AKAWAN NEWSLETTER

Before leaving, let's stay in touch.

Once a month, receive practical insights from our AI and digital experts - covering use cases, real-world experiences, and trends - with no jargon, just useful ideas.

Your address remains confidential. You can unsubscribe at any time with a single click.

le-carnet-de-santé-numérique-que-vous-n-avez-pas

The digital health record you don't have

Article akawan : Multi-sites, zero visibilite...

The digital health record you don't have

Your batches have a file. Your data, however, does not…

On August 2, 2026, the European Artificial Intelligence Act became applicable, following an entry into force in 2024 and a phased implementation since February 2025 (European Commission, 2026). In most industrial management teams, the text was shelved under software vendor topics: a matter for those who design models, not for those who manufacture parts.

Yet, the risk does not come from the model you are going to buy. It comes from the one your teams are already using, without a contract, without a defined scope, without a log. Your manufacturing ranges, your production deviations, your supplier terms have been circulating for months in generic assistants open in a browser tab. The day a client, an auditor, or a prime contractor asks you what came out of your information system, you won't have an answer. Not because you made a mistake. Because nobody recorded anything.

A few figures to measure the gap between usage and control:

  • 18% of companies established in France declare using at least one artificial intelligence technology in 2025, which is 8 points higher than in 2024 (Insee, 2026)

  • 17% in the manufacturing industry, compared to 58% in companies with 250 or more employees, across all sectors combined (Insee, 2026)

  • 73% of companies using AI rely on paid cloud services (Insee, 2026)

  • 63% of surveyed organizations have no AI governance policy in place to guide its use (IBM, 2025)

  • 97% of organizations that fell victim to an AI-related security incident state they did not have appropriate access controls in place for these tools (IBM, 2025)

  • 39.7% of interactions with corporate AI tools involve sensitive data (Cyberhaven, 2026)

Definition drawings, supplier pricing, non-conformance reports: what your teams are pasting into a browser

The mechanism is far from spectacular. A quality engineer needs to produce a root cause analysis at the end of the day. He has a forty-page non-conformance report, a three-hour deadline, and an assistant that responds in ten seconds. He pastes the report. The analysis is good, the deadline is met, nobody talks about it.

What just happened, technically, is a transfer. The content has left your perimeter, it has been processed on an infrastructure you have not qualified, in a country you did not choose, under retention conditions you did not read. The proportion of interactions concerned is not marginal: nearly four out of ten interactions involve sensitive data (Cyberhaven, 2026). And since AI usage heavily relies on paid cloud services (Insee, 2026), the data stays on the workstation no more than it does on-site.

Three direct consequences, which do not appear on any dashboard:

No trace on the IT side: the request left through the browser, not through an application interface. Your monitoring only sees an HTTPS flow to a legitimate domain.

No retention rules: you do not know how long the content is kept, whether it feeds a training model, or which subcontractors access it.

No reversibility: design data sent to a third party does not come back. You can neither recall it nor prove that it was not used.

Nothing is logged. A usage policy without a log is like a blank health record: the patient is doing great, until the day you have to explain why they are no longer doing well.


Since August 2, 2026, usage is no longer enough; proof is required

The European schedule has placed obligations before usages, which is unusual and alters the workload of technical departments.

Prohibited practices and AI literacy obligations have applied since February 2, 2025. Governance rules and obligations related to general-purpose models have applied since August 2, 2025. The regulation itself has been applicable since August 2, 2026, and the requirements targeting systems used in certain high-risk areas, including critical infrastructures, will apply starting December 2, 2027 (European Commission, 2026).

Operational translation: the literacy obligation does not apply to a product, it applies to your teams. It assumes that you know who is using what. This is precisely what you do not know.

Additionally, there is the personal data aspect. In July 2025, the French National Commission on Informatics and Liberty (CNIL) finalized its recommendations on the development of AI systems and reminds that models trained on personal data may be subject to the GDPR, that the annotation phase is crucial for the quality of the model, and that robust filters must be planned at the level of the system encapsulating the model (CNIL, 2025). Your production files contain operator names, authorizations, and intervention records. This is personal data.

What this schedule establishes is not a technical constraint, it is a reversal of the burden. Until now, digital usage was presumed legitimate as long as no incident contradicted it. From now on, it is up to you to establish what was used, by whom, on what data, and within what framework. Your sectors already know how to work this way for material goods: no batch leaves without a file, no part is released without a record. Digital systems, however, have long remained outside this discipline. They have just entered it.

Being compliant and being able to demonstrate it are two distinct states. Only the second is defensible, document in hand, within fifteen days of a request.

The burden of proof lies with you.

"We don't do AI": the objection that protects you from nothing

The classic objection can be summarized in one sentence: "we don't do AI." It is sincere and false. You do not have an AI project; you have AI usages. This is not the same thing, and only the second engages your responsibility.

The discrepancy is visible in the figures. The manufacturing industry reports a 17% adoption rate, while companies with 250 or more employees reach 58% (Insee, 2026). An industrial site with 400 people statistically has more usages than it has declared. We described this gap between real adoption and the established framework in DeepSeek: the application devouring your business....

The cost of this blind spot is documented. Organizations with high exposure to shadow AI see the average cost of a data breach increase by $670,000, and 63% of surveyed organizations have no AI governance policy (IBM, 2025). The problem is not the lack of security tools: 97% of organizations affected by an AI-related incident state they did not have appropriate access controls to these tools (IBM, 2025). Access was simply open.

For a mid-sized company or an industrial SME, the issue is therefore not the fine. It is the gap between two disciplines coexisting within the same company: the one that prohibits releasing a batch without a record, and the one that lets a design file leave without any trace. The first has been taught, audited, and maintained for thirty years. The second has never been written.

It is not your size that exposes you. It is your lack of a logbook.

3 concrete actions to open the logbook

  1. Map flows, not tools. Start with data, not applications: which families of documents leave, from which departments, for what use. A tool inventory becomes obsolete in three weeks. A flow map lasts two years.

  2. Set a technical boundary, not a charter. A memo filters nothing. A single gateway, where requests are anonymized before leaving and recorded in transit, filters everything that matters without prohibiting usage. It is there, and nowhere else, that the log line is written: request, user, timestamp, destination, retention period. Without it, your compliance is an intention; with it, it is a file.

  3. Decide where the model runs. This is the truly sovereign trade-off. A model hosted on your infrastructure does not fall under the same regime as the same model called from hyperscalers subject to extraterritorial laws. This trade-off is played out in your architecture, not in your terms and conditions: it is the subject of our expertise in Artificial Intelligence.

akawan designed Bosl.ai to address exactly this gateway in an industrial context: a web application that integrates request anonymization algorithms, warns and alerts users about leakage risks, and bases processing on sovereign AI, with data remaining on local servers. The user journey has been redesigned so that the secure path is also the fast path, a necessary condition for it to be adopted. The design of this application is presented on the page Secure chat with Bosl.ai.

Sovereignty is not declared, it is engineered

The question is not whether generative AI will enter your industry: it is already there, from the bottom up, without architecture. The question is whether it enters through a door you have installed, instrumented, and logged, or through a window that no one is watching.

This shift does not require a transformation program. It requires an architectural decision: a gateway, an anonymization rule, a log, and an explicit choice of where to run. The rest follows, because usage always follows the shortest path.

The question to bring to your next executive committee is not "do we have an AI policy." It is: if an auditor asks us tomorrow for the list of production data that left our IS this quarter, are we capable of producing it?


Who are we?

akawan is an independent expert IT services company based in Toulouse, specializing in artificial intelligence, digital transformation, information systems architecture, and agility. We support companies and industries in modernizing their software ecosystem, enabling technical and operational departments to leverage their data and secure their growth.

Do you have a project?

akawan, agency in Toulouse, specialist in digital transformation and artificial intelligence.

Together, let's build your digital future.

2025 - akawan

English

akawan, agency in Toulouse, specialist in digital transformation and artificial intelligence.

Together, let's build your digital future.

2025 - akawan

English

akawan, agency in Toulouse, specialist in digital transformation and artificial intelligence.

Together, let's build your digital future.

2025 - akawan

English