The AI Act Is Live. Half the AI Is Invisible.
Nine days after Europe's high-risk obligations became enforceable, the evidence says roughly half of enterprise AI activity never reaches the security stack that is supposed to prove compliance.
On August 2, the EU AI Act crossed from principle into enforcement. Articles 6 through 49 — the high-risk regime — now bind the systems regulated firms care most about: creditworthiness assessment, credit scoring, insurance risk pricing. The obligations are not aspirational. Traceability, human oversight, conformity controls, and technical documentation must exist and be producible, with penalties reaching 3% of global annual turnover. In the same window, U.S. supervisors replaced SR 11-7 with SR 26-2 — and pointedly carved generative and agentic AI out of scope as "novel and rapidly evolving." Europe is regulating the thing; Washington is still deciding what the thing is.
Not an intent problem — an evidence problem
Almost no regulated institution intends to run ungoverned AI. The trouble is that the register on the compliance team's desk and the traffic on the wire have quietly diverged. Akamai's Enterprise AI Usage Risk Report, published August 5, found that nearly half of enterprise AI use bypasses corporate security controls entirely, that roughly three quarters of AI browser extensions demand high or critical permissions, and that 16.3% of them ship with known CVEs. IBM's 2026 Cost of a Data Breach Report, drawn from 602 organizations, puts the consequence in numbers: shadow AI touched 43% of breached organizations, more than double last year's 20%, and breaches now take 247 days to find and contain. An AI inventory that cannot be reconciled against telemetry is not evidence. It is an assertion.
Source: Akamai Enterprise AI Usage Risk Report 2026; IBM Cost of a Data Breach Report 2026.
What regulated firms should do now
- Discover before you attest. Build the AI system register from network and browser telemetry, not from a departmental survey. A supervisor asking for traceability evidence will test the register against the traffic, and self-reported inventories lose that test every time.
- Treat the browser as a control plane. An extension holding high or critical permissions reads the same authenticated session your customer data lives in. Baseline the estate, remove the 16.3% carrying known CVEs, and allowlist by publisher rather than by popularity.
- Bind every agent to a named owner. Any autonomous action reaching a credit, pricing, or fraud decision needs a scoped credential, a human accountable for it, and a retained log — the same standard your model risk function has applied to models for a decade.
- Close the 247-day gap deliberately. Detection content for AI-specific abuse — prompt injection, tool misuse, anomalous agent-to-agent traffic — should be written and tested now, not after the first incident forces it.
The burden of proof has moved: it is no longer enough for a regulated firm to use AI responsibly — it has to be able to demonstrate it, and no institution can evidence what its controls never saw.
Important links
- Nearly Half of Enterprise AI Use Bypasses Corporate Security — Akamai
- One in Four Malicious Breaches Are AI-Enabled, Costing $6 Million on Average — IBM
- Data Breach Cost 2026 Averaged $4.99 Million, AI Attacks Ran Higher — Help Net Security
- AI Act: What Really Changes on August 2, 2026 — aiacto
- Regulatory Framework for Artificial Intelligence — European Commission