Jeen: EU AI Act Compliance Isn't a Policy Problem, It's an Evidence Problem, New Analysis Finds
As Article 50 enforcement begins, Jeen argues most enterprises can't prove why their AI made a decision, not just that it made one
Regulators are now asking something fundamentally different: can you prove that the policy actually governed the action?”
NEW YORK, NY, UNITED STATES, August 20, 2026 /EINPresswire.com/ -- Jeen, the governed enterprise AI operating layer, today published new analysis arguing that the real risk enterprises face under the EU AI Act isn't the transparency deadline itself, but the audit that follows it. According to Jeen, most organizations can show regulators a policy. Almost none can show a regulator why a specific AI decision happened. — Moti Krispil, Chief Strategy and Growth Officer at Jeen
Article 50 of the EU AI Act, effective August 2, 2026, requires AI systems that interact with EU citizens to clearly disclose their artificial nature. Jeen's analysis emphasizes that although the high-risk system requirements have been postponed to December 2027 and August 2028 under the 2026 Digital Omnibus, organizations still face imminent compliance challenges. The record-keeping standards these systems will ultimately face—combined with Article 26's six-month log retention rule—require enterprises to implement evidence-generating architectures well in advance. Crucially, an audit isn't satisfied with learning what an AI system did; it demands to know why it made each decision.
"Most compliance programs were designed to answer a single question: do we have a policy?" said Moti Krispil, Chief Strategy and Growth Officer at Jeen. "But regulators are now asking something fundamentally different: can you prove that the policy actually governed the action? These are not the same exercise—and no amount of PDF-based governance can close the gap between them."
The Compliance Reality of Fragmented AI Tools
Jeen's analysis points to a widening gap between AI deployment and AI governance. Grant Thornton's 2026 AI Impact Survey of nearly 1,000 senior US business leaders found that 78% lack strong confidence they could pass an independent AI governance audit within 90 days, a finding Grant Thornton calls the "AI proof gap." IBM's 2025 Cost of a Data Breach Report found 63% of organizations still have no formal AI governance policy in place, and Reco's 2025 State of Shadow AI Report found the median unauthorized AI tool remains active inside an enterprise for over 400 days before security discovers it.
Gartner projects that 80% of unauthorized AI transactions in 2026 will trace back to internal policy violations rather than external attacks, underscoring that most enterprises' primary exposure is not a hacker, but an ungoverned workforce moving faster than its own oversight.
Jeen's analysis argues that manually governing this kind of scale is not simply inefficient; it's structurally impossible. A representative enterprise AI estate today can span thousands of agents, a dozen models, and dozens of applications across multiple cloud and on-premises environments, with procurement visibility into only a fraction of it. At that scale, the unit of risk is no longer a single tool. It's the end-to-end action, and no individual vendor API or endpoint control can govern it.
What an Audit Actually Requires
Under Article 12 of the AI Act, evidence of a high-risk AI decision must be generated automatically, at the moment the decision is made, not reconstructed afterward from memory or screenshots. Article 26 compounds this: because deployers must retain logs for at least six months, an audit can reach back across actions taken well before the request arrives. Jeen's analysis warns that enterprises running fragmented AI tools, each with its own log format and retention policy, will have nothing coherent to hand over when that request lands.
The formal financial exposure is significant on its own: fines of up to €15 million or 3% of worldwide annual turnover for many infringements, with higher thresholds reserved for prohibited practices. Jeen's analysis notes the reputational cost may be less bounded. ISACA research has linked weak AI incident-response procedures directly to regulatory exposure, reputational damage, and service continuity risk.
Operationalized Accountability
Jeen positions its Enterprise AI Harness as the structural answer: a governed runtime layer that routes every model call, agent action, and policy check through a single control point, regardless of which underlying model or environment is doing the work. Every enforcement decision, policy version, input, and output is written to an immutable, traceable ledger as it happens.
"You cannot retrofit a 'why' onto a system that was never built to keep one," Krispil said. "The record has to exist because the decision was governed when it was made, not because someone went looking for it afterward. That's what operationalized accountability actually means in practice."
Jeen's analysis frames this as more than a compliance requirement. Because the control layer is model-agnostic, enterprises can apply a new regulation or internal policy once and enforce it across their entire AI estate, rather than retrofitting every system individually each time a rule changes.
About Jeen
Jeen is the governed enterprise AI operating layer. It unifies employees, models, data, agents, and workflows in one governed platform, helping enterprises move from scattered AI activity to production-grade adoption with fast first value and less risk on every next deployment. Built for regulated, complex, and mission-critical sectors, Jeen delivers governance, security, and control from the start so that models can change and workflows can evolve while governance stays in place. Jeen is SOC 2 (AICPA) compliant and ISO 27001 certified, listed on the Tel Aviv Stock Exchange (TASE: JEEN), with a global presence across Tel Aviv, London, San Francisco, New York, Singapore, and Bangalore.
Sources
Grant Thornton, 2026 AI Impact Survey: https://www.grantthornton.com/services/advisory-services/artificial-intelligence/2026-ai-impact-survey
IBM, 2025 Cost of a Data Breach Report: https://www.ibm.com/think/x-force/2025-cost-of-a-data-breach-navigating-ai
Reco, 2025 State of Shadow AI Report: https://www.reco.ai/state-of-shadow-ai-report
Gartner, cited via VentureBeat: https://venturebeat.com/security/ciso-inference-security-platforms-11-runtime-attacks-2026
ISACA: https://www.isaca.org/about-us/newsroom/press-releases/2026/new-isaca-research-reveals-ai-blind-spot-at-the-heart-of-enterprise-risk
EU AI Act, Article 12: https://artificialintelligenceact.eu/article/12/
EU AI Act, Article 26: https://artificialintelligenceact.eu/article/26/
EU AI Act, Article 99 (Penalties): https://artificialintelligenceact.eu/article/99/
Natalia Magalhaes
Jeen AI Technologies UK LTD
press@jeen.ai
Visit us on social media:
LinkedIn
Legal Disclaimer:
EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.
