That does not make transparency a cause of strong governance. It makes proof a condition for independent assurance. The practical question is whether the organisation can show, quickly and coherently, who understood the risk, who owned the decision and whether the ability to change course was preserved.
AI adoption has moved into the operating model
In 2025, one in five EU enterprises used AI. Among large enterprises, the share was 55%. In banking, the European Banking Authority observed that 92% of EU banks were already deploying AI. Those numbers matter because they change the nature of governance: AI is no longer a specialist innovation programme sitting at the edge of the enterprise. It is increasingly embedded in customer service, fraud detection, credit, workflow, content, clinical support and public services.
Once AI becomes operational, the cost of an assurance gap changes. A missing record is no longer merely a documentation weakness. It can slow procurement, complicate a regulator response, weaken a board's ability to explain why a system was allowed to scale, and make cross-border remediation harder when the same model sits inside several legal regimes.
The 90% finding is really about decision freedom
In the first RATE AI release, 40 of the 202 assessed high-impact AI systems reach at least 90% verifiable transparency. That is an observed cohort pattern, not a claim that transparency alone causes a stronger rating. But it exposes a practical truth: independent assurance becomes more decisive when the evidence trail can survive somebody outside the organisation trying to reconstruct it.
That is why transparency should not be read as public-relations disclosure. The valuable form of transparency is decision-grade evidence: what was known, when it was known, who had authority, what alternatives were considered, what changed after deployment and whether the organisation could still pause, redesign or withdraw.
The external environment is moving in the same direction
The EU AI Act's transparency obligations started to apply on 2 August 2026. OECD principles call for lifecycle traceability and systematic risk management, while the OECD's 2025 incident-reporting framework was designed as a common benchmark across jurisdictions and sectors. The direction is consistent: organisations are being asked to make AI behaviour, responsibility and response legible across time.
For a board, this is less about publishing more and more about avoiding retrospective archaeology. If an inquiry arrives, the organisation should be able to assemble a coherent answer from an existing evidence spine rather than reconstructing intent from scattered emails, model cards, supplier documents and committee minutes.
Questions a decision-maker should be able to answer now
Can we identify every consequential AI system that is already influencing a customer, employee, patient or citizen?
Can we show who owns the decision to continue, pause or redesign each system?
Could we reconstruct the evidence behind that decision within days, not months?
If the system moves into another market, does the evidence travel with it?
What RATE AI is watching next
Whether the 90% pattern persists as later cohorts expand.
Whether organisations with stronger decision trails move faster through procurement, supervision and cross-border review.
Which sectors convert internal control into externally defensible evidence most effectively.
Official context: Eurostat, AI use in EU enterprises · EBA, AI in EU banking · EU AI Act enforcement and transparency · OECD AI Principles · OECD AI incident reporting framework.
Reading note: RATE AI ratings are independent risk-intelligence positions, not legal opinions or certificates of regulatory compliance. Technical methodology remains in the Public White Paper v1.1.
