This is what Regulation (EU) 2026/1744, adopted on July 8 by the Parliament and the Council, has added to the AI Act’s timeline: the requirements for high-risk systems listed in Annex III—those related to employment, education, justice, and access to essential public services—were originally set to take effect on August 2, 2026. They will now take effect on December 2, 2027.
Since then, the same phrase has been repeated far too often: we have time.
Admittedly, this is a comforting interpretation, but it is false—and not just for legal reasons.
Let’s start with the legal aspects, though. The postponement applies only to one category of systems. The prohibited practices have been banned since February 2025. The transparency requirement under Article 50—which involves informing citizens that they are interacting with a machine and identifying AI-generated content—has been in effect since August 2, 2026, the day the Commission also launched a complaint tool accessible to all citizens. And two additional prohibitions will take effect on December 2.
Let’s take stock of the gap between the regulatory timeline and actual practices within organizations.
Good news: Belgium is ahead of the curve
34.5% of Belgian companies with ten or more employees were using at least one AI technology in 2025, compared to a European average of 20.0% (Eurostat). This ranks Belgium fourth in the EU, behind Denmark, Finland, and Sweden. What the Federal Public Service for the Economy highlighted in June was the trend: 24.7% in 2024, rising to 34.5% a year later.
The other finding is mentioned far less often. 81% of Belgian organizations allow their employees to use AI tools, while only 29% have a written AI policy and 26% have adjusted their cybersecurity strategy since then. These three figures come from the same survey, conducted by Ipsos for Proximus NXT among 403 organizations in February 2026.
The barometer published this summer by Inetum is just as revealing. In fact, 47% of Belgian executives surveyed report using AI without authorization from their management. Executives. Not interns.
Banning it only shifts the problem
Netskope analyzed actual traffic in Europe over a 12-month period, from March 2025 to March 2026. This is a reassuring figure, as the percentage of users employing AI via a personal account for professional purposes dropped from 79% to 43%. However, the figure we’re hearing less about concerns those who switch between personal and work accounts—a group that grew from 7% to 15%.
People haven’t stopped. They’ve learned to switch over, specifically when the official tool refuses access—that is, when the data is most sensitive.
Mapping the current situation remains the right first step, on one condition: that reporting it costs nothing. If an employee thinks that admitting to having uploaded a document to an unauthorized tool will earn them a reprimand in a team meeting, they’ll keep quiet. Your mapping will be inaccurate from day one, and you’ll never know it.
What a policy won’t decide for you
A policy sets out principles. It doesn’t decide, on a Tuesday at 2 p.m., which model should process an agent’s request. Three questions come up constantly, and none of them can be settled once and for all in writing.
- Which model for which task? A study published in *Scientific Reports* compared traditional methods and large language models for classifying administrative texts. Logistic regression on embeddings: 0.0021 Wh for 189 inferences. The best LLM tested: 34.15 Wh. A factor of about 16,000. And the lightest model was also the most accurate. So it’s not a matter of choosing between performance and efficiency. It’s a more expensive tool being used to produce a poorer result. All that’s left is to multiply that by your annual volume of requests.
- What data is sent, where does it go, and when? A public document, an internal memo, and a file containing personal data do not require the same processing or the same hosting. Three classification levels, and for each, a list of approved models. One page is enough, but it’s not worth much unless it’s enforced automatically when the request is sent—without relying on individual judgment.
- How reliable are the results? The EBU and the BBC had journalists from 22 public service media outlets in 18 countries evaluate more than 3,000 responses from AI assistants. Forty-five percent had at least one significant issue, and 20 percent contained a major factual error. In terms of fact-checking, researchers at the University of Pennsylvania found that between 3% and 13% of source references were fabricated—a result that came as a surprise. The agents cited most frequently were also the ones that generated the most fabricated information. The level of scrutiny is therefore calibrated to the stakes involved, and for an administrative act, the requirement to provide a rationale does not become less stringent simply because an AI was involved.
No one knows
Gartner found that only 22% of organizations have deployed AI beyond a single unit, and 11% do not know how much their department spent on AI in 2025.
McKinsey, for its part, reports that 37% report some effect on EBIT, and 6% report an effect of at least five points. Finally, BCG states that only 14% of companies have determined the impact of their AI initiatives on the income statement.
Different methodologies and samples, but the same result: the problem isn’t that AI isn’t delivering results—it’s that almost no one is able to say so. And what can’t be quantified is hard to justify in the next budget.
The Belgian case
In July 2025, thirty-eight federal agencies signed the charter for the responsible use of AI in public services. The commitment is very real.
However, the regulatory framework does not yet exist. Belgium has still not designated its market oversight authority, even though the European deadline was August 2, 2025. The government agreement points to the IBPT, the FPS Economy is coordinating efforts, and a preliminary draft bill has been announced (Senate, written question No. 8-314). To date, nothing has been adopted.
So no one will be telling you what to do for a while. This is bad news in itself if you were counting on the authority to set your roadmap.
What we’re implementing
Our approach is to begin our support with one essential step: identifying actual use cases—including those that no one has reported—classifying the data into three levels, and then selecting two or three useful, measurable use cases with limited risk. These are the ones that will teach you the most. Above all, they’re what will help you secure the mandate you need today from leadership, business units, and IT.
Where we go a step further is by making these decisions actionable. Our Responsible AI Steward acts as a routing hub for your application requests. It determines which model processes which request, based on the nature of the task and the sensitivity of the data. It controls what is sent to an external model—and when. It tracks actual usage, cost, and environmental footprint in a dashboard, broken down by team and use case. It also allows you to fine-tune your own models on your data when recurring usage warrants it.
The effect is immediate. The classification rule outlined in your policy becomes a rule applied to the request. The inventory of AI systems—which regulations will eventually require—is automatically compiled. And when you’re asked what AI costs and what it delivers, the answer is already there.
One point that should not be underestimated is training. Article 4 of the AI Act was rewritten in July. Here’s what it says: “take measures to support it.” This is a relaxation compared to the previous version.
Does this sound familiar?
The question is no longer whether your organization uses AI. It’s about who in your organization decides which model sees which data—and whether that decision is documented and known to everyone, or simply carried out silently, every day, by every employee sitting at their screen.
Every organization has its own context, constraints, and pace.
Let’s talk about yours: often, just one initial conversation is enough to identify concrete steps forward.
Sources
- Regulation (EU) 2026/1744 of July 8, 2026, amending Regulation (EU) 2024/1689 (Digital Omnibus on AI), Official Journal of July 24, 2026, effective July 27, 2026.
- European Commission, entry into force of the AI Act rules and transparency obligations on August 2, 2026.
- Eurostat, The Use of Artificial Intelligence Technologies in the European Union, 2026 edition (ICT Enterprise Survey, data collected in the first quarter of 2025).
- FPS Economy, Belgian Digital Economy Barometer, press release of June 9, 2026.
- Proximus NXT and Ipsos, annual cybersecurity survey, 403 Belgian organizations with more than 10 employees, fieldwork conducted in February 2026.
- Inetum and Institut Bona Fidé, Tech, AI, and Society Barometer, 2,400 executives and managers in France, Belgium, Spain, and Portugal; Belgian section published in July 2026.
- Netskope Threat Labs, Threat Labs Report Europe 2026, telemetry from March 2025 to March 2026.
- Comparing Energy Consumption and Accuracy in Text Classification Inference, Scientific Reports, 2026.
- EBU and BBC, News Integrity in AI Assistants, 22 public service media organizations, 18 countries, 14 languages, October 2025.
- D. Rao, E. Wong, C. Callison-Burch (University of Pennsylvania), “Detecting and Correcting Reference Hallucinations in Commercial LLMs and Deep Research Agents,” arXiv, April 3, 2026.
- Gartner, Survey on AI Scaling, 1,303 respondents, fieldwork January–April 2026, published September 1, 2026.
- McKinsey, The State of AI, 1,719 respondents in 97 countries, published August 25, 2026.
- BCG, survey of 152 CEOs, published on July 22, 2026.
- Charter for the Responsible Use of Artificial Intelligence in Public Services, SPF BOSA and AI4Belgium, signed on July 11, 2025, by 38 federal agencies.
- Belgian Senate, Written Question No. 8-314, response dated November 25, 2025, on the national implementation of the AI Act.
See also: Shadow AI, transforming informal use into a public good.

