AI Adoption in Businesses Is Outpacing Their Ability to Control It

June 14, 2026

Artificial intelligence is already used daily in companies of all sizes, often without a formal strategy, internal protocols, or clear oversight. Tools like ChatGPT, Copilot, Gemini or Claude have moved from being experimental solutions to being integrated into human resources, customer service, finance, marketing, analytics, or productivity processes.

However, this accelerated adoption occurs at a key moment: the European Union’s Artificial Intelligence Regulation, known as the AI Act, is rolling out obligations progressively and contemplates penalties that can reach €35 million or 7% of a company’s worldwide annual turnover. The Regulation came into effect on August 1, 2024 and since February 2, 2025 the first obligations have applied, including prohibited practices and AI literacy requirements.

To this, there has been a double recent update to the framework: the Digital Omnibus Agreement, reached in Brussels on May 7, 2026, which adjusts the European timetable, and the Spanish AI governance bill approved by the Council of Ministers on May 26, 2026.

From CenteIA Consulting, a division specialized in technology transformation and AI governance for companies, they warn that many organizations have adopted AI before establishing an internal policy, training their teams, or identifying what systems are actually in use within the company. “AI has come into many companies through the back door: first as a productivity tool, then as a daily habit and now as a governance risk,” explains Juan Luis Pascual, CEO of CenteIA Consulting.

The AI Act Is No Longer a Conversation About the Future

The situation becomes especially relevant at a moment when the European Union’s AI Act, the first comprehensive regulation to govern the development and use of artificial intelligence systems based on their level of risk, is no longer a framework for the future but a regulatory reality with progressive effects already in motion. The rule sets obligations for both developers of AI systems and those using third‑party tools within their processes.

Warning, scroll to continue reading

The calendar is already moving. The AI Act came into force on August 1, 2024. Since February 2, 2025 the first provisions have applied, including certain prohibited uses and the AI literacy obligation; and on August 2, 2025 new obligations related to governance and general‑purpose models began to deploy.

On May 7, 2026, within the Digital Omnibus Agreement, the European Parliament and the Council reached a provisional political agreement that re-tunes the timetable: the obligations for high‑risk systems in Annex III, which were due to apply from August 2, 2026, are pushed back to December 2, 2027, and those in Annex I are moved to August 2, 2028. The agreement also introduces a specific prohibition for non‑consensual intimate image‑generation systems. However, this adjustment does not affect the most relevant obligations for most companies: AI literacy, prohibited practices, and the enforcement regime remain fully enforceable.

The big date for many companies will be exactly one year later: this coming August 2, 2026, when much of the Regulation begins to apply and its obligations will continue to roll out progressively in certain high‑risk areas.

The new regulatory framework establishes a risk‑based system and contemplates meaningful penalties for breaches. Violations related to prohibited practices can reach up to €35 million or 7% of worldwide annual turnover; other breaches can reach up to €15 million or 3%; and providing incorrect or misleading information to authorities can incur fines of up to €7.5 million or 1% of turnover.

From the firm, with a presence in Europe and LATAM in AI training, they note that the main problem is not the technology itself, but the speed with which it is being rolled out inside organizations. According to CenteIA’s experience, many organizations are already using AI systems in tasks that directly affect people or important business decisions: from automated hiring processes to financial analysis or scoring tools. “We’re seeing companies that have integrated six or seven AI tools in less than a year, and when we ask who owns the internal responsibility, no one raises a hand. The speed of adoption has clearly outpaced the ability to manage it internally,” says Pascual.

The consequence, the consultancy notes, is a growing mix of risks: potential data leaks, automation without human oversight, regulatory non‑compliance, and reputational exposure.

Garrett Mercer

I cover business, startups, and the companies shaping today’s economy. My work focuses on breaking down complex topics into clear, useful insights, with a strong interest in growth strategies and market shifts. I aim to deliver content that is both informative and easy to understand for a wide audience.

Get in Touch with Our Team
Have a question, a partnership opportunity, or a story to share? Reach out to us and connect with a media platform focused on business insights and growth.