There is no published measurement of AI governance readiness among mid-market organisations in the United Kingdom and the DACH region.
That is not a rhetorical opening. It is the finding that produced this report. A structured review of the 2025–2026 evidence base identified fifteen candidate sources on AI governance readiness. One was an authoritative primary source, and it measured skills rather than governance. Every substantive dataset located shares one of two limitations: it measures enterprises with revenues above one billion US dollars, or it measures a different market entirely.
The organisations most exposed to the European Union Artificial Intelligence Act's deployer obligations — firms of roughly fifty to one thousand employees, using AI systems they did not build, without a dedicated compliance function — are the least measured population in the field.
This edition does two things about that. It sets out what the evidence genuinely establishes, with every figure attributed and dated. And it provides the diagnostic instrument that the evidence base lacks, so that organisations can measure themselves against the obligations that actually apply to them.
The Confidence Gap
Two findings, from two independent surveys, do not fit together.
Organisations believe they are prepared. A Conga survey of 1,500 European decision makers in legal and revenue operations found 80% considered themselves very or somewhat prepared to comply with the EU AI Act. Confidence varied by country: 89% in the United Kingdom, 82% in Germany, 68% in France.
Their leaders cannot identify the controls. EY surveyed 975 C-suite leaders across 21 countries, all at organisations with revenues above one billion US dollars, in August and September 2025. Asked to match appropriate controls to five AI-related risks, only 12% answered correctly on average. Chief risk officers — the executives formally accountable for those risks — performed below average, at 11%.
A third dataset points the same way. Littler's 2025 European Employer Survey found that only 18% of organisations described themselves as “very prepared” for the EU AI Act, while 20% were “not at all prepared”.
This is the single most important reason to use a structured diagnostic rather than an internal show of hands. A question that asks “are you prepared?” measures confidence. A question that asks “do you hold a current inventory of every AI system in use, classified by risk tier, with a named owner for each?” measures readiness. The instrument in Section Four asks the second kind of question exclusively.
What Actually Applies, and When
Mid-market organisations frequently assume the EU AI Act governs the companies that build AI systems. The deployer obligations say otherwise: an organisation that uses a high-risk AI system it purchased carries substantive duties of its own.
The European Union timeline
| Obligation | Applies from |
|---|---|
| Article 4 — AI literacy. Staff who interact with AI systems must receive training sufficient to use, interpret and oversee them | Already in force 2 February 2025 |
| Core enforcement by the AI Office and national authorities begins | 2 August 2026 |
| Article 26 — deployer duties for Annex III high-risk use cases | December 2027 |
| Article 26 duties for high-risk systems embedded in regulated products | August 2028 |
The Article 4 date deserves emphasis. The AI literacy obligation has been in force since February 2025. It is not on a future timeline, it applies to deployers rather than only to providers, and it is the obligation most commonly overlooked because it requires no technical change — only evidence that staff were trained.
Article 26, when it bites, implies five operational capabilities for deployers: an inventory of AI systems with risk classification; assigned and documented human oversight; monitoring with log retention of at least six months; incident detection with escalation to providers and market surveillance authorities without undue delay; and demonstrable adherence to the provider's instructions for use.
The United Kingdom position
The United Kingdom has deliberately not enacted horizontal AI legislation. Obligations arrive through three other doors.
The Data (Use and Access) Act 2025 revises the rules on automated decision-making, with a statutory AI and ADM code of practice to follow. Sector regulators set expectations directly: the Financial Conduct Authority remains technology-agnostic but increasingly AI-attentive, and the Information Commissioner's Office published an AI and biometrics strategy update in March 2026. The 2024 UK Corporate Governance Code, Provision 29, effective for 2026 financial years, requires boards to make an annual declaration on the effectiveness of all material controls — financial, operational, reporting and compliance — and to describe any that did not operate effectively.
Provision 29 is the quiet one. It contains no reference to artificial intelligence, and it does not need to: an AI system embedded in a material operational process is covered by a control-effectiveness declaration whether or not anyone has labelled it an AI governance matter.
DACH
Germany's draft Implementation Act for the EU AI Act, released for consultation in September 2025, addresses supervisory architecture and notification procedures rather than adding substantive obligations. The practical signal is that national market surveillance authorities will be operational. No equivalent implementation material for Austria or Switzerland was located in this review.
A note on organisations serving both markets. A UK firm with EU customers faces the EU AI Act extraterritorially and the UK sectoral regime. The instrument below is built for that overlap rather than for one jurisdiction.
What the Evidence Does Not Tell You
Reports of this kind usually present their evidence base as stronger than it is. The honest position here is more useful.
What is well established: the regulatory position, the phasing, and the direction of travel. These are documented in primary sources and are not seriously contested.
What is established only for large enterprises: every substantive readiness dataset located measures organisations far larger than the mid-market. EY's respondents all sit above one billion dollars in revenue. IBM's October 2025 EMEA study reports that 66% of surveyed enterprises achieved significant productivity gains from AI — but breaks down as 72% of large enterprises against 55% of small and medium-sized enterprises. That eighteen-point gap is the clearest published signal that smaller organisations experience AI differently, and IBM does not publish governance metrics segmented by size.
What is not established at all: how mid-market organisations in the UK and DACH actually govern AI. Not the proportion holding a formal policy. Not the proportion with a named owner for AI risk. Not the proportion with any inventory. No located source measures this population.
The Readiness Instrument
Eight dimensions, three questions each. Each question scores 0 to 3. Maximum score 72. Answer honestly — a score that flatters the organisation reproduces the confidence gap described in Section One.
| Score | Meaning |
|---|---|
| 0 | Not in place |
| 1 | Informal or partial; no documentation |
| 2 | Documented and in place; not consistently operated or reviewed |
| 3 | Documented, operated consistently, evidenced, and reviewed within the last twelve months |
Your Score
0 out of 72
Reveal your score and benchmark position
Complete the instrument above, then submit to see your score, your maturity band, and what each band means. Your responses contribute to the first measurement of mid-market AI governance readiness in the UK and DACH — you will receive your position against the aggregate once the sample supports publication.
Interpreting the bands
| Score | Band | What it means |
|---|---|---|
| 0–17 | Exposed | Little governance infrastructure. The immediate priority is Dimension 1 — without an inventory, the other dimensions cannot be evidenced. |
| 18–35 | Aware | Policy exists; operational control does not follow it. Typically strong on Dimension 2, weak on Dimensions 4, 5 and 7. |
| 36–53 | Structured | Governance operates but is not consistently evidenced. Provision 29 declarations and Article 26 evidentiary expectations are the binding constraint. |
| 54–72 | Evidenced | Governance is documented, operated and demonstrable. Focus shifts to maintenance and change detection. |
Two cautions. A high total with a zero in Dimension 1 is not a high score — it is an unevidenced one, because the inventory underwrites four other dimensions. And Dimension 8 is already in force, so a low score there is a present position rather than a future risk.
Method, and What Comes Next
Method. Sources were identified through a structured review of publicly available 2025–2026 material, then screened: every statistic reproduced here was verified against its original publication before inclusion, and figures that could not be verified were excluded rather than hedged. Attribution includes the commissioning organisation, sample size where published, and date. Regulatory statements draw on European Commission guidance, IAPP analysis, the Financial Reporting Council, the Information Commissioner's Office and UK legislation.
The instrument is constructed by mapping deployer obligations — EU AI Act Articles 4 and 26, UK DUAA automated decision-making rules, and Corporate Governance Code Provision 29 — onto measurement domains, cross-referenced with constructs already operationalised in the EY, IBM and PwC studies so that responses will be comparable where comparison is possible.
What this edition does not claim. It does not report original data on mid-market governance readiness, because none exists. It documents that absence and supplies the instrument to address it.
Edition Two. Responses to this instrument will produce the first measurement of AI governance readiness among UK and DACH mid-market organisations. That dataset — not this document — is the contribution.