MarketPulse

AI Governance and Data Sovereignty: From Policy to Enforcement in European Enterprises

An AI policy won’t detect an employee pasting a confidential contract into a public AI tool. It won’t block a transfer or leave an audit trail. Those tasks require controls that put the policy into practice.

The latest report from Antal in partnership with MakoLab, AI Governance and Data Sovereignty: From Policy to Enforcement in European Enterprises, examines how organisations can see where AI is being used, control what data it receives and demonstrate that the safeguards are working.

Deployment is moving faster than governance

Deloitte’s data show the scale of the gap between growth and readiness. 74% of the surveyed organisations plan to implement agentic AI within two years, yet only 21% report having a mature governance model for autonomous agents.¹ The challenge is translating AI policies into controls that will continue to work as adoption expands.

Can an organisation demonstrate how its AI policy is applied in practice? The report examines the controls, responsibilities and evidence needed to answer that question.

Get the report
Numerous European companies have an AI policy document and acceptable use guidelines. Sometimes, they even have a full governance framework. But the enforcement layer is missing. It’s a bit like a speed limit sign without a speed camera. The rule exists, but there’s nothing detecting violations in real time.
Maciej Grala, Cybersecurity Architect, MakoLab S.A.

Shadow AI: The gap between perceived and actual control

Shadow AI involves tools used without organisational approval and approved tools used outside their authorised scope. The problem can remain hidden even when managers believe they have full visibility in terms of AI use.

Okta’s AI Agents at Work 2026 study, conducted by Apprize360, illustrates this gap. 96% of the respondent British managers are confident about the visibility of AI usage within their organisation, while 55% of the British knowledge workers surveyed admit to using unauthorised AI tools.²

Employees may choose external tools because they are faster, better suited to their needs or more readily available. Simply locking access can shift usage to personal devices, alternative accounts or informal integrations. Effective controls therefore need to be supported by approved tools that people can use to get their work done effectively.

People aren’t trying to break the rules. They’re trying to complete their work efficiently, particularly when approved tools don’t yet provide the same capabilities or user experience as public alternatives do.
Maciej Grala

The prompt as a data export event

A prompt can contain the same sensitive information as a protected document, such as personal data, source code, contract details or company strategy. Data classification needs to cover what employees enter into AI tools and what they store in corporate systems.

When prompts, files or retrieved content are sent to an AI service outside the organisation’s controlled environment, they should be assessed as external data sharing. The report explores which data can be used in which tools, which have to stay within the controlled environment and who approves any exceptions.

From an enterprise data governance viewpoint, the highest risk is with unstructured data because it’s one of the easiest categories to paste into a chat window without anyone flagging it. It includes things like draft contracts, client and customer correspondence, source code, internal strategy documents and the personal data embedded inside all of them. A great many organisations have established classification schemes for data stored in databases or document management systems, but they don’t always extend to text entered into a browser-based AI tool, even though it’s not the sensitivity of the content itself that’s changed, but only the format.
Jerzy Wiśniewski, Cybersecurity Architect, MakoLab S.A.

Data sovereignty is more than just server location

Data residency describes where data are stored. Data sovereignty also encompasses who can access them, which jurisdiction applies and how suppliers and sub-processors handle them.

Choosing a European cloud region leaves some of these questions unresolved. Organisations also need to understand the provider’s legal obligations and the wider chain of services involved in processing their data.

Strategic priority is not always translatable into action. SUSE finds that 98% of the surveyed organisations regard digital sovereignty as a strategic priority, but only 52% are taking concrete action.³

Data storage location is the easy 20% of the problem. The more challenging 80% involves processing, sub-processors and legal jurisdiction. In other words, who can access the data, regardless of where the servers are physically located.
Jerzy Wiśniewski

An audit asks for the policy and then for the evidence

An audit trail needs to connect an AI output with the data, model and configuration that produced it. Policies alone cannot provide that evidence.

Models change and prompts are modified. Without records, it may become impossible to establish the conditions behind a specific recommendation. The report explains why organisations should retain inputs, outputs and configuration details from the outset. Reconstructing those conditions supports an investigation; however, it does not guarantee that a model will generate an identical response.

Technically speaking, reproducibility is certainly doable. Organisations can version prompts, log model parameters and maintain immutable logs of results. What’s more, building this audit trail from the outset can make the process significantly easier and more cost-effective. Introducing it later is still possible, but it may require additional effort and resources.
Przemysław Kapuściński, Cybersecurity Architect, MakoLab S.A.

Five steps from policy to enforcement

The report sets out five steps towards enforceable governance, with safeguards matched to the risk of each application. Three practical priorities are:

·       identifying the current status, including a register of tools used organically by teams;

·       appointing a business owner to be responsible for each significant AI application, its purpose, scope, risk and compliance;

·       building evidence from the outset, so that auditability is part of the architecture rather than a reaction to an audit.

The full framework also covers risk categorisation and technical controls, helping organisations connect policy with day-to-day practice.

A centrally developed AI policy is an important starting point, but its effectiveness depends on how well it’s translated into everyday practice across an organisation. And that requires active cooperation with the local teams working with AI tools, data and business processes on a day-to-day basis. Their involvement helps identify practical constraints, clarify responsibilities and build shared ownership of the controls that are being introduced.
Włodzimierz Mrozek, Cybersecurity Expert, MakoLab S.A.

Download the report to explore the five steps, the evidence organisations should retain and the questions that help assess their control over their data.

Can your organisation demonstrate its AI governance in practice?

Are you keen to apply the framework to your organisation?
Book a working session with MakoLab’s experts to review your current AI use, identify gaps in your controls and audit evidence and discuss the priorities for improvement.

The broader research programme

AI Governance and Data Sovereignty: From Policy to Enforcement in European Enterprises is the third publication in a research series by Antal in partnership with MakoLab. It was preceded by AI-Ready Infrastructure: Observability and Operations and A New Way of Working: Managing Software Delivery Using Agentic Engineering.

Designed for IT leaders and decision-makers, the programme maps the operational reality behind enterprise AI adoption. Forthcoming reports will cover:

·       The practical applications of neuro-symbolic AI;

·       AI adoption and readiness across European enterprises; a comprehensive quantitative study tracking the current state of play.

Sources

¹ Deloitte. State of AI in the Enterprise: The Untapped Edge. January 2026; fieldwork August-September 2025; 3,235 business and IT leaders across 24 countries.

² Okta. AI Agents at Work 2026: Securing the Agentic Enterprise. A survey conducted by Apprize360, March 2026; 292 executives and 492 knowledge workers across seven countries (Australia, Canada, France, Germany, Japan, UK, US). The figures quoted are for the UK. By country, unsanctioned use runs from 67% in the US to 50% in Canada.

³ SUSE. Navigating Digital Resilience. April 2026; 309 IT leaders across France, Germany, India, Japan and the US.

28th September 2026
7 min. read
Author(s)

Anna Kaczkowska

Content Marketing Specialist

Responsible for planning, creating and managing content

Maciej Grala

Architect IT/Senior .NET Developer

Jerzy Wiśniewski

Cybersecurity Architect

Przemysław Kapuściński

Cybersecurity Architect

Contents

Read more Insights

Insights
Follow our news and the know-how we share. Keep up with our CSR activities and join us behind the scenes with MakoLife.
Browse through our