TL;DR
Thorsten Meyer AI has framed European enterprise AI strategy as a choice between building capability and tightening control as EU AI Act milestones arrive. Confirmed regulatory facts include AI literacy and prohibited-practice rules already applying, GPAI duties in force, transparency rules due from 2 August 2026, and high-risk deadlines now set later under the AI omnibus agreement.
Thorsten Meyer AI has published “Capability or Control: The European Enterprise AI Playbook for the AI Act Era,” framing a central choice now facing European companies: how to expand AI use while meeting the European Union’s staged AI Act obligations.
The confirmed development is the publication and framing of the playbook. The headline does not provide named authors, case studies, financial data or proprietary survey findings, so those points cannot be reported as facts. The factual regulatory backdrop is confirmed by the European Commission: the AI Act entered into force on 1 August 2024; prohibited practices and AI literacy duties have applied since 2 February 2025; rules for general-purpose AI models have applied since 2 August 2025; and most transparency duties under Article 50 are due from 2 August 2026.
The Commission says the law uses risk-based rules for AI developers and deployers. High-risk examples include AI in education, employment, essential services, law enforcement, migration, justice and certain biometric uses. The Commission also lists obligations for high-risk systems covering risk management, data quality, activity logging, technical documentation, user information, human oversight, robustness, cybersecurity and accuracy.
On 19 May 2026, the Commission issued draft guidelines on classifying high-risk AI systems and invited feedback until 23 June 2026. The Commission has also reported a 7 May 2026 political agreement on an AI omnibus package that sets rules for some high-risk areas from 2 December 2027 and product-integrated systems from 2 August 2028.
Capability or Control
● EnterpriseThe EU AI Act doesn’t ban models by origin. Together with the CLOUD Act, GDPR, and a supply chain that can be switched off, it forces European enterprises to choose — workload by workload — between capability and control. Origin matters far less than license, deployment, and jurisdiction.
Nationality isn’t the gate. License, data destination, and where you deploy are.
No single point is right for a whole company. The right answer is a portfolio, assigned per workload.
Sort workloads by data sensitivity & regulatory exposure, then match each to a stack.
Independent commentary, produced with AI assistance under human editorial oversight; the views are the author’s own and may change. This is analysis and opinion, not legal, compliance, investment, or technical advice; the EU AI Act, its implementation, and model availability are evolving — verify specifics with qualified counsel and primary regulatory sources before acting. Figures and milestones are drawn from public sources read as of June 2026 and are subject to change. References to specific companies, models, regulators, and government actions are factual and analytical, not partisan, and imply no affiliation or endorsement.
Compliance Becomes Enterprise Strategy
For enterprise readers, the immediate issue is no longer whether AI tools will be used; it is who owns the risk map, model inventory, data lineage, procurement checks and employee-use rules when those tools move from pilots into operations. The playbook framing matters because AI capability and control now sit in the same budget conversation: companies need usable systems, but they also need evidence that those systems are governed.
The consequences differ by role. Providers of general-purpose AI models face transparency, copyright and, for systemic-risk models, safety and security duties. Deployers using AI in hiring, credit, education or public-service settings may face obligations tied to human oversight, monitoring and incident reporting. Companies outside the EU can also be covered when their systems are placed on the EU market or used in the EU.
This affects procurement as much as legal compliance. Buyers will need model documentation, content-labelling positions, vendor attestations and escalation paths before rolling out AI across HR, customer service, software development or analytics teams. The practical risk is that slow governance can block useful systems, while loose adoption can create compliance, reputational and operational exposure.

The Future of Enterprise Software Delivery: How AI Is Redefining Enterprise Strategy, Accelerating Software Development, and Delivering Trusted Systems at Scale
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
AI Act Deadlines Are Near
The AI Act became EU law on a staged calendar rather than a single start date. Prohibited practices, including social scoring and several biometric and manipulation-related uses, became effective in February 2025. GPAI rules followed in August 2025, supported by a voluntary GPAI Code of Practice covering transparency, copyright, safety and security.
That code is relevant because many enterprise AI systems now rely on models built or supplied by other companies. The European Commission says signatories can use the GPAI Code of Practice as a way to show compliance, while providers that use other methods must show those methods are adequate. The Commission’s listed signatories include major model providers and enterprise technology companies.
The next regulatory focus is high-risk classification. The Commission’s May 2026 consultation asks stakeholders, including businesses, public authorities, academia, research bodies and citizens, to comment on draft guidelines before 23 June 2026. That process is meant to clarify which systems fall into the high-risk category, but the final wording has not been settled.
“Capability or Control: The European Enterprise AI Playbook for the AI Act Era”
— Thorsten Meyer AI

AI for Project Managers: A Desk Reference & Field Guide: Use Artificial Intelligence to Streamline Workflows, Automate Tasks, and Make Smarter Decisions with Practical Tools and Ethical Insights
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Guidance Still Leaves Gaps
Several details remain unsettled. The article details beyond its headline were not available for this report, meaning any specific recommendations, examples or internal methodology cannot be attributed beyond the title.
Regulatory details also remain in motion. The Commission says the transparency code published on 10 June 2026 is undergoing adequacy review by the Commission and AI Board, and guidance on the scope of Article 50 transparency duties is still expected. It is also not yet clear how consistently market surveillance authorities will judge non-signatory compliance methods across Member States.
For high-risk systems, companies still need final guidance, harmonised standards and more supervisory practice before they can classify every internal system with confidence. The current compliance task is to inventory AI use now and separate low-risk productivity tools from systems that affect people’s rights, access to services or workplace outcomes.

Koala Laser Transparency Film, 8.5×11 Inch, 20 Sheets Transparent OHP Film for Laser Printers, Copiers, for Crafts, Overhead Projectors and Presentations
【Perfect for Crafts】Koala Laser transparency film offers optimal performance and professional looking, allowing you to make crafts and…
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Firms Face June Feedback Deadline
The nearest public milestone is 23 June 2026, the deadline for feedback on the Commission’s draft high-risk classification guidelines. After that, companies should watch for final guidance, standards and Article 50 transparency materials, because those documents will shape labelling, documentation and oversight practices before the August 2026 transparency date.
Enterprise teams should treat the coming months as a mapping period: identify AI systems, record vendors and model dependencies, classify intended uses, document human review points and decide where deployment needs legal, security, procurement or works-council review. That work will determine whether AI adoption is led by business capability alone, by control alone, or by a governance model that can support both.
Source: Thorsten Meyer AI

Practical Agentic AI Governance, Compliance, and Runtime Security: Build Auditable, Compliant, and Continuously Protected Autonomous Agents and Multi-Agent Platforms at Enterprise Scale
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Key Questions
What is the actual news in this development?
Thorsten Meyer AI has framed European enterprise AI strategy around capability and control in the AI Act era. The confirmed regulatory backdrop is the EU’s staged AI Act calendar and the Commission’s current guidance work.
Is this a new EU AI law?
No. The EU AI Act entered into force on 1 August 2024. The news value is that enterprise planning is now shifting from broad preparation to concrete mapping, classification, documentation and oversight work as 2026 milestones approach.
Which AI systems should companies review first?
Companies should start with systems used in employment, education, credit, essential services, biometric identification, migration, justice, public services and safety-related product functions. They should also review generative AI systems that create public-facing text, images, audio or video.
What remains uncertain for enterprises?
Final high-risk guidance, harmonised standards, Article 50 transparency guidance and Member State enforcement practice remain developing areas. The detailed recommendations inside the Thorsten Meyer AI article cannot be reported beyond the headline because the full article text was not available for this report.
Source: Thorsten Meyer AI