Perspectives

AI Adoption Risks Every European SME Should Know About

SMEs are adopting AI without mapping dependencies. Here's what vendor lock-in, the EU AI Act, and NIS2 mean for your business in 2026 and beyond.

13 Jun 2026 ·5 min read ·Pranoti Kshirsagar
AI strategySMENIS2 compliancevendor lock-inEU AI Act

Most European SMEs adopting AI tools right now are making the same decision large enterprises made a decade ago with cloud software — and are about to discover the same consequences. Tool by tool, subscription by subscription, the dependency architecture builds. By the time the regulatory environment catches up, the cost of changing course is already significant. The December 2025 European Parliament study on software and cyber dependencies puts hard numbers on what this looks like at scale. They are worth knowing before your next renewal or sign-up.


The AI adoption risks European SMEs are building into their stack

The starting point matters. AI tools do not run on neutral infrastructure — they run on cloud platforms, and Europe’s cloud market is heavily concentrated in the hands of a small number of US providers.

According to the European Parliament’s ITRE study (PE 778.576, December 2025), AWS, Microsoft Azure, and Google Cloud together hold approximately 70% of the EU cloud market. European providers — OVHcloud, Deutsche Telekom, SAP — each hold around 1–2%. Overall, roughly 80% of EU corporate cloud and software spending flows to US companies.

The productivity and collaboration layer is similarly concentrated. Microsoft holds approximately 90% of the EU office suite market. More than 74% of all publicly listed European companies depend on US-based email and productivity services, according to a Proton analysis cited in the study.

For SMEs, this is the baseline before any AI tool enters the picture. The AI tools being adopted now — generative AI assistants, CRM AI features, productivity copilots — are largely built on and delivered through the same infrastructure. The study estimates OpenAI holds approximately 30% of European generative AI revenue, Microsoft 25%, AWS 20%, and Google 15%. The same providers that dominate EU cloud also dominate the AI layer being built on top of it.


What you are committing to when you adopt AI tools without a strategy

The lock-in mechanics that apply to software generally are intensified with AI tools. The ITRE study identifies several reinforcing factors directly relevant to SMEs making adoption decisions now.

Proprietary formats and bundled ecosystems mean that once an organisation’s data and workflows are inside one vendor’s stack, extracting them is costly. The study notes that companies considering a cloud or software migration typically face 6–15 months of transition time, unanticipated costs, and diversion of staff from core work. For an SME without a dedicated IT function, this is a practical ceiling on future optionality — not a theoretical risk.

Subscription-based models have shifted the dynamics further. The move from one-time software licences to ongoing subscriptions means organisations continuously re-commit to a vendor’s ecosystem rather than making a single purchase decision they can revisit. The study cites Microsoft’s transition from Office to Microsoft 365 as the defining example of how this changes the competitive dynamics and lock-in effects in the software market.

AI features deepen existing dependencies rather than sitting alongside them. An SME adopting a productivity copilot is not adding one new dependency — it is deepening its cloud dependency, its productivity suite dependency, and adding a model dependency simultaneously. The study states this directly: the rapid adoption of AI “is likely to further strengthen dependencies on incumbent cloud providers, because AI workloads, models, and data pipelines are typically built on provider-specific services which increase switching costs.”

The study also cites data that only 53% of professionals in critical infrastructure are confident their organisation has full visibility of its software supply chain vulnerabilities. SMEs, with fewer resources for this kind of mapping, are likely in a weaker position still.


The regulatory environment is converging on the same dependency architecture

The EU regulatory framework developing around AI and cybersecurity is not a set of isolated compliance events. It targets the same dependency architecture — the same cloud providers, the same software stacks, the same data flows — from multiple directions simultaneously.

The 2023 NIS2 Directive introduced mandatory technical and organisational measures for operators of essential services, including requirements on supply chain security. The ITRE study notes this explicitly: organisations are directly responsible for the security of their supply chain, which includes the software and AI vendors they use. An SME that has not mapped which vendors process its data, or under what legal jurisdiction, cannot satisfy that requirement.

The EU AI Act is now in force, with the European Commission issuing guidance on its application as of mid-2025. The study flags that overlaps between AI rules and existing data-protection, consumer-protection, and cybersecurity legislation remain unresolved — meaning compliance is not simply a matter of reading one regulation.

The European Commission’s 2025 Digital Omnibus package aims to cut administrative burden by 25% for all firms and 35% for SMEs by consolidating overlapping data rules, streamlining cybersecurity reporting obligations, and clarifying AI Act implementation. This is a genuine acknowledgement that the current regulatory stack is complex. But simplification takes time. The obligations exist now.

The structural point is that NIS2, the AI Act, and the Data Act are all pointing at the same question: what happens to your operations when the infrastructure you depend on is controlled by entities outside your jurisdiction? For SMEs that have adopted AI tools without mapping that infrastructure, the answer is not yet known — and regulators are beginning to require that it be.


What a deliberate adoption decision looks like

This is not an argument against adopting AI tools. By 2024, 13.5% of EU enterprises with over 10 employees had adopted some form of AI — up from 8% in 2023, according to Eurostat data cited in the study. The pace of adoption is accelerating. The argument is that adoption without a minimum of deliberate structure creates risks that are both operational and regulatory, and that are cheaper to address before adoption than after.

Three things matter, and none of them require a dedicated IT function or a formal AI policy document.

Map what you are using and where your data goes. For each AI tool in use — including free-tier or personal accounts used for work — note which vendor operates it, which country it is hosted in, and what data it processes. This takes an afternoon and immediately surfaces the questions worth asking before the next renewal.

Distinguish tools that can stay ad hoc from tools that need a standard. Not everything requires a formal procurement decision. But any AI tool that touches customer data, financial data, or business-critical workflows should be a deliberate choice — not the default that one team member signed up for.

Ask one contractual question before renewing any software or cloud subscription. Under what circumstances can you leave, and what does it cost to export your data? The ITRE study notes that EU regulations — the Data Act and the Digital Markets Act — are beginning to address unfair contract terms that impede switching. But the obligation to read the contract remains yours.


The SMEs navigating this period well are not the ones with the most AI tools deployed. They are the ones that know what they have committed to, at which layer, and have made an active decision that the dependency is acceptable. That mapping exercise does not require a consultant or a compliance team. It requires one deliberate afternoon — ideally before the next AI feature gets added to a subscription you are already paying for.

If you are working through this at your business — get in touch →



Browse all Perspectives or get in touch →

Found this useful? Share it or read more perspectives.