<\/li>\n\n\n\n<li>Do you regularly review and update your AI policies?<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Ownership<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Is there a clearly designated person responsible for AI compliance?<\/li>\n\n\n\n<li>Are roles and responsibilities for AI governance clearly defined?<\/li>\n\n\n\n<li>Is there an escalation process for AI-related incidents?<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>AI Literacy<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Have your employees received training on responsible AI use?<\/li>\n\n\n\n<li>Are your teams aware of the EU AI Act risk categories?<\/li>\n\n\n\n<li>Do you have ongoing education programs for AI literacy?<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Data Governance<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Have you implemented a data governance framework?<\/li>\n\n\n\n<li>Do you ensure data quality and provenance for AI training data?<\/li>\n\n\n\n<li>Are appropriate data protection measures (GDPR) in place for AI systems?\u00a0<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Out of 15 questions total:<strong><\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>12\u201315 Answers \u201cYes\u201d: You\u2019re AI-ready.<\/strong>&nbsp;Strong foundations across inventory, governance, and literacy. The work now is making it bulletproof \u2014 document what you\u2019ve built, validate it against the Act\u2019s specific obligations, and set a review cadence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>9\u201311 Answers \u201cYes\u201d: You\u2019re on track, but gaps remain.<\/strong>&nbsp;Solid progress in several areas, real holes in others. Most organizations at this level need 6\u201312 months of structured work to reach full compliance. The EU AI Act timeline is active \u2014 start with your weakest area now.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>5\u20138 Answers \u201cYes\u201d: You\u2019re at an early stage.<\/strong>&nbsp;Some awareness, but limited formal structures. Without action, your organization carries real compliance risk as EU AI Act obligations phase in. A focused 90-day sprint can close the foundational gaps.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>0\u20134 Answers \u201cYes\u201d: Compliance work hasn\u2019t started.<\/strong>&nbsp;Very few or no foundations in place. The EU AI Act is already in force for high-risk systems. Starting today is materially better than waiting \u2014 even three basic steps reduce your exposure significantly.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Key Takeaways<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The EU AI Act is not a future concern \u2013 it\u2019s an active regulatory framework with obligations already in force and a major enforcement deadline on&nbsp;<strong>August 2, 2026<\/strong>. For most DACH companies using generative AI tools like ChatGPT, Copilot, or AI-powered business software, the immediate priorities are:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Gain visibility<\/strong>\u00a0into which AI tools are used, by whom, and with what data<\/li>\n\n\n\n<li><strong>Define clear policies<\/strong>\u00a0\u2013 vague or absent guidelines directly increase regulatory and security risk<\/li>\n\n\n\n<li><strong>Build AI literacy<\/strong>\u00a0across your organization (legally required since February 2025)<\/li>\n\n\n\n<li><strong>Anchor AI governance in data governance<\/strong>\u00a0\u2013 transparency, lineage, and accountability start with your data infrastructure<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Companies that treat this as an operational and strategic priority \u2013 rather than a legal checkbox \u2013 will move faster, govern better, and build a data foundation that serves them well beyond compliance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Want to understand where your organization stands today? Start with an honest AI tool audit. If your data infrastructure isn\u2019t built for transparency and accountability, that\u2019s the foundation to lay first.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Does the EU AI Act apply to my company if we only use tools like ChatGPT or Copliot &#8211; not build AI?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Yes. The EU AI Act distinguishes between AI providers (who build models) and deployers (companies that use AI tools in their operations). As a deployer, you are responsible for how AI outputs are used in your business processes. This includes obligations around transparency, documentation, and ensuring employees have adequate AI literacy.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What is Shadow AI and why is it an EU AI Act risk?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Shadow AI refers to employees using AI tools independently, without IT approval or company oversight \u2013 think personal ChatGPT accounts, browser-based AI assistants, or AI features in SaaS tools. Under the EU AI Act, your organization remains accountable for AI usage within your operations, even if you didn\u2019t officially sanction those tools. Shadow AI creates traceability and accountability gaps that directly conflict with the Act\u2019s requirements.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What are the fines under the EU AI Act?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Fines vary by violation type. The most severe penalties \u2013 for prohibited AI practices \u2013 can reach up to \u20ac35 million or 7% of global annual turnover (whichever is higher). Violations of other obligations (e.g., transparency, governance) can result in fines of up to \u20ac15 million or 3% of global turnover. Full enforcement for most operators takes effect on August 2, 2026.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What does AI literacy mean under the EU AI Act?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The Act requires organizations to ensure that employees involved in the operation or use of AI systems have sufficient AI literacy \u2013 meaning they understand how the AI tools they use work, what the risks are, and how to use them responsibly. This obligation has been active since February 2, 2025. It applies to both technical and non-technical staff who interact with AI tools.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">How does data governance relate to EU AI Act compliance?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Data governance is the foundation of AI governance. The EU AI Act requires accountability and traceability around how AI systems are used \u2013 and that means knowing what data flows into AI tools, how it\u2019s used, and who is responsible. Companies with strong data governance (documented data lineage, clear access controls, defined ownership) are far better positioned to demonstrate compliance than those with fragmented or opaque data landscapes.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Your employees are using AI right now \u2013 many with tools you haven\u2019t approved. Some paste customer data into ChatGPT, upload strategy documents to AI summarizers, or run browser extensions that silently send session data to third-party servers. In most organizations, no one is tracking any of it. This is the reality the EU AI [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":21582,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","footnotes":""},"categories":[62,63],"tags":[],"class_list":["post-21233","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-digital-marketing-en","category-process-automation-en"],"_links":{"self":[{"href":"https:\/\/wearekemb.com\/en\/wp-json\/wp\/v2\/posts\/21233","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wearekemb.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wearekemb.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wearekemb.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/wearekemb.com\/en\/wp-json\/wp\/v2\/comments?post=21233"}],"version-history":[{"count":3,"href":"https:\/\/wearekemb.com\/en\/wp-json\/wp\/v2\/posts\/21233\/revisions"}],"predecessor-version":[{"id":21237,"href":"https:\/\/wearekemb.com\/en\/wp-json\/wp\/v2\/posts\/21233\/revisions\/21237"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/wearekemb.com\/en\/wp-json\/wp\/v2\/media\/21582"}],"wp:attachment":[{"href":"https:\/\/wearekemb.com\/en\/wp-json\/wp\/v2\/media?parent=21233"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wearekemb.com\/en\/wp-json\/wp\/v2\/categories?post=21233"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wearekemb.com\/en\/wp-json\/wp\/v2\/tags?post=21233"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}