Skip to content

EU AI Act: Why Most Firms Aren’t Ready for Compliance

The EU AI Act is transforming how organizations approach AI governance, with strict transparency requirements and significant penalties for non-compliance. A recent analysis reveals the challenges firms face in demonstrating regulatory readiness, particularly in communications surveillance and evidence management.

Editor, Lazyfounder

Published 6 min read
EU AI Act: Why Most Firms Aren’t Ready for Compliance
Image: (Image credit: Getty Images) via source

The EU AI Act is transforming how organizations approach AI governance, with strict transparency requirements and significant penalties for non-compliance. A recent analysis reveals the challenges firms face in demonstrating regulatory readiness, particularly in communications surveillance and evidence management.

30 SEC SUMMARY

  • The EU AI Act imposes strict transparency and compliance requirements for organizations using AI, with fines up to €35 million or 7% of global turnover.
  • Only 19% of organizations globally have the controls to prove compliance for AI-driven communications.
  • Comms surveillance is critical for demonstrating regulatory readiness and connecting evidence to outcomes.
  • Fragmented evidence chains across systems create challenges in meeting regulatory expectations.
  • Regulators demand proof of how risks are identified, reviewed, and escalated, not just the existence of controls.

TABLE OF CONTENTS

  • Regulatory Demands Under the EU AI Act
  • Compliance Gaps in AI-Driven Communications
  • The Role of Comms Surveillance in Compliance
  • Moving Toward Unified Governance
  • Background: Why the EU AI Act Matters
  • What this means
  • Key takeaways
  • FAQ
  • Sources

KEY HIGHLIGHTS

  • The EU AI Act imposes fines of up to €35 million or 7% of global turnover for non-compliance.
  • Only 19% of organizations globally have the controls to prove compliance for AI-driven communications.
  • Comms surveillance is critical for demonstrating regulatory readiness and connecting evidence to outcomes.
  • Regulators expect firms to show how risks are identified, reviewed, and escalated, not just that controls exist.
  • Fragmented evidence chains across systems create challenges in meeting regulatory expectations.

Regulatory Demands Under the EU AI Act

According to TechRadar, the EU AI Act introduces stringent transparency requirements for organizations using AI, particularly in communications surveillance. Firms must demonstrate not only the existence of compliance controls but also how these controls operate in practice when risks emerge. This shift places a significant burden on organizations to prove their regulatory readiness.

Non-compliance with the EU AI Act can result in fines of up to €35 million or 7% of global turnover, making AI governance a critical priority for businesses operating in the EU.

Compliance Gaps in AI-Driven Communications

TechRadar reports that only 19% of organizations globally have the necessary controls to prove compliance for AI-driven communications. This gap highlights a major vulnerability, as regulators increasingly expect firms to provide clear evidence of how risks are identified, reviewed, and escalated.

Many organizations struggle with fragmented evidence chains, which are spread across disparate systems and workflows. This fragmentation makes it difficult to compile and present compliance evidence quickly and clearly, especially during regulatory inquiries.

The Role of Comms Surveillance in Compliance

Comms surveillance has evolved from a basic monitoring function to a core component of regulatory compliance, according to TechRadar. It is now essential for demonstrating how risks are managed and how supervisory outcomes are achieved.

Traditional compliance metrics, such as the number of alerts generated or cases escalated, are no longer sufficient. Regulators expect firms to explain the reasoning behind decisions, including why a risk was flagged, how it was reviewed, and what evidence supported the outcome.

Without a unified evidence layer, organizations cannot confidently demonstrate what AI tools produced or who reviewed it, leaving them exposed to regulatory scrutiny.

Moving Toward Unified Governance

TechRadar highlights that organizations are increasingly adopting a unified approach to communications governance, surveillance, investigations, and retention. This shift aims to address the fragmentation in evidence chains and improve operational visibility.

Operational visibility is now as important as data capture for compliance teams. Firms must be able to demonstrate how risks are identified, investigated, and supervised over time to meet regulatory expectations.

Background: Why the EU AI Act Matters

The EU AI Act is part of a broader trend of regulatory frameworks aimed at increasing transparency and accountability in AI usage. Similar to other data protection and technology regulations, it reflects growing concerns about the ethical and operational risks of AI-driven systems.

For organizations, this means adapting to a landscape where compliance is not just about avoiding penalties but also about building trust with stakeholders. The Act’s focus on evidence chains and operational visibility aligns with global regulatory expectations, including those in the U.S. and Asia.

What this means

Lazyfounder analysis — our interpretation, not reported fact.

The EU AI Act represents a fundamental shift in how organizations must approach AI governance. For founders and operators, compliance is no longer about ticking boxes—it’s about building transparent, auditable processes that demonstrate how risks are managed in practice. The fact that only 19% of organizations have the controls to prove compliance for AI-driven communications is a wake-up call. Many firms have treated compliance as an afterthought, relying on siloed systems that can’t withstand regulatory scrutiny.

The focus on how controls operate, not just their existence, reflects a broader trend in regulation. Regulators are no longer satisfied with policies that look good on paper but fail in practice. For startups, this creates both a risk and an opportunity. The risk is clear: non-compliance can result in massive fines and reputational damage. The opportunity lies in turning compliance into a competitive advantage. Firms that invest in unified governance, operational visibility, and clear evidence chains will not only avoid penalties but also build trust with customers, investors, and partners.

However, many startups lack the resources or expertise to implement these systems effectively. Off-the-shelf compliance tools may not address the unique risks of AI-driven workflows, and custom solutions can be expensive. This is where collaboration with specialized providers—or even proactive engagement with regulators—could make a difference. The key takeaway? Compliance is no longer just a legal issue; it’s a product and operational issue. Ignoring it won’t just lead to fines—it could jeopardize the entire business.

Key takeaways

  • The EU AI Act introduces strict transparency requirements and fines of up to €35 million or 7% of global turnover for non-compliance.
  • Only 19% of organizations globally have the controls to prove compliance for AI-driven communications.
  • Comms surveillance is now a core component of regulatory readiness, not just a monitoring function.
  • Fragmented evidence chains and lack of operational visibility create compliance challenges.
  • Regulators expect firms to demonstrate how risks are identified, reviewed, and escalated, not just the existence of controls.

FAQ

What is the EU AI Act?

The EU AI Act is a regulatory framework that imposes transparency and compliance requirements on organizations using AI, particularly in high-risk applications. It includes strict penalties for non-compliance, such as fines of up to €35 million or 7% of global turnover.

Why is comms surveillance important for compliance under the EU AI Act?

Comms surveillance helps organizations demonstrate how risks are identified, reviewed, and escalated. Under the EU AI Act, regulators expect firms to show not just that controls exist but also how they operate in practice, making comms surveillance a critical component of compliance.

What are the biggest challenges organizations face in complying with the EU AI Act?

Organizations struggle with fragmented evidence chains, lack of unified governance, and insufficient controls for AI-driven communications. Only 19% of firms globally have the necessary controls to prove compliance, making it difficult to meet regulatory expectations for transparency and operational visibility.

How can organizations improve their regulatory readiness?

Organizations can improve readiness by adopting a unified approach to communications governance, surveillance, and retention. This includes investing in tools that provide operational visibility, connecting surveillance activity to supervisory outcomes, and ensuring evidence chains are clear and auditable.

Related on Lazyfounder

Sources

  1. TechRadar · 2026-09-29
    The regulatory readiness problem hiding in plain sight

This story is an original summary drafted with AI by Lazyfounder from the reporting listed above and checked by automated validation. Facts are attributed to their original publishers; sections marked as analysis are Lazyfounder's. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links, and see our AI policy and corrections policy.

About the author

Editor, Lazyfounder

Tarun Mottlia edits LazyFounders, covering Indian startups, funding rounds, AI and product launches. Every story on the site is AI-assisted and checked against its cited sources before publication.

More stories by Tarun Mottlia

Get the LazyFounder Brief

Startup, funding and AI news in a five-minute read. Join the early-access list.

Lazy Founder - Powered by Blogy.in

Contact us

Have a story tip, correction or partnership idea?

Write to us at tarun.kumar@blogy.in or message us on WhatsApp. We read every message.