Two numbers from the same survey describe the state of artificial intelligence (AI) in European business in October 2026, and they do not agree. Asked whether their company uses AI, roughly 70% of the 6,000 euro-area firms in the European Central Bank (ECB) Survey on the Access to Finance of Enterprises say yes. Asked whether that use is significant, 7% say yes. Other measures bracket the pair. Eurostat, which counts only enterprises with ten or more employees that deploy one of the AI technologies on its list in their operations, finds 20.0% across the Union in 2025, up from 13.5% in 2024. A global survey of executives, reported by the Stanford AI Index, finds AI in use in at least one business function at 88% of organisations, 91% in Europe, and generative AI at 70%. In the same survey's 2026 edition, 6% of organisations attribute an earnings effect of 5% or more to AI. Among employees, three-quarters of white-collar staff without managerial responsibilities in a 14-market survey already use AI regularly. Use is broad, and generative AI is the main reason it became broad so quickly. However, use that becomes significant adoption, or that shows in the accounts, is rare. The distance between the two is what this article calls the value gap.

Since 27 July 2026 that gap has a calendar attached. Regulation (EU) 2026/1744, the Digital Omnibus on AI, fixed the dates by which European companies must have documented, overseen and auditable AI systems in hiring, credit, insurance and worker management: 2 December 2027 for the use cases listed in Annex III, the AI Act's list of high-risk systems under Article 6(2), and 2 August 2028 for AI embedded in regulated products. Legacy content-marking and two new prohibitions fall due on 2 December 2026. Firms that treat these dates as a legal project will arrive with a binder. Firms that use them to close the value gap will arrive with a return.

What it is, where it stands, why it matters

Three things every senior leader needs to understand about generative AI in the enterprise
What it is. Generative AI is the family of systems that produce text, code, images and decisions from a prompt, built on general-purpose models from a handful of vendors and deployed through products such as Copilot, Gemini, ChatGPT and Claude, or bespoke integrations. In EU law it is now a named category. Annex XIV of the AI Act (Regulation (EU) 2024/1689), the new list of codes that fixes the scope of conformity-assessment bodies under Article 30, lists "generative AI systems, including AI systems based on general-purpose AI models" and "emerging technologies, including Agentic AI".
Where it stands. Use is broad and shallow. One in five EU enterprises with ten or more employees uses at least one AI technology, on Eurostat's count. Seven in ten euro-area firms report some use. Three-quarters of white-collar employees in a 14-market survey that includes Spain are regular users, and 84% of companies have not redesigned jobs around it. Task-level gains are large and replicated. Firm-level gains appear only where training, data and workflow redesign accompany the tools. For instance, Danish administrative data find no effect on earnings or hours two years after ChatGPT, and the ECB finds no significant productivity difference between users and non-users on average.
Why it matters. The AI Act's dates are fixed and staggered: transparency and vendor-model enforcement since 2 August 2026, legacy content-marking and the new prohibitions on 2 December 2026, national sandboxes by 2 August 2027, high-risk duties for hiring, credit and worker-management systems from 2 December 2027, and AI in regulated products from 2 August 2028. The work those rules require is the same organisational work the evidence associates with enterprise returns. Meaning, an inventory, human oversight assigned to named people, and documented data.

Everyone uses it. Few firms earn from it.

Analysis: Ahorro Sostenible reads the 2026 evidence as one finding at three scales. At the task, generative AI is already in routine professional use and its gains are measured. At the firm, it has produced returns for a minority with a specific profile. At the economy, it is not visible in European productivity statistics. The consistency is the point: the technology works, and most organisations have not done the work that makes it pay yet. Figure 1 sets the three scales side by side.

One finding at three scales: task, firm, economy Three stacked bands. Task level: an AI assistant raises customer-support issues resolved per hour by 15% on average, and enterprise workers report 40 to 60 minutes saved a day. Firm level: 7% of euro-area firms describe their AI adoption as significant, and 6% of organisations surveyed by McKinsey attribute a material earnings effect to AI. Economy level: the ECB finds no statistically significant average productivity difference between users and non-users, and Danish administrative data rule out effects on earnings or hours larger than 2%. The signal weakens as the unit of measurement widens. One finding, three scales TASK · FIRM · ECONOMY · THE SIGNAL WEAKENS AS THE UNIT OF MEASUREMENT WIDENS TASK Large, replicated gains +15% issues resolved per hour, 5,172 customer-support agents 40–60 minutes saved per worker per day, around 9,000 enterprise workers Brynjolfsson, Li & Raymond, Quarterly Journal of Economics, 2025 · OpenAI, State of Enterprise AI, December 2025 FIRM Returns for a minority with a specific profile 7% of euro-area firms describe AI adoption as significant (70% report some use) 6% of organisations attribute a material earnings effect to AI, unchanged for two years ECB Occasional Paper 395, 2026 · McKinsey, State of AI 2026 ECONOMY Not yet visible in European labour and productivity statistics No statistically significant average productivity difference, AI users vs non-users Earnings and hours within ±2% two years after ChatGPT, 25,000 Danish workers ECB Occasional Paper 395, 2026 · Humlum & Vestergaard, NBER Working Paper 33777, rev. March 2026 Sources as stated on each band. Ahorro Sostenible analysis.
Figure 1. One finding at three scales: task, firm and economy and labour-market effects. Ahorro Sostenible analysis.

According to Eurostat, in 2025, 20.0% of EU enterprises with ten or more employees used at least one AI technology, against 13.5% in 2024: 55.0% of large enterprises, 30.4% of medium-sized, 17.0% of small. Asked why they had not adopted AI after considering it, 70.3% of firms cited a lack of expertise, 53.6% uncertainty about legal consequences and 52.7% data protection. The ECB's Occasional Paper 395, the first harmonised European dataset to separate shallow use from deep adoption, finds on productivity no statistically significant average difference between users and non-users, with gains concentrated in technological sectors.

The task-level gains are not in dispute. Brynjolfsson, Li and Raymond's study of 5,172 customer-support agents, published in the Quarterly Journal of Economics in 2025, finds that an AI assistant raises issues resolved per hour by 15% on average, with the largest gains among the least experienced and small quality declines among the most skilled. The Stanford AI Index 2026 puts measured gains at 14% to 26% in customer support and software development, "with weaker or negative effects in tasks requiring more judgment". OpenAI's enterprise data of December 2025, around 9,000 workers at roughly 100 enterprises, report 40 to 60 minutes saved per worker per day.

What the evidence does not show is that these gains add up by themselves. The cleanest test is Danish. Humlum and Vestergaard linked surveys of 25,000 workers in eleven exposed occupations to administrative records and found "rapid currents under still waters": most employers have chatbot initiatives, workers report time savings and new tasks in content generation, AI oversight and AI integration, yet earnings and recorded hours show "precise null effects", ruling out changes larger than 2% two years after ChatGPT's launch. The same study shows where the gap closes. Where employers do nothing, 7% of workers use chatbots daily. Where employers encourage use and provide enterprise tools and training, 28% do, and 19% save more than an hour a day. Research published through the Bank for International Settlements, the European Investment Bank and Bruegel in February 2026 says the same at firm level: AI adoption among EU firms is associated with roughly 4% higher labour productivity, rising by 5.9 points per additional point of training expenditure and 2.4 points per point of software and data investment. McKinsey's 2026 survey of 1,719 respondents finds that nearly three-quarters of the 6% of organisations with a material earnings effect, defined as 5% or more of earnings before interest and taxes (EBIT), have fundamentally redesigned workflows, against one-quarter of everyone else. Deloitte's January 2026 survey of 3,235 leaders in 24 countries finds that 84% of companies have not redesigned jobs around AI at all.

Analysis: the lineage is older than the technology. Robert Solow observed in 1987 that computers were everywhere except in the productivity statistics. Erik Brynjolfsson and colleagues later showed that the gap closed only where technology was paired with organisational change. The 2026 data put coefficients on the complements. Sampsa Samila and co-authors at IESE Business School add why the curve is steep this time: large language models look simple to the user because their complexity has been relocated to infrastructure, compliance and specialised people, so "competitive advantage no longer stems from mere AI adoption, but from mastering this redistributed complexity". The deferral of regulatory deadlines, examined below, did not move a single one of those coefficients.

20.0%
EU enterprises (10+ employees) using AI in 2025
Eurostat, 2025 survey
7%
Euro-area firms describing AI adoption as significant
ECB Occasional Paper 395, 2026
2 Dec 2027
Annex III high-risk duties apply: hiring, credit, insurance, worker management
Regulation (EU) 2026/1744

The time is saved. Nobody says what to do with it.

The firm-level gap has an exact reflection in the workforce. The AI at Work survey by Boston Consulting Group (BCG), 11,749 white-collar respondents in 14 markets from the United States, the United Kingdom and Germany to India, Japan, Brazil and Spain, published in June 2026, finds that 74% of frontline employees, meaning those without managerial responsibilities, are regular AI users, 23 points more than in 2025. Among regular users, 42% save at least a full working day a week, but 66% receive limited or no guidance on how to use the time. The sharpest result concerns direction rather than tooling: 80% of employees in organisations with strong strategic clarity and limited tools report measurable impact, against 60% where tools are strong and clarity is limited. Across the sample, 88% expect to need major upskilling and 36% feel properly trained.

Value is accruing to the people who direct and verify, not to those who merely use. Microsoft's 2026 Work Trend Index, 20,000 AI-using workers in ten countries, finds that 86% treat AI output as a starting point and that the skills now prized are quality control of AI output (50%) and critical thinking (46%). In US job postings, Alekseeva, Azar, Giné and Samila find that firms adopting AI more intensively post relatively more managerial vacancies, shifted toward stakeholder management, creativity and coordination. The same pattern now starts lower in the organisation. Alejandro Casasempere teaches "Generative AI in the Enterprise" in the Master's in Data Science & Business Analytics at Universidad Francisco de Vitoria. His views on AI, work and the apprenticeship of young professionals have been quoted by El Confidencial (4 October 2026), where he described the junior who "commissions several AI agents to prepare an analysis, reviews what they return, corrects it and answers for the result" as practising, on a small scale, what a manager does with a team: "delegate, supervise and take responsibility".

The hard part is that people are poor judges of when to trust the machine. Shaw and Nave at Wharton, in three preregistered experiments with 1,372 participants, find "cognitive surrender": people adopted the assistant's answers with minimal scrutiny, so accuracy rose 25 points when it was right and fell 15 when it was wrong, while confidence rose either way. Massachusetts Institute of Technology (MIT) researchers working with Commonwealth Bank of Australia find that humans anchor to AI recommendations 60% to 80% of the time, and that asking them to state why they are following a recommendation reduces uncritical reliance without lengthening the task. An MIT working group that interviewed more than 20 companies makes "learn when to trust" and "maintain accountability" two of its ten levers for AI that improves performance.

Analysis: this is where the governance and the productivity questions become one question. Article 4 of the AI Act, the AI-literacy obligation as amended in July 2026, requires providers and deployers to "take measures to support the development of AI literacy" among their staff. The Commission had proposed removing that duty, and the European Parliamentary Research Service (EPRS) valued the saving at €222.75 million a year. Parliament kept it, softened to a standard that "does not require providers or deployers to guarantee any specific level of AI literacy of any individual". Set against the European firm-level finding that training carries the largest productivity coefficient, the firms that comply well with Article 4 will also be the firms that earn the return. Paradoxically, EU institutions debated abolishing the one obligation that pays for itself. Finally they kept it.

One structural consequence of adoption is already visible. Stanford's Digital Economy Lab reported in August 2026 that employment of 22-to-25-year-olds in the occupations most exposed to AI is about 19% below trend, with no comparable gap among experienced workers, primarily through reduced hiring. The authors call these descriptive patterns, not causal estimates. The Federal Reserve Bank of New York attributes 64% of the rise in unemployment among young US graduates to remote work. Alejandro Casasempere's published position in Vozpópuli (28 September 2026) is that the two channels reinforce each other. "AI takes away the tasks people learned from, and distance takes away the mentoring, the closeness and the human contact," he said. Junior work, he said in the same piece, "was never just routine. It was the excuse for someone more experienced to review your analysis, ask why you had chosen that assumption or that working hypothesis, and hand it back with more questions than answers." When the tasks are automated and the office empties, the apprenticeship through which professionals learn to detect error disappears, and the human oversight the law requires becomes formally present and substantively empty. The remedy, he pointed out, is to "turn the junior into the reviewer of what the AI produces: question the result, check it against reliable sources and other tools, and be clear from the start what it is used for and within what limits."

The calendar is fixed. What moved was who pays, and when.

Regulation (EU) 2026/1744 was adopted on 8 July 2026, published in the Official Journal on 24 July (OJ L 2026/1744) and entered into force on 27 July, eight months after the Commission's proposal of 19 November 2025. It left the architecture of the AI Act intact and changed the timing and, in places, the balance between obligation and relief. The high-risk obligations for Annex III use cases, due on 2 August 2026 under the original text, moved to 2 December 2027, and those for AI in regulated products from 2 August 2027 to 2 August 2028.

The AI Act calendar after the Digital Omnibus, with adjacent EU instruments, as at 11 October 2026 A horizontal timeline from mid-2024 to 2030. Above the axis, the AI Act milestones: in force 1 August 2024; prohibitions and AI literacy 2 February 2025; general-purpose AI obligations 2 August 2025; Digital Omnibus in force 27 July 2026; general application with Article 50 transparency and AI Office enforcement 2 August 2026; legacy synthetic-content marking and the new prohibitions 2 December 2026; national sandbox and legacy GPAI compliance 2 August 2027; Annex III high-risk 2 December 2027; Annex I high-risk 2 August 2028; legacy public-authority high-risk systems 2 August 2030. Below the axis, adjacent instruments: Data Act 12 September 2025; Pay Transparency Directive 7 June 2026; Cyber Resilience Act Article 14 on 11 September 2026; Platform Work Directive 2 December 2026; Product Liability Directive 9 December 2026; Cyber Resilience Act full application 11 December 2027. A marker shows today, 11 October 2026. The compliance calendar, as amended AI ACT (REG. 2024/1689, AS AMENDED BY REG. 2026/1744) · ADJACENT EU INSTRUMENTS · AS AT 11 OCTOBER 2026 AI ACT ADJACENT EU INSTRUMENTS 2025 2026 2027 2028 2029 2030 1 Aug 2024 AI Act in force Reg. (EU) 2024/1689 2 Feb 2025 Prohibitions · AI literacy Chapters I–II apply 2 Aug 2025 GPAI model obligations governance · penalties 27 Jul 2026 Digital Omnibus in force Reg. (EU) 2026/1744 2 Aug 2026 General application Art. 50 · enforcement begins 2 Dec 2026 Art. 50(2) legacy marking new Art. 5 prohibitions (ba), (bb) 2 Aug 2027 National sandbox operational legacy GPAI models comply 2 Dec 2027 Annex III high-risk employment · credit · education · biometrics 2 Aug 2028 Annex I high-risk AI in regulated products 2 Aug 2030 Legacy public-authority high-risk systems comply 12 Sep 2025 Data Act applies cloud switching, Art. 23 7 Jun 2026 Pay Transparency Dir. transposition deadline 11 Sep 2026 Cyber Resilience Act Art. 14 reporting 2 Dec 2026 Platform Work Dir. transposition deadline 9 Dec 2026 Product Liability Dir. software is a product 11 Dec 2027 Cyber Resilience Act full application AI Act milestone (operative date) Adjacent instrument (application or transposition date) Date of this analysis
Figure 2. The compliance calendar as amended by Regulation (EU) 2026/1744, with adjacent EU instruments, as at 11 October 2026.

Six dates matter to a board, all from Articles 111 and 113 as amended, and Figure 2 places them alongside the adjacent EU instruments. Since 2 August 2026, the Article 50 transparency duties apply to the systems that article lists, those that interact with people, generate synthetic content, recognise emotions or categorise biometrics, or produce deepfakes, and the AI Office enforces the obligations of general-purpose model providers under Implementing Regulation (EU) 2026/1755, the procedural rules for that supervision. On 2 December 2026, systems placed on the market before August 2026 must mark synthetic content under Article 50(2), and two new letters enter Article 5, the list of prohibited practices: prohibitions on systems that generate non-consensual intimate imagery of identifiable persons and on systems that generate child sexual abuse material, agreed on 7 May 2026 at Spain's request. By 2 August 2027 every Member State must have an operational regulatory sandbox and general-purpose models placed on the market before 2 August 2025 must comply. On 2 December 2027 the obligations of Chapter III, the high-risk regime, apply to the use cases in Annex III. On 2 August 2028 they apply to AI that is a safety component of regulated products. High-risk systems already in use by public authorities before those dates must comply by 2 August 2030.

Annex III was not touched. It still lists systems used for recruitment and selection, for decisions on employment terms, promotion or termination, for allocating tasks and for monitoring and evaluating performance, and systems that evaluate creditworthiness or credit scores, except for fraud detection, and that assess risk and price life and health insurance. A company using AI for those purposes is, in the typical case, operating a system that will be high-risk on 2 December 2027, whoever built it, unless the narrow Article 6(3) derogation for systems that pose no significant risk to health, safety or fundamental rights applies and the assessment is documented.

Three changes define the enterprise's position in the chain. A new Article 4a gives providers and deployers a legal basis to process special categories of personal data, "exceptionally and where strictly necessary", to detect and correct bias. It is the bridge between a Responsible AI policy and the fairness testing Annex III will demand. Article 25(2) now obliges the original provider to cooperate, share information and give technical access when a company becomes the provider by putting its name on a high-risk system, substantially modifying one, or changing a system's intended purpose so that it becomes high-risk, and Annex XII, the transparency information a general-purpose model provider owes to the downstream providers that integrate its model, lists what the integrator is entitled to receive. That entitlement matters: of 30 deployed agents documented by MIT's 2025 AI Agent Index, 25 disclose no internal safety results. Article 75 makes the AI Office exclusively competent, with listed exceptions, for AI systems built on a general-purpose model where model and system come from the same provider or group, and for AI inside very large online platforms. For a deployer, the vendor's product is supervised in Brussels and the deployment by the national market-surveillance authority. Figure 3 places the three changes on the chain.

Three changes that define the enterprise's position in the AI value chain A three-link chain from left to right: the general-purpose model provider, the provider of the AI system, and the deployer, which is the company using it. Three amendments are annotated. Annex XII: the model provider owes the downstream provider the technical information needed for integration. Article 25, paragraph 2: if the company becomes the provider by putting its name on a high-risk system, substantially modifying one, or changing a system's purpose so that it becomes high-risk, the original provider must cooperate, share information and give technical access. Article 4a: providers and deployers gain a legal basis to process special categories of personal data, exceptionally and where strictly necessary, to detect and correct bias. Article 75: the AI Office supervises systems built on a general-purpose model from the same provider or group and AI inside very large online platforms, with listed exceptions; the national market-surveillance authority supervises the deployment. Three changes, one chain REGULATION (EU) 2026/1744 · ARTICLES 4a, 25(2) AND 75 · ANNEX XII · WHERE THE ENTERPRISE STANDS GENERAL-PURPOSE MODEL PROVIDER Trains and places the model on the market (e.g. a US frontier-model vendor) PROVIDER OF THE AI SYSTEM Builds the product on the model. The enterprise itself if it rebrands, substantially modifies or repurposes DEPLOYER The enterprise using the system in hiring, credit, insurance or worker management ANNEX XII · information owed to the downstream provider ART. 25(2) · original provider must cooperate, share information and give technical access ART. 4a A legal basis for bias testing Providers and deployers may process special categories of personal data, "exceptionally and where strictly necessary", to detect and correct bias. The bridge to Annex III fairness testing. ART. 25(2) · ANNEX XII Who owes what along the chain If the enterprise becomes the provider (its name on a high-risk system, a substantial modification, a change of purpose into high- risk), the original provider must cooperate. Annex XII lists the model information owed to downstream providers. ART. 75 Two supervisors, one product AI Office (Brussels): systems built on a general-purpose model from the same provider or group, and AI inside very large online platforms, with listed exceptions. National market-surveillance authority: the deployment. Articles as amended by Regulation (EU) 2026/1744, consolidated text of 27 July 2026. Ahorro Sostenible analysis.
Figure 3. Three changes, one chain: Article 4a, Article 25(2) with Annex XII, and Article 75, as amended by Regulation (EU) 2026/1744. Ahorro Sostenible analysis.

The relief is procedural rather than economic. The new small mid-cap tier brings simplified documentation and a lower fine cap, an extension the EPRS valued at €2.5 million a year across the Union. Penalties are unchanged: up to 7% of worldwide turnover or €35 million for prohibited practices, up to 3% or €15 million for most other obligations. None of this reduces the organisational work, which is where the cost sits. In one documented deployment of an agent for clinical adverse events, MIT's Kate Kellogg found that about 80% of the effort went to data engineering, stakeholder alignment, governance and workflow integration, not to the model.

The AI Act does not stand alone, and the adjacent dates fall first. The Platform Work Directive (Directive (EU) 2024/2831), with its chapter on algorithmic management, must be transposed by 2 December 2026, and the Product Liability Directive (Directive (EU) 2024/2853), which makes software a product, by 9 December 2026, applying to products placed on the market after that date. The Data Act's cloud-switching rights (Regulation (EU) 2023/2854) have applied since 12 September 2025, the Pay Transparency Directive (Directive (EU) 2023/970) was due in national law by 7 June 2026, and the Cyber Resilience Act's reporting duties (Regulation (EU) 2024/2847, Article 14) have applied since 11 September 2026. Article 22 of the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) has governed solely automated decisions since 2018.

Spain, as a worked example. Spain sits a point above the EU average: 21.1% of firms with ten or more employees used AI in the first quarter of 2025, according to the Instituto Nacional de Estadística (INE), up 8.7 points in a year, with micro-enterprises at 13.4%. The Adecco Group's survey of 37,500 workers in 31 countries adds the workforce detail: workers in Spain believe they save 171 minutes a day with AI, and only 38% can confidently measure the impact of their work. Adecco itself calls that belief "disconnected from the productivity gains that employers are seeing in reality". In the domestic legal layer, since 2021, Article 64.4.d) of the Estatuto de los Trabajadores, Spain's Workers' Statute, has given works councils in Spain the right to be informed of the parameters, rules and instructions behind the algorithms or AI systems that affect decision-making. Deployments are supervised by the Agencia Española de Supervisión de la Inteligencia Artificial (AESIA). Plan IA360, presented on 21 September 2026, targets 55% of Spanish firms using AI by 2030, from 21.1% today, backed by a €5 billion public-private AI gigafactory and a €600 million business AI voucher, the Bono IA.

Analysis: the financial sector will feel the calendar twice, and the ECB has already described the fault line. In Opinion CON/2026/10 of 13 March 2026, the ECB noted that it has no market-surveillance mandate under the AI Act, asked for a legal basis to share prudential information with the authorities that do, requested that generalised linear models used in credit scoring be excluded from the high-risk definition, and warned that internal models under the Capital Requirements Regulation (Regulation (EU) No 575/2013) and credit-scoring systems under Annex III are "closely interlinked" and will "most likely" be assessed by two authorities at different points in time. If nothing changes, a bank preparing for December 2027 should expect exactly that: two supervisors, two clocks, one model.

The value gap is not a technology or a regulation gap. It is a people gap. The AI Act asks firms to keep a human who can tell when the machine is wrong, and that person is not produced by a compliance manual. For those of us in the management suite leading companies, organisations and institutions, it is our obligation to keep developing people who can think critically without an algorithm. To lead, you need to have been wrong before with something important at stake, and that cannot be downloaded from any app. The returns arrive only where people are trained in values, trusted and accountable. Accompaniment, the patient work of listening, dialogue and feedback that turns a junior into a professional, is not a soft complement to an AI strategy. Today, it is the strategy, and the one input no vendor can sell you.

— Alejandro Casasempere · Managing Partner, Ahorro Sostenible

Four levels of assurance, and the right to leave

Every enterprise deployment of generative AI in Europe rests on a model, a cloud and, usually, a chip that are American. US private AI investment was $285.9 billion in 2025, 23 times China's, by the Stanford AI Index's count. The Commission's answer to that dependency, published on 3 June 2026, defines sovereignty rather than demanding autarky. The proposed Cloud and AI Development Act (COM(2026) 502) sets four sovereignty assurance levels for public procurement, from data processed and stored in EU infrastructure (level 1), through demonstrated independence from third countries and supply-chain transparency (level 2) and EU ownership and control (level 3), to full control of the software supply chain with no third-country interference (level 4). Figure 4 shows the ladder. The same proposal aims to at least triple the Union's data-centre capacity within five to seven years while "the vast majority of the market remains open to our partners". The frame explored in The Sovereignty Imperative is now a procurement ladder, and demand has moved ahead of the law: 77% of companies in Deloitte's survey already factor an AI solution's country of origin into vendor selection.

The four sovereignty assurance levels proposed for public procurement A four-step ladder rising from left to right. Level 1: data processed and stored in EU infrastructure. Level 2: demonstrated independence from third countries and supply-chain transparency. Level 3: EU ownership and control. Level 4: full control of the software supply chain with no third-country interference. Source: proposed Cloud and AI Development Act, COM(2026) 502, 3 June 2026. Four levels of sovereignty assurance PROPOSED CLOUD AND AI DEVELOPMENT ACT · COM(2026) 502 · 3 JUNE 2026 · PUBLIC PROCUREMENT LEVEL 1 EU infrastructure Data processed and stored in EU infrastructure LEVEL 2 Independence, transparency Demonstrated independence from third countries and supply-chain transparency LEVEL 3 EU ownership and control Ownership and control located in the EU LEVEL 4 Full control Full control of the software supply chain, no third-country interference Source: Commission proposal COM(2026) 502. Ahorro Sostenible analysis.
Figure 4. The four sovereignty assurance levels proposed for public procurement in the Cloud and AI Development Act (COM(2026) 502, 3 June 2026). Ahorro Sostenible analysis.

Analysis: for a company, the ladder is a vocabulary for a contract. A board can state on which level each AI dependency sits, and the Data Act's switching rules are how it moves between levels. Four facts bear on the choice of vendor. On the European side, the General-Purpose AI Code of Practice, the European Commission's voluntary code under the AI Act, has 22 confirmed signatories including Anthropic, OpenAI, Microsoft, Google, Amazon, IBM and Mistral AI. xAI has signed only the safety chapter and Meta is not on the list. On the US side, policy changes quarterly: the Bureau of Industry and Security of the US Department of Commerce rescinded the AI Diffusion Rule on 13 May 2025 and since 14 January 2026 reviews H200 and MI325X exports to China case by case, with no criterion weighing allied supply. In Washington, the White House's Executive Order 14365 of 11 December 2025, "Ensuring a National Policy Framework for Artificial Intelligence", set a litigation task force against the AI laws of US states. A European firm planning its inference capacity on a single US provider is planning on a US policy it does not control. Switching optionality has moved from a procurement footnote to a board-level risk item. Europe's one durable asset in this contest is trust: the Stanford Index finds that, across surveyed countries, the EU is trusted more than the United States or China to regulate AI effectively.

The contested terrain

From Eurostat and the ECB to the Commission, the EPRS, the universities, the consultancies and the vendors, five contradictions recur. They define the choices institutions must make now.

Contradiction Position A Position B Why They Disagree
How many European firms "use AI" 20.0% of EU enterprises with 10+ employees deployed at least one AI technology in 2025; Spain 21.1% (Eurostat; INE) About 70% of euro-area firms report some AI use; 88% of surveyed organisations worldwide; 74% of frontline employees are regular users (ECB; Stanford AI Index; BCG) Unit and definition. Eurostat counts the enterprise deploying a defined technology; the ECB asks a finance officer whether the firm uses AI at all; BCG asks the employee. The ECB's own split, 70% some use against 7% significant, reconciles them.
Whether generative AI is producing returns 79% of executives say AI has improved productivity and will contribute significantly to revenue by 2030; 80% of McKinsey respondents report higher individual productivity; workers believe they save an average of two hours a day, 171 minutes in Spain (IBM Institute for Business Value; McKinsey; Adecco) Only 24% of the same executives can see where that revenue will come from; 37% of organisations report any EBIT effect and 6% a material one; Danish administrative data show no effect on earnings or hours larger than 2%; the ECB finds no significant average productivity difference (IBM Institute for Business Value; McKinsey; Humlum and Vestergaard; ECB Occasional Paper 395) Level of measurement. Individual time saved is real; it reaches the profit and loss account only where work is redesigned around it, and 84% of companies have not redesigned jobs (Deloitte). The vendor narrative has itself moved, from "Now Comes the Hard Part" (Microsoft, 2024) to "Agents, human agency" (2026).
Regulation as the main brake 53.6% of EU firms that considered AI cite unclear legal consequences; the European Commission framed the Omnibus as burden relief worth up to €429.5m a year (Eurostat; European Commission via EPRS) 70.3% cite lack of expertise, above legal uncertainty; the EPRS attributes the deferral to missing standards, authorities and tools, not to the rules (Eurostat; EPRS) Institutional framing. Competitiveness actors foreground compliance cost; the statistical evidence foregrounds skills; the European Parliament's research service, the EPRS, reads the deferral as an implementation fix.
What AI sovereignty requires Sovereignty is assurance and optionality: four procurement levels, switching rights, "the vast majority of the market remains open to our partners" (European Commission, Cloud and AI Development Act) Sovereignty is infrastructure: a €5bn gigafactory, a state-backed model family, "Made in EU" requirements in public procurement (Plan IA360; European Commission, Industrial Accelerator Act proposal) Scale and geopolitics. Both respond to a US federal posture that challenges the AI laws of US states and licenses frontier chips to China without weighing allied supply. Both agree that trust and assurance are the licence to scale, and 77% of companies already weigh country of origin (Deloitte).
How many firms use AI agents 35% of organisations have adopted agentic AI and a further 44% plan to; 23% use it at least moderately today and 74% expect to within two years (MIT Sloan Management Review and BCG, November 2025; Deloitte, January 2026) AI agent deployment is "in single digits across nearly all business functions"; only 21% of companies have a mature governance model for agents; of 30 deployed agents documented, 25 disclose no internal safety results (Stanford AI Index 2026; Deloitte; MIT AI Agent Index) Unit and population. Executive surveys count any organisation with a pilot; the Index counts deployment by business function. The gap between the two is the same adoption-to-value gap one layer up, with less governance and less disclosure.

What is settled, contested, and still open

Generative AI in the European enterprise: State of Play, October 2026
Task-level gains are large and replicated (15% in customer support; 40–60 minutes a day). Adoption is deep in few firms and shallow in many (20% deployment, 70% some use, 7% significant; 84% without job redesign). Size and skills, not regulation, predict adoption (55% large against 17% small; expertise 70% against legal uncertainty 54%). Complementary investment determines the return (+5.9 points per training point; 28% daily use and 19% saving over an hour a day where employers encourage, equip and train, against 7% daily use where they do nothing). The calendar is fixed: 2 Dec 2026 (content marking for systems already on the market and the two new prohibitions), 2 Aug 2027 (national sandboxes and legacy general-purpose models), 2 Dec 2027 (Annex III high-risk duties, including hiring, credit and worker management), 2 Aug 2028 (AI in regulated products, Annex I) and 2 Aug 2030 (legacy high-risk systems of public authorities).
Whether the delegation-heavy pattern of enterprise use (64% of business conversations through Anthropic's application programming interface are directive, in the Anthropic Economic Index) is a transitional phase before work is redesigned or the start of structural substitution of entry-level professional work. Whether regulatory deferral changes investment behaviour or only buys time. Whether sovereignty means owning the stack or preserving the option to switch.
How much "adoption" is deployment governed by the enterprise and how much is employee-initiated use nobody has inventoried, to which Article 50 and Annex III attach duties regardless. Who finances professional apprenticeship once junior tasks are automated. Whether Data Act switching rights become real optionality before December 2027.

The limits of what we know

What is established beyond reasonable doubt: generative AI makes individual tasks faster and, in controlled settings, better. The gains do not aggregate to the enterprise without purpose-driven training, data and workflow redesign. The European regulatory calendar is now fixed in operative law rather than in commentary.

What remains contested: the size of the macroeconomic effect, which the International Monetary Fund's July 2026 update credits without quantifying. The direction of the labour-market effect for entry-level professionals. Whether the Omnibus deferral will register in any investment series at all.

The single most important unanswered question: not whether generative AI creates value, which it does at task level, but what organisational design converts task-level gains into enterprise returns before the 2027 clock forces firms to document systems they have not yet learned to govern. Understanding the gap between individual productivity and corporate impact is no longer optional. The shortage is not of tools or of briefings, but of people who can lead with perspective, verify and govern the AI systems their companies already use.

What this means for your organisation

Fourteen months separate this analysis from 2 December 2027. Boards go first: a March 2026 paper by Samila and co-authors from IESE Business School, the Board AI Institute and Egon Zehnder observes that AI governance "fails in two directions", under-engagement that leaks value and over-acceleration that destroys it.

Analysis: Ahorro Sostenible would use the fourteen months in a fixed order beneath that frame, set out in Figure 5. First, inventory: list every AI system in use, including the consumer tools employees adopted on their own, and map each against Article 5, Article 50 and Annex III as amended. Second, ownership: name a human accountable for each system, with the authority to stop it. MIT's Center for Information Systems Research reports the same rule from practice: at One New Zealand, "deployed AI agents must have a named human agent owner to ensure accountability for outcomes and learning". For high-risk systems the AI Act's Articles 14 and 26 require effective human oversight assigned to natural persons with "the necessary competence, training and authority". Third, data: document provenance and run the bias testing Article 4a now permits, before a hiring or credit system becomes high-risk. Fourth, vendor position: establish for each dependency which sovereignty assurance level it sits on, what Annex XII entitles the firm to receive from the model provider, and what Data Act switching would cost. Fifth, people: treat Article 4 as an investment line rather than a compliance line, because training carries the largest coefficient in the European firm-level evidence, and build in the pause that keeps judgment in the loop. Firms that do this will arrive at the deadline with the organisational design the evidence rewards. Firms that outsource it to a legal checklist will arrive compliant and no richer. In generative AI as in The Digital Euro: Who Controls Europe's Money?, the cost of arriving late is not measured in fines. It is measured in the return that was available and never collected.

Fourteen months, five steps in a fixed order Five numbered steps from left to right, ending at 2 December 2027. One, inventory: list every AI system in use, including employee-adopted consumer tools, and map each against Article 5, Article 50 and Annex III. Two, ownership: name a human accountable for each system with the authority to stop it, as Articles 14 and 26 require for high-risk systems. Three, data: document provenance and run the bias testing Article 4a permits. Four, vendor position: establish each dependency's sovereignty assurance level, what Annex XII entitles the firm to receive, and the cost of Data Act switching. Five, people: treat Article 4 AI literacy as an investment line and build in the pause that keeps judgment in the loop. Fourteen months, five steps, one order WHAT A BOARD DOES BEFORE 2 DECEMBER 2027 · ARTICLE REFERENCES TO REG. (EU) 2024/1689 AS AMENDED 1 Inventory Every AI system in use, including consumer tools adopted by staff on their own. Map each against Art. 5, Art. 50 and Annex III. Arts. 5, 50 · Annex III 2 Ownership A named human, accountable for each system, with authority to stop it. Competence, training and authority for high-risk use. Arts. 14, 26(2) 3 Data Document provenance. Run the bias testing Art. 4a now permits, before a hiring or credit system becomes high-risk. Art. 4a · Annex III 4 Vendor position For each dependency: its sovereignty assurance level, what Annex XII entitles the firm to receive, and the cost of Data Act switching. Art. 25(2) · Annex XII 5 People Treat AI literacy as an investment line, not a compliance line. Build in the pause that keeps judgment in the loop. Art. 4 2 December 2027 · Annex III high-risk obligations apply Publication Analysis and sequence proposed by Ahorro Sostenible. Legal references from the AI Act as amended by Reg. (EU) 2026/1744.
Figure 5. Roadmap, from inventory to people. Ahorro Sostenible analysis.

FAQ, answered

Any further questions? Let us know.

When do AI Act obligations apply to companies using generative AI?

On a staggered timetable. Obligations for providers of general-purpose AI models have applied since 2 August 2025, with the AI Office's enforcement powers since 2 August 2026. The Article 50 transparency rules have applied to the categories of system that article lists since 2 August 2026, and systems generating synthetic content that were already on the market have until 2 December 2026 to comply with Article 50(2). Two new prohibitions apply from 2 December 2026. High-risk obligations for Annex III systems, including hiring, credit, insurance and worker management, apply from 2 December 2027, and for AI in regulated products under Annex I from 2 August 2028 (Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744).

Does the Digital Omnibus remove the duty to train staff in AI?

No. Article 4, in force since 2 February 2025, was kept. It requires providers and deployers to take measures to support AI literacy among their staff and the other people who use AI systems on their behalf, taking account of their technical knowledge, experience, education and the context of use, without guaranteeing a specific level for any individual.

Is a company that uses a vendor's AI system a "provider" under the AI Act?

Normally it is a deployer. Under Article 25(1) it becomes the provider if it puts its own name or trademark on a high-risk system already on the market, makes a substantial modification to a high-risk system, or changes the intended purpose of a system that was not high-risk so that it becomes high-risk. In those cases Article 25(2) obliges the original provider to cooperate and to make available the information, technical access and assistance needed to meet the new provider's obligations, including conformity assessment.

What separates the firms that earn a return from generative AI from those that only use it?

Organisational design, not tooling. Nearly three-quarters of the 6% of organisations with a material earnings effect have redesigned workflows, against one-quarter of the rest, while 84% of companies have not redesigned jobs at all. Among EU firms, productivity rises with training expenditure and with software and data investment, not with adoption alone.

How should a Chief Financial Officer read the productivity claims around generative AI?

By unit of measurement. Task-level gains of 15% in customer support are replicated. At firm level only 7% of euro-area firms call their adoption significant and 6% of organisations report a material earnings effect. At economy level, the ECB finds no statistically significant average productivity difference between users and non-users in its sample, which is not the same as no effect in any firm. Capitalise the task savings only where the workflow that converts them has been built.

As a corporate lawyer, which uses of generative AI become high-risk on 2 December 2027?

Those listed in Annex III: recruitment and selection, decisions on employment terms, promotion or termination, task allocation and performance monitoring, creditworthiness and credit scoring of natural persons (except fraud detection), and risk assessment and pricing in life and health insurance. Classification follows the system's intended purpose and Article 6. Whoever is the provider must document any Article 6(3) assessment that takes the system out of the high-risk class. Otherwise Chapter III applies to the system and Article 26 to its deployer.

What is a company that integrates a vendor's model entitled to know about its technology?

If it integrates a general-purpose model into an AI system of its own, it is a downstream provider, and Annex XII lists what the model provider owes it: the tasks the model is intended to perform, its architecture and number of parameters, the modality and format of inputs and outputs, the technical means required for integration, and information on the data used for training, testing and validation, subject to the Act's protection of trade secrets. A company that only uses a finished application is a deployer and relies on its contract. If the integrator becomes a provider under Article 25, the original provider must also cooperate. Of 30 deployed agents documented by MIT's AI Agent Index, 25 disclosed no internal safety results, so the entitlement has to be exercised.

What is still moving in Brussels and Madrid that could change these obligations?

The harmonised standards and Commission guidelines whose absence the EPRS identifies as the reason for the deferral. The Cloud and AI Development Act, still a proposal. The Commission's first annual assessment of Annex III and the prohibited practices under Article 112(1), published on 20 May 2026, which proposed no new Annex III category. Spain's Plan IA360, a roadmap of actions for the following twelve months presented on 21 September 2026. The application dates themselves are in Article 113 and move only by a new regulation.

Why may a bank's credit-scoring model be assessed twice?

ECB's Opinion CON/2026/10 warned that internal models under the Capital Requirements Regulation and credit-scoring systems under Annex III are "closely interlinked" and will "most likely" be assessed by two authorities at different points in time, and asked for a legal basis to share prudential information with AI Act market-surveillance authorities. How much overlap a given model faces depends on its function and governance.

Which route applies to AI in a hospital or a medical device?

AI that is a medical device, or a safety component of one, follows the Annex I route from 2 August 2028 where the medical-device legislation requires third-party conformity assessment. Emergency healthcare patient triage systems are named in Annex III, point 5(d), and fall due on 2 December 2027. Other clinical tools are classified by intended purpose. In one documented clinical deployment, about 80% of the effort went to data, governance and workflow integration rather than to the model.

Does the AI Act reach the operation of energy networks?

Yes, in defined cases. Annex III lists AI intended to be used as a safety component in the management and operation of critical digital infrastructure and in the supply of water, gas, heating and electricity, due on 2 December 2027. A forecasting or customer-service tool is not high-risk on that ground. The sector also sits on the other side of the sovereignty question: the proposed Cloud and AI Development Act aims to at least triple the Union's data-centre capacity, and, for instance, Spain's Plan IA360 ties data-centre deployment to energy and environmental standards.

What is the public-authority calendar?

The ordinary dates apply to new systems. For high-risk systems already in use by public authorities before Chapter III applies, Article 111(2) gives providers and deployers until 2 August 2030 to comply. Annex III systems are registered in the EU database under Article 49, with public-authority deployers registering their own use. The four sovereignty assurance levels proposed in the Cloud and AI Development Act are written for public procurement, so contracting authorities would be the first to apply them if the proposal is adopted.

How does the AI Act treat AI in universities and training providers?

Annex III lists AI used to determine admission, evaluate learning outcomes, assess the appropriate level of education or monitor prohibited behaviour during tests, due on 2 December 2027. Article 4 applies to a university or training provider in its capacity as provider or deployer of AI. In Spain, Plan IA360 announces the adaptation of the secondary and vocational-training curriculum to the use of AI.

What does Article 50 require of a media company that publishes AI-generated content?

It depends on the company's role. Providers of generative systems must ensure that synthetic audio, image, video and text are marked in a machine-readable, detectable way, and providers of systems that interact with people must make that clear unless it is obvious. Deployers must disclose deepfakes, and AI-generated text published to inform the public on matters of public interest unless it has had human review and someone holds editorial responsibility. These duties have applied since 2 August 2026, and systems on the market before that date must mark synthetic content from 2 December 2026. The Commission's voluntary code of practice on marking and labelling, with a set of EU icons, is a compliance tool, not a substitute for the article.

Does the AI Act apply directly to AI in vehicles?

Only in part. Motor vehicles, two- and three-wheelers, agricultural vehicles and rail sit in Section B of Annex I, and Article 2(2) applies only a short list of the Act's articles to them, so the high-risk requirements reach vehicle AI through type-approval law rather than directly. The manufacturer's own uses of AI in hiring, worker management or credit remain Annex III systems like any other company's.

Is defence and military AI inside the AI Act?

No. Article 2(3) excludes systems placed on the market or used exclusively for military, defence or national-security purposes, and the Omnibus left that line untouched. A supplier in both markets assesses each system and deployment separately: the exclusively military version is outside the Act, the civil one inside. Civil aviation, including unmanned aircraft, is listed in Section B of Annex I and follows the sectoral route.

What changes for a retail company's customer service built on generative AI?

The task-level gains are the best documented in the literature: 15% more issues resolved per hour in a study of 5,172 agents. The duties are transparency, under Article 50, for a chatbot that interacts with customers unless it is obvious that it is AI, and liability under the Product Liability Directive, which treats software as a product and applies to products placed on the market after 9 December 2026.

Where does AI in real estate property and mortgage decisions fall?

AI that evaluates the creditworthiness of a natural person for a mortgage is an Annex III system from 2 December 2027. Valuation and tenant-facing tools are not listed in Annex III, but they remain subject to other law: Article 22 of the GDPR restricts decisions based solely on automated processing that produce legal or similarly significant effects, subject to its exceptions and safeguards, and customer-facing chatbots fall under Article 50.

What should AI due diligence on a portfolio company cover?

Board governance frames four things from this article. An inventory of every AI system in use, including employee-adopted tools. Whether the company is a deployer or has become a provider under Article 25 by putting its name on a high-risk system, substantially modifying one, or changing a system's purpose so that it becomes high-risk. The sovereignty assurance level of each dependency, a framework the Cloud and AI Development Act proposes for public procurement and a useful vocabulary for private buyers, 77% of whom already weigh country of origin in vendor selection. Whether a named human owns each system, a governance practice Ahorro Sostenible recommends rather than a literal requirement of the Act.

Is the regime lighter for a small or mid-sized family business?

Small and medium-sized enterprises and, since the Omnibus, small mid-cap enterprises have simplified technical documentation, a lower fine cap and priority access to the regulatory sandboxes, without relief from the substantive duties where a system is high-risk. The evidence is the same for every size: training expenditure carries the largest productivity coefficient in the European firm-level evidence, and Article 4 makes AI literacy an obligation on every provider and deployer. In Spain, the Bono IA announced in Plan IA360 is aimed at SMEs and the self-employed, subject to the call conditions.

Alejandro Casasempere, Managing Partner of Ahorro Sostenible

About the author

Alejandro Casasempere is Managing Partner of Ahorro Sostenible, a precision advisory firm integrating strategy, finance, law, technology, data & AI and institutional affairs into a single practice. He has more than 20 years of professional experience across these disciplines, working alongside leaders from Madrid, Brussels and New York. Connect on LinkedIn.