u/GovixFounder

▲ 21 r/ciso+1 crossposts

EU AI Act enforcement hits August 2026 — what are mid-market companies actually doing to prepare?

Curious what people are seeing in the field. Most companies I've spoken with fall into three buckets:

  1. Unaware — don't realize the Act applies to them even if they have EU customers or operations
  2. Aware but paralyzed — know they need to do something but don't know where to start
  3. Spreadsheet governance — tracking AI tools in Excel and hoping that's enough

The practical starting point that seems to work is a proper AI inventory — just knowing what AI systems you have, what data they touch, and who owns them. That alone gets you 40% of the way there.

NIST AI RMF is the cleanest US-friendly framework to structure around. The four functions — Govern, Map, Measure, Manage — map reasonably well to EU AI Act requirements too.

What are you seeing? Anyone found tools or approaches that actually work at mid-market scale without requiring a six-month consulting engagement?

reddit.com
u/GovixFounder — 9 days ago