July 2, 2026 3 mins read

Reality Check: What EU AI Act Compliance Actually Looks Like in Practice

Last updated: July 30, 2026

Reading Time: 4 min read

As enforcement dates approach, corporate boardrooms are moving from high-level conversations about AI ethics to the technical realities of regulatory compliance. But what does actual readiness look like across the market?

A benchmark study from the Thomson Reuters Foundation—analysing nearly 3,000 global enterprises through the AI Company Data Initiative (AICDI)—offers an empirical look at corporate progress. The data reveals a clear dynamic: while proactive alignment with the EU AI Act correlates strongly with governance maturity and investor confidence, a substantial policy-to-practice gap persists across major industries.

Here are five key takeaways that every compliance leader, enterprise architect, and risk officer needs to address to achieve true operational readiness.

1. Fundamental Rights Impact Assessments (FRIAs) Are the Largest Exposure Area

Under Article 27, deployers of high-risk AI systems must complete a Fundamental Rights Impact Assessment (FRIA) prior to deployment and notify relevant market surveillance authorities.

Despite this explicit requirement:

  • Fewer than 1 in 4 companies currently disclose a Human Rights Impact Assessment.
  • Only 1 in 3 companies publicly disclose a formal Ethical Impact Assessment.

Operational Reality: FRIAs represent the widest gap between regulatory expectations and enterprise practice. Legal exposure will be highest for organizations that treat FRIAs as generic checklists rather than structured, system-specific risk evaluations.

2. Supply Chains Are the Primary Enforcement Mechanism

You do not need to be headquartered in Brussels to feel the weight of the AI Act. The study reveals that 47% of companies referencing the Act in their corporate disclosures are based outside the EU—with US firms leading the pack.

Compliance expectations are spreading rapidly through enterprise procurement:

  • EU-based buyers are embedding AI Act conformity requirements directly into Requests for Proposals (RFPs), vendor due diligence, and commercial contracts.
  • Third-party software vendors and model providers are being forced to provide verifiable technical documentation, risk management records, and lifecycle guarantees to retain enterprise clients.

3. The “Policy-to-Practice” Gap in Human Oversight

High-level public statements about “responsible AI” are common, but operational documentation remains shockingly thin.

  • Only 12.4% of companies globally have established a formal Human Oversight Policy.
  • Of those that do have a policy on paper, 48% have failed to document the actual operational processes—such as real-time monitoring tools, human-in-the-loop intervention protocols, or emergency override workflows—needed to enforce it.

4. Technical Tracking Infrastructure Is Urgently Needed

Maintaining compliance throughout an AI system’s lifecycle requires comprehensive asset inventory tracking. However, technical governance tools lag behind legal commitments:

  • AI Model Registries—essential databases for tracking training data sources, model versions, system boundaries, and downstream modifications—remain rare.
  • Even among governance-focused companies citing the AI Act, only 19% of EU firms and 21% of non-EU firms have deployed formal model registries. For non-citing enterprises, that figure drops to a negligible 1–2%.

5. Engagement Is a Barometer for Institutional Resilience

For investors, enterprise customers, and board members, engagement with the EU AI Act has become a clear indicator of overall organizational health. Organizations proactively aligning with the framework are demonstrating greater operational maturity, stronger supply chain positioning, and lower long-term liability risks.

Action Items for Compliance Teams

  1. Conduct System-Level FRIAs: Audit high-risk deployments immediately to map potential impacts on fundamental rights, safety, and non-discrimination.
  2. Operationalize Human Oversight: Move beyond static policy statements by building concrete “human-in-the-loop” mechanisms, alert escalation pathways, and intervention protocols into product workflows.
  3. Deploy Enterprise Model Registries: Establish an automated inventory to map every AI model, vendor dependency, data pipeline, and API across your software stack.
  4. Update Vendor Procurement Safeguards: Standardise contractual language to ensure external AI tools satisfy supply chain documentation requirements before integration.