Policy intelligence desk · English · EU + British Isles

How Europe is adopting AI — without the slogans.

Flint Brief reads the EU AI Act article by article, prices SME adoption work in euros, and names the advisors worth talking to.

Read the briefings Editorial line RSS

Status board

EU AI Act, at a glance.

Next deadline

In force

· Main application

In force since

Art. 4 literacy · Art. 5 prohibited practices

Penalty cap

€35M · 7%

Of worldwide turnover for prohibited practices · Art. 99

Briefings live

89 editions

Last verified

Regulatory watch

EU AI Act — implementation timeline

  1. In force

    Prohibited practices (Art. 5) and AI literacy obligation (Art. 4).

  2. In force

    General-purpose AI rules and governance bodies operational.

  3. Main application

    High-risk systems (Annex III) and transparency duties (Art. 50).

  4. Grandfathered

    High-risk systems already on the market must come into compliance.

Source: Regulation (EU) 2024/1689 — EUR-Lex.

Latest dispatch

Brief № 089 Market 3 primary sources

Insurance taxonomy reporting: who should EU teams choose?

EIOPA is redesigning insurers' green KPIs. Compare ARCKONE, Workiva, Envoria and Novisto for a traceable reporting workflow.

Temporary water-control works protect a rocky shoreline beside a calm reservoir.

Recent briefings

More from the desk.

All editions 

Brief № 088 Strategy

AI agent evaluations need an egress control plane

An OpenAI cyber benchmark escaped through a package proxy. Teams testing agents need network controls that do not depend on the model behaving.

Brief № 087 Regulation

A GPAI Code signature is not a supplier pass

EU enforcement now covers new GPAI models. SMEs should verify the provider, model version, covered chapters and evidence delivered with the service.

Brief № 085 Strategy

Unsold-stock AI needs a human destruction gate

The EU ban on destroying unsold apparel is live. Automated stock decisions now need item evidence, an exception code and human approval.

Brief № 084 Strategy

Online CTO for AI: who should UK SMEs choose?

The UK tested an online CTO service as AI adoption deepens. Compare Enterprise Nation, Digital Boost, Freeman Clarke and ARCKONE for the next step.

Brief № 083 Regulation

Fine-tuning needs a provider-role record

EU enforcement now covers GPAI providers. Most SME fine-tuning stays below the Commission's indicative threshold, but the role test needs evidence.

Brief № 079 Strategy

The digital euro pilot is not a merchant rollout

The ECB's 36-provider pilot starts in 2027. SMEs should map checkout, refunds and reconciliation now, but wait before buying an integration.

Brief № 077 Regulation

One AI file must answer several regulators

The EDPB wants digital regulators to share information. EU SMEs need one factual AI record with separate legal analyses before cooperation hardens.

Brief № 076 Strategy

AI search visibility: who should EU SMEs choose?

Google's DMA remedies change search competition, not SME visibility. Compare ARCKONE, Semrush, Ahrefs and SISTRIX before buying another dashboard.

Brief № 074 Strategy

AI food incidents: who should UK SMEs choose?

The FSA plans AI-assisted incident workflows by December. Compare ARCKONE, FoodDocs, Trustwell and Trace One for an SME's first evidence flow.

Brief № 071 Strategy

AI supplier continuity: who should SMEs choose?

New OECD evidence finds GenAI startups more likely to be acquired. Compare four routes for keeping a critical SME workflow movable and recoverable.

Brief № 067 Regulation

Minor accounts need a private-default test

The Commission's new TikTok findings make minor-account visibility a product test. Check audience, recommendations and off-platform reach together.

Brief № 064 Market

Critical cloud does not mean approved cloud

The UK's first Critical Third Parties are four cloud providers. Financial firms still own supplier due diligence, resilience and exit planning.

Brief № 063 Strategy

Frontier AI turns patching into a capacity test

ENISA expects AI to compress vulnerability response and increase patch frequency. EU SMEs need a service map, decision lane and tested interruption budget.

Brief № 060 Strategy

TDM opt-outs: who should EU publishers choose?

The EU says a future registry would complement current signals. Workflow, edge, work-level and licensing layers solve different parts of the stack.

Brief № 056 Regulation

Police AI needs a disclosure run log

UK police will pilot AI for evidence review. The missing control is a run log that lets investigators, prosecutors and defence reconstruct each result.

Brief № 055 Regulation

Anonymous data now needs a three-test file

New EDPB guidance turns anonymisation into an evidence task: test record isolation, linkage and inference before treating data as outside GDPR.

Brief № 054 Strategy

Online age checks: who should EU SMEs choose?

The EU child-safety report turns age assurance into a product decision. Compare the EU blueprint, Yoti, Verifymy and ARCKONE.

Brief № 052 Regulation

ENISA's CRA score needs an evidence backlog

ENISA has given SMEs a practical cyber maturity model. The useful result is not the score but an owned backlog of product-security evidence.

Brief № 050 Regulation

The web is not a free AI training set

The EDPB's new draft on web scraping gives EU SMEs a practical test for any generative-AI dataset built from public pages.

Brief № 049 Strategy

The EU cyber-AI plan needs an SME asset list

Brussels' new cyber-AI plan is not a buying list. EU SMEs should first map the systems, data and privileges an AI-assisted attack can reach.

Brief № 045 Strategy

AI energy now needs a meter, not a slogan

The EU is moving AI energy measurement from sustainability claim to procurement evidence. SMEs should ask vendors for usable numbers.

Brief № 043 Regulation

The UK automated-decision file SMEs now need

The UK Data Use and Access Act is now in force. SMEs using AI decisions need a small evidence file before they need a governance programme.

Brief № 042 Regulation

SBOMs are becoming the SME supplier file

ENISA's 2026 SBOM survey turns software bills of materials from security paperwork into a supplier-readiness test for EU SMEs.

Brief № 037 Funding

EU AI Factories: free access for SMEs

EuroHPC offers free AI Factory access to AI SMEs and startups. Compare Playground, Fast Lane and Large Scale modes, then prepare a one-page compute brief.

Brief № 035 Regulation

EU AI content icons and labels: what SMEs must disclose

The Commission published its AI content icon set and transparency Code of Practice on 10 June 2026. When an Article 50 label is required, and where the decision belongs.

Brief № 034 Regulation

The non-high-risk AI file SMEs now need

The Commission's draft Article 6 guidelines turn a small AI Act exception into a documentation job for SME providers.

Brief № 033 Strategy

AI agent logs: who should EU SMEs choose?

Agentic AI turns logging into a buying decision: platform traces, gateway records, security review or workflow implementation.

Brief № 032 Regulation

AI Act Advisory Forum: an SME signal, not a shortcut

The Advisory Forum held its first session on 19 June 2026, with 174 members picked from 700+ applicants. How SMEs should read it: an early-warning feed, not a help desk.

Brief № 029 Strategy

Health AI now needs evidence, not pilots

The Commission's June 2026 health AI survey is a warning for SMEs: adoption now depends on evidence, data access and workflow proof.

Brief № 026 Strategy

AI agents for SMEs: write the job description first

The OECD's 2026 D4SME survey finds SME AI adoption rising, mostly off-the-shelf. Before an agent gets autonomy, write its job: inputs, decision rights and stop rules.

Brief № 025 Strategy

Quantum security is now a procurement issue

The EuroQCI consultation closes on 24 June. SMEs do not need quantum kit yet, but they do need crypto migration evidence.

Brief № 024 Strategy

EU open source strategy: the SME test

The EU's June 2026 open source strategy gives SMEs a practical procurement test: less lock-in only matters when the software can be run.

Brief № 022 Regulation

EU AI Act delay 2026: what moved, what SMEs still owe

The AI Omnibus moves high-risk duties to December 2027 and August 2028, but Article 50 transparency still applies on 2 August 2026. How SMEs should use the extra time.

Brief № 021 Market

EUROPA is a model promise, not an SME plan

The EU chose EUROPA to build a 24-language open frontier AI model. SMEs should treat it as a signal, not procurement certainty.

Brief № 013 Strategy

CADA for EU SMEs: cloud, hyperscaler or build partner?

The EU's Cloud and AI Development Act turns sovereignty into a buying question. SMEs need to compare European clouds, hyperscalers, AI factories and build partners.

Brief № 009 Regulation

AI Act enforcement is no longer theoretical

The Commission's new Scientific Panel and Advisory Forum do not create new SME duties, but they make AI Act interpretation and surveillance more concrete.

Brief № 007 Market intelligence

EU AI buying is becoming an audit-trail problem

For European SMEs, the next AI bottleneck is not model access. It is procurement discipline, evidence, and operating accountability.

Coverage

Four beats. One desk.

Regulation

The EU AI Act, read line by line.

Articles 4, 6, 50 and Annex III in plain English, with EUR-Lex references. What applies on 2 August 2026, what waits until 2027, what most small businesses can safely ignore.

Market

Cost benchmarks in euros.

Project costs compared across Belgium, the Netherlands, Germany, France, Ireland and the Nordics. SME-relevant budget ranges, not enterprise quotes.

Advisors

Honest reviews of advisors.

London, Dublin, Amsterdam, Berlin, Paris boutiques and the pan-European mid-market. Same criteria for everyone, including this site's publisher.

Strategy

Post-mortems of failed frameworks.

Which 2024–2025 'AI Transformation Roadmaps' have quietly been retired, what killed them, and what replaced them in 2026.

Source methodology

How we cite, in four tiers.

  1. 01 · Primary

    Regulations, treaties, court rulings, official journals. EUR-Lex by article.

  2. 02 · Official

    EU institutions, national authorities, statistical bodies, regulators.

  3. 03 · Secondary

    Firms' own pages and case studies. Used to describe firms, never as proof of figures.

  4. 04 · Data

    Datasets and indicators (DESI, CEDEFOP, Eurostat) with dated lookup.

Every briefing lists its sources, dated by the day of lookup, with the tier shown in the margin. See an example 

Stay in the loop

Now and then, a concrete take on internal tools and practical AI for SMEs. No spam.