Edition One · September 2026

The AI Governance Readiness Benchmark 2026

A diagnostic for UK and DACH mid-market organisations

Helium42 · London & Hamminkeln

There is no published measurement of AI governance readiness among mid-market organisations in the United Kingdom and the DACH region.

That is not a rhetorical opening. It is the finding that produced this report. A structured review of the 2025–2026 evidence base identified fifteen candidate sources on AI governance readiness. One was an authoritative primary source, and it measured skills rather than governance. Every substantive dataset located shares one of two limitations: it measures enterprises with revenues above one billion US dollars, or it measures a different market entirely.

The organisations most exposed to the European Union Artificial Intelligence Act's deployer obligations — firms of roughly fifty to one thousand employees, using AI systems they did not build, without a dedicated compliance function — are the least measured population in the field.

This edition does two things about that. It sets out what the evidence genuinely establishes, with every figure attributed and dated. And it provides the diagnostic instrument that the evidence base lacks, so that organisations can measure themselves against the obligations that actually apply to them.

Section One

The Confidence Gap

Two findings, from two independent surveys, do not fit together.

80%
of organisations consider themselves very or somewhat prepared for the EU AI Act
Conga, n=1,500 · 2026
12%
of C-suite leaders correctly matched controls to five AI-related risks
EY, n=975 · Aug–Sep 2025
18%
describe themselves as “very prepared” when asked precisely
Littler · 2025

Organisations believe they are prepared. A Conga survey of 1,500 European decision makers in legal and revenue operations found 80% considered themselves very or somewhat prepared to comply with the EU AI Act. Confidence varied by country: 89% in the United Kingdom, 82% in Germany, 68% in France.

Their leaders cannot identify the controls. EY surveyed 975 C-suite leaders across 21 countries, all at organisations with revenues above one billion US dollars, in August and September 2025. Asked to match appropriate controls to five AI-related risks, only 12% answered correctly on average. Chief risk officers — the executives formally accountable for those risks — performed below average, at 11%.

A third dataset points the same way. Littler's 2025 European Employer Survey found that only 18% of organisations described themselves as “very prepared” for the EU AI Act, while 20% were “not at all prepared”.

The gap is not between organisations that are ready and organisations that are not. It is between confidence and competence inside the same organisations. Self-assessment is measuring the former and reporting it as the latter.

This is the single most important reason to use a structured diagnostic rather than an internal show of hands. A question that asks “are you prepared?” measures confidence. A question that asks “do you hold a current inventory of every AI system in use, classified by risk tier, with a named owner for each?” measures readiness. The instrument in Section Four asks the second kind of question exclusively.

Section Two

What Actually Applies, and When

Mid-market organisations frequently assume the EU AI Act governs the companies that build AI systems. The deployer obligations say otherwise: an organisation that uses a high-risk AI system it purchased carries substantive duties of its own.

The European Union timeline

ObligationApplies from
Article 4 — AI literacy. Staff who interact with AI systems must receive training sufficient to use, interpret and oversee themAlready in force
2 February 2025
Core enforcement by the AI Office and national authorities begins2 August 2026
Article 26 — deployer duties for Annex III high-risk use casesDecember 2027
Article 26 duties for high-risk systems embedded in regulated productsAugust 2028

The Article 4 date deserves emphasis. The AI literacy obligation has been in force since February 2025. It is not on a future timeline, it applies to deployers rather than only to providers, and it is the obligation most commonly overlooked because it requires no technical change — only evidence that staff were trained.

Article 26, when it bites, implies five operational capabilities for deployers: an inventory of AI systems with risk classification; assigned and documented human oversight; monitoring with log retention of at least six months; incident detection with escalation to providers and market surveillance authorities without undue delay; and demonstrable adherence to the provider's instructions for use.

The IAPP's analysis of evidentiary expectations under Article 26 makes a point that shapes this entire benchmark: many smaller organisations lack an AI system inventory, and without one they cannot satisfy any of the obligations that depend on it — oversight, monitoring, log retention or escalation. The inventory is not one requirement among five. It is the precondition for four of the others.

The United Kingdom position

The United Kingdom has deliberately not enacted horizontal AI legislation. Obligations arrive through three other doors.

The Data (Use and Access) Act 2025 revises the rules on automated decision-making, with a statutory AI and ADM code of practice to follow. Sector regulators set expectations directly: the Financial Conduct Authority remains technology-agnostic but increasingly AI-attentive, and the Information Commissioner's Office published an AI and biometrics strategy update in March 2026. The 2024 UK Corporate Governance Code, Provision 29, effective for 2026 financial years, requires boards to make an annual declaration on the effectiveness of all material controls — financial, operational, reporting and compliance — and to describe any that did not operate effectively.

Provision 29 is the quiet one. It contains no reference to artificial intelligence, and it does not need to: an AI system embedded in a material operational process is covered by a control-effectiveness declaration whether or not anyone has labelled it an AI governance matter.

DACH

Germany's draft Implementation Act for the EU AI Act, released for consultation in September 2025, addresses supervisory architecture and notification procedures rather than adding substantive obligations. The practical signal is that national market surveillance authorities will be operational. No equivalent implementation material for Austria or Switzerland was located in this review.

A note on organisations serving both markets. A UK firm with EU customers faces the EU AI Act extraterritorially and the UK sectoral regime. The instrument below is built for that overlap rather than for one jurisdiction.

Section Three

What the Evidence Does Not Tell You

Reports of this kind usually present their evidence base as stronger than it is. The honest position here is more useful.

What is well established: the regulatory position, the phasing, and the direction of travel. These are documented in primary sources and are not seriously contested.

What is established only for large enterprises: every substantive readiness dataset located measures organisations far larger than the mid-market. EY's respondents all sit above one billion dollars in revenue. IBM's October 2025 EMEA study reports that 66% of surveyed enterprises achieved significant productivity gains from AI — but breaks down as 72% of large enterprises against 55% of small and medium-sized enterprises. That eighteen-point gap is the clearest published signal that smaller organisations experience AI differently, and IBM does not publish governance metrics segmented by size.

What is not established at all: how mid-market organisations in the UK and DACH actually govern AI. Not the proportion holding a formal policy. Not the proportion with a named owner for AI risk. Not the proportion with any inventory. No located source measures this population.

A deliberate omission. A widely circulated figure attributing 78% non-compliance to a named consultancy could not be traced to a primary source and does not appear in this report. Neither do figures from a mid-market survey that could not be independently verified and which measures the United States rather than Europe. Statistics that could not be checked against their original publication have been left out, and there are fewer numbers in this report as a result.
Section Four

The Readiness Instrument

Eight dimensions, three questions each. Each question scores 0 to 3. Maximum score 72. Answer honestly — a score that flatters the organisation reproduces the confidence gap described in Section One.

ScoreMeaning
0Not in place
1Informal or partial; no documentation
2Documented and in place; not consistently operated or reviewed
3Documented, operated consistently, evidenced, and reviewed within the last twelve months

Your Score

0 out of 72

Reveal your score and benchmark position

Complete the instrument above, then submit to see your score, your maturity band, and what each band means. Your responses contribute to the first measurement of mid-market AI governance readiness in the UK and DACH — you will receive your position against the aggregate once the sample supports publication.

Interpreting the bands

ScoreBandWhat it means
0–17ExposedLittle governance infrastructure. The immediate priority is Dimension 1 — without an inventory, the other dimensions cannot be evidenced.
18–35AwarePolicy exists; operational control does not follow it. Typically strong on Dimension 2, weak on Dimensions 4, 5 and 7.
36–53StructuredGovernance operates but is not consistently evidenced. Provision 29 declarations and Article 26 evidentiary expectations are the binding constraint.
54–72EvidencedGovernance is documented, operated and demonstrable. Focus shifts to maintenance and change detection.

Two cautions. A high total with a zero in Dimension 1 is not a high score — it is an unevidenced one, because the inventory underwrites four other dimensions. And Dimension 8 is already in force, so a low score there is a present position rather than a future risk.

Section Five

Method, and What Comes Next

Method. Sources were identified through a structured review of publicly available 2025–2026 material, then screened: every statistic reproduced here was verified against its original publication before inclusion, and figures that could not be verified were excluded rather than hedged. Attribution includes the commissioning organisation, sample size where published, and date. Regulatory statements draw on European Commission guidance, IAPP analysis, the Financial Reporting Council, the Information Commissioner's Office and UK legislation.

The instrument is constructed by mapping deployer obligations — EU AI Act Articles 4 and 26, UK DUAA automated decision-making rules, and Corporate Governance Code Provision 29 — onto measurement domains, cross-referenced with constructs already operationalised in the EY, IBM and PwC studies so that responses will be comparable where comparison is possible.

What this edition does not claim. It does not report original data on mid-market governance readiness, because none exists. It documents that absence and supplies the instrument to address it.

Edition Two. Responses to this instrument will produce the first measurement of AI governance readiness among UK and DACH mid-market organisations. That dataset — not this document — is the contribution.

Answered 0 of 24 · running total 0/72