Skip to main content

White paper · Read online · June 2026 Edition

AI Maturity of French SMEs 2025-2026

The reference white paper for business leaders, MATIA Method™

By Paul-Antoine Tual, AI Transformation Leader · Croissance et Transitions · June 2026 Edition, golden standard, v2.3 · Published 23 May 2026, revised 11 July 2026

Version française →

Preamble: the narrow window

In the second quarter of 2026, 58% of French micro-businesses and SMEs report using AI (almost half of them daily), compared with 55% at the end of 2025[1]. This figure, drawn from the Bpifrance Le Lab / Rexecode barometers, marks a historic turning point. In the space of three years, artificial intelligence has gone from an R&D topic for large corporates to a daily tool of the real economy.

However, behind this massive adoption, another statistic attracts far less attention: only around 11% of organisations are “AI leaders” that derive clear business value from AI. This is the share measured by the KPMG Global AI Pulse for the first quarter of 2026 (2,110 business leaders, 20 countries), where 82% of these leaders report significant value, compared with 62% of the others[2]. The Stanford AI Index 2026 confirms this from the other end of the spectrum: 88% of organisations use AI in at least one function, but fewer than 10% have genuinely scaled it in even a single one of them[29]. Out of 100 equipped SMEs, the overwhelming majority merely dabble; one in ten reaps the rewards; a handful genuinely transform. The window is narrow, but it is still open.

This white paper is addressed to business leaders who are not content to adopt AI merely to say they have done so. It offers a five-level framework, a method, and field data, drawn from more than thirty documented engagements with French SMEs and mid-caps since 2024[8].

The thesis is simple: AI in SMEs is not won through technology. It is won through method. The 11% that succeed are not better equipped. They are better organised. The fewer than 0.5% that define their sector are not more innovative. They are better governed.

The June 2026 edition incorporates four new elements compared with the initial edition of April 2026:

  1. The extension of the MATIA Method™ Scale to 5 levels: Spectateur and Pionnier added at the top and bottom, in line with the 2025-2026 “golden standard” frameworks (Gartner 5 levels, PwC AI-Native, Microsoft Agentic L100→L500).
  2. The updated AI Act timetable: delay following the Digital Omnibus of 7 May 2026[15].
  3. Two new chapters: sovereignty & infrastructure (Chapter 4), mastering the cost of AI & FinOps (Chapter 5).
  4. The integration of context engineering: “commanding AI” rather than “writing prompts”, within the 5-phase methodology (Chapter 6).

Chapter 1: Where French SMEs stand, 2025-2026

1.1 Surface adoption, depth of value

The Bpifrance Le Lab barometer from late 2025 indicates 55% reported use of generative AI among micro-businesses and SMEs, up by around 30 points in eighteen months[1]. Three uses dominate: drafting marketing content, summarising documents, and help with drafting emails. Three uses that share one characteristic: they are individual, outside any process, and unmeasured.

The France Num 2025 barometer (DGE, September 2025, 11,021 businesses: the most recent published data, with the 7th edition expected in autumn 2026) refines the picture: 26% of micro-businesses and SMEs report using at least one AI tool in 2025 (double the 2024 figure), but the proportion rises with size: 23% for 1-4 employees, 35% for 20-49, rising to 42% for 50-249 employees[12]. Regular use, however, remains a minority.

Digging deeper yields another figure, a far less flattering one: only around 11% of organisations are “AI leaders” drawing clear business value from AI. This is the finding of the KPMG Global AI Pulse for Q1 2026 (2,110 business leaders, 20 countries); 82% of these leaders report significant value, compared with 62% of the rest[2]. That is, a visible effect on the profit and loss account, on revenue, on costs, or on productivity. The international finding is borne out on the ground: according to the Stanford AI Index 2026, 88% of organisations use AI in at least one function, but fewer than 10% have genuinely scaled it in even a single one[29]; and the OECD notes that only 29% of SMEs using generative AI deploy it in their core business[30]. The remainder, the yawning gap between reported use and measured value, is the zone of scattergun adoption.

Deloitte goes further in its State of AI in the Enterprise 2026 (January 2026, 3,235 business leaders, 24 countries): only 30% of organisations are redesigning their key processes around AI, while 37% use it superficially, without changing anything fundamental. And barely a quarter report a genuinely transformative effect[20]. This is the “industrialisation gap”: the dividing line between the minority that genuinely transforms its operations and the majority that remains stuck in permanent pilot mode.

1.2 The executive committee's blind spots

The Bpifrance Le Lab “AI in French SMEs and mid-caps” study (fieldwork late 2024, 1,209 business leaders) brings to light two blind spots in the executive committee[3]:

  • Nearly six in ten business leaders see AI as a matter of survival, yet an equivalent proportion has no formalised AI strategy. AI is perceived as a matter of tools, not as a subject for senior management.
  • 43% of businesses carry out no analysis of their data at all. No cross-functional dashboard, no data team, no governance, and therefore no raw material for a credible AI transformation. (At national level, INSEE confirms the scale of the task: only 10% of businesses with 10+ employees used an AI technology in 2024[3].)

To this is added the phenomenon of executive Shadow AI: the Microsoft Work Trend Index 2026 documents a persistent gap between business leaders and employees in AI usage (67% of business leaders familiar with agents, against 40% of employees), with business leaders often adopting AI personally before the business has formalised its use[13]. This is not in itself a problem. It becomes a risk when it takes hold over time without a framework: exfiltration of sensitive data, dependence on non-auditable tools, opaque decisions.

Underlying use, however, remains cautious in France. According to ADP (People at Work 2026, close to 40,000 workers across 36 countries), only 11% of French employees use AI almost daily, and 29% never do, one of the lowest rates studied, against a global average of 20% for near-daily use[11]. Deep diffusion, not surface adoption, remains the real task at hand.

The most telling figure now concerns execution: 43% of major AI initiatives are judged doomed to fail, owing more to a lack of organisational readiness than to technology (HCLTech, May 2026, a survey of 467 business leaders at companies with revenue above $1 billion)[5]. Gartner confirms the trend in its Hype Cycle for Agentic AI from April 2026: at least half of generative AI projects are abandoned after the pilot phase, and more than 40% of agentic AI projects will be by 2027[4]. It is not AI that fails to work. It is projects that are not carried through.

1.3 The cost of waiting

Leaders, for their part, document a median ROI of 159.8% measured over 24 months on well-scoped AI projects[7]. The figure, drawn from Denis Atlan's AI & ROI Barometer for French SMEs 2022-2025 (more than 200 B2B deployments analysed, a 73% success rate), corroborates more than thirty documented engagements in France[8].

The question is therefore no longer “should we do it”. It has become “should we do it now or in two years”. The answer is simple: the laggards of 2026 will be the casualties of 2030. Not through sudden disruption: through margin erosion and loss of competitiveness.

The Osez l'IA plan, launched by Bpifrance in July 2025 (€200 million initial envelope, within an overall drive of €10 billion), sets the target: 80% of French SMEs and mid-caps at Orchestre level or above by 2030[14].

1.4 Regulatory context: the AI Act after the Digital Omnibus

On 7 May 2026, the European Council and Parliament adopted the political agreement on the Digital Omnibus[15]. This simplification package reorganises the timetable of several major pieces of legislation: the GDPR, NIS2, the Data Act, and notably the AI Act (EU Regulation 2024/1689[9]).

For SMEs, three concrete implications:

  1. Deferral of obligations for high-risk systems. The main obligations for high-risk AI systems, initially due on 2 August 2026, are pushed back to end of 2027 / 2 August 2028, depending on category. The timetable in this white paper's April 2026 edition is therefore out of date on this point.
  2. Administrative relief announced. The Digital Omnibus provides for a 35% reduction in the administrative burden for SMEs by 2029, notably via a one-stop shop for digital compliance.
  3. The AI literacy obligation remains in place. Article 4 of the AI Act, requiring a sufficient level of user proficiency, has applied since February 2025, unchanged, with no threshold.

Key takeaway. The deferral of the high-risk obligations does not change the trajectory: it changes the pace. SMEs that have put Architecte-level governance (MATIA-4) in place before 2 August 2028 will be compliant by design. Others will have to catch up urgently, amid an already well-documented skills shortage.

Chapter 2: The MATIA Method™ Scale, the 5 levels

2.1 Why a framework dedicated to French SMEs

Most AI maturity models borrow their framework from large corporates. Gartner, Microsoft, PwC, BCG, McKinsey, Deloitte: each has its own dial[16][17][18][19][20]. They all share one major flaw for an SME business leader: they were designed for large corporates.

The MATIA Method™ Scale corrects this flaw. It was designed on the basis of more than thirty documented engagements with French SMEs and mid-caps since 2024[8]. Five rungs, each associated with a memorable metaphor and a simple question. The 5-level framework is consistent with the 2025-2026 “golden standard” frameworks (Gartner, PwC AI-Native, Microsoft Agentic L100→L500) while remaining specific to French SMEs. No official French 5-level framework exists to date; the MATIA Method™ fills this gap.

2.2 The five stages: overview

# Name Business leader question % SMEs
1Spectateur“AI, we're watching from a distance. Are we missing something?”~50%
2Artisan“Are my people using AI, each in their own corner?”~30%
3Orchestre“Is AI embedded in our processes, steered and measured?”~13-15%
4Architecte“Is AI a structural competitive advantage?”~2-3%
5Pionnier“Are we setting the standard for our sector?”< 0.5%

Total for levels 3+: ~16-18%, consistent with the Stanford AI Index 2026 (fewer than 10% have scaled AI within a function[29]) and the share of “AI leaders” measured by KPMG in Q1 2026 (~11%)[2].

2.3 Level 1: Spectateur

“AI, we're watching from a distance. Are we missing something?”

The company is aware that generative AI exists. The business leader has heard about it; a few staff may have tried ChatGPT personally, once. But no official tool is in place, no business use case has been identified, and no budget line exists. The danger is not being at this level in May 2026; it is still being at this level in May 2028.

~50% of French SMEs: a MATIA estimate anchored on the Baromètre France Num 2025 (74% of micro-businesses and SMEs declare no AI tool at all), cross-read with Bpifrance's usage measurements to distinguish those genuinely not using AI from those with sporadic individual use[12].

2.4 Level 2: Artisan

“Are my people using AI, each in their own corner?”

The company harbours individual, uncoordinated uses. The territory of Shadow AI: each has subscribed to their own tool, sometimes on a personal account, without a framework. Three concrete risks: data exfiltration, undetected hallucinations, personal dependency. ~30% of French SMEs: the differential between Bpifrance's adoption rate (58% reported usage in Q2 2026) and the value actually measured (≈11% “AI leaders”, KPMG Q1 2026), refined using the Microsoft Work Trend Index 2026[13].

2.5 Level 3: Orchestre

“Is AI embedded in our processes, steered and measured?”

The company has identified 2 to 5 priority business use cases, deployed them through a genuine project-based approach, and measures their effects. Usage charter approved by the executive committee, 2 to 4 business champions, data policy, quarterly AI committee, AI Act register. This is where the documented median ROI of 159.8% over 24 months resides[7]. ~13-15% of French SMEs: the share of “AI leaders” (≈11%, KPMG Q1 2026) and Bpifrance Le Lab (15-20% with structured steering).

2.6 Level 4: Architecte

“Is AI a structural competitive advantage?”

AI is an attribute of the business. Proprietary knowledge base (5 to 10 years of cleaned business archives), agents under supervision on defined scopes, AI Act register maintained in real time[9][15], ISO 42001 governance initiated[21], LLM gateway, mature FinOps. The advantage is structural: a competitor seeking to replicate it would need 18 to 24 months[8]. ~2-3% of French SMEs: BCG AI Radar 2026: 15% of “Trailblazer” business leaders globally[19], adjusted downward for French SMEs; consistent with the ~16% of “Frontier” professionals orchestrating agents (Microsoft, Work Trend Index 2026)[13].

2.7 Level 5: Pionnier

“Are we setting the standard for our sector?”

AI-first processes and hybrid human-plus-agent teams in production: multi-step autonomous agents supervised asynchronously (hours then days), token budgets and contractual quality indicators, orchestrated amongst themselves and with staff. AI governance steered by senior management (certified ISO 42001 / Responsible AI), demonstrated value on the income statement, and capitalisation on proprietary knowledge and data (“Owned Intelligence”). Microsoft speaks of “Frontier Firms”[13], PwC of “AI-Native”[17], BCG, in its AI Radar 2026, of “Trailblazer” business leaders[19].

An anti-hype clarification on two markers often presented as “golden standard”: data sovereignty (sovereign cloud, SecNumCloud, or on-premise) is a deployment choice dependent on sector constraints, not a maturity tier: no global 2026 framework places hosting location at the summit; and the “agent-to-agent” (A2A) business plays out across two layers: the interoperability layer (the A2A protocol “production-ready” at 150+ organisations, MCP, process exposure via API) is already achievable: making one's information system agent-ready, open to one's own agents and to those of clients and suppliers, is a 2026-2027 action objective; the transactional layer “on both sides” (widespread inter-agent commerce and payment) remains an emerging frontier, 2028 horizon. Fewer than 0.5% of French SMEs. McKinsey, in its State of AI Trust 2026 (March 2026), measures average maturity at 2.3 out of 4, with only one organisation in three at level 3 or above[6]; set against French SMEs, the fully “pioneering” fraction is smaller still. The Pionnier of 2026 will be the sector benchmark of 2030.

At the summit, nine dimensions define the “golden standard 2030” target of the Pionnier (full grid below): sovereign AI mastered (RAG + targeted fine-tuning, local/on-premise option), resilience impervious to the splinternet (multi-cloud redundancy + on-premise failover), ~100% of staff augmented and ~100% cultural adoption, certified ISO 42001 governance, technical debt < 1% and security score > 99.5%. These are deliberate apex thresholds: it is their conjunction, achieved by fewer than 0.5% of SMEs, that defines the sector standard.

2.8 The golden rule: no level can be skipped

An Artisan-level SME that invests €200,000 to build an autonomous agent platform fails more than one time in two, not for lack of technology, for lack of foundations. This is exactly the definition of the “POC graveyard” that Gartner documents[4]. The CIO Playbook 2026 (IDC-Lenovo, January 2026) quantifies it: only 46% of POCs reach production. Half remain stuck at the pilot stage[27].

Transition durations and budgets (SME 50-500 employees)[8]:

  • Spectateur → Artisan: 3 to 6 months · €5,000 to €15,000
  • Artisan → Orchestre: 6 to 12 months · €30,000 to €80,000
  • Orchestre → Architecte: 12 to 24 months · €80,000 to €250,000
  • Architecte → Pionnier: 24 to 36 months · structural investment

A Spectateur → Architecte transformation takes 3 to 4 years. Spectateur → Pionnier takes 5 to 7 years. The irreducible duration of organisational maturation, independent of the speed of the technology.

Key takeaway. No level can be skipped. An Artisan-level SME that invests €200,000 in an agent platform fails more than one time in two, not for lack of technology, but for lack of foundations[8]. Spectateur → Architecte takes 3 to 4 years: this is the pace of people, processes and data, not that of tools.

The 9 dimensions of maturity, level by level

Overall positioning breaks down into nine dimensions. Each progresses from Spectateur to Pionnier; Level 5 describes the “golden standard 2030” target, achieved today by fewer than 0.5% of SMEs, which is what makes it rare. The numerical thresholds (≈100%, < 1%, > 99.5%) are apex targets, not market averages.

Dimension Spectateur Artisan Orchestre Architecte Pionnier (2030 target)
Sovereignty & control of models Consumer tools, data not controlled Personal accounts, exposed data Classified data, EU/SecNumCloud for sensitive data Sovereign cloud + RAG, targeted fine-tuning if justified Sovereign AI: RAG + targeted fine-tuning, local/on-premise option, reversibility
Resilience & imperviousness to the splinternet Total dependence, risk ignored Single provider, no plan Basic DR/BCP, data replicated in EU Multiple providers, proven reversibility Multi-cloud redundancy + on-premise failover: continuity even in a splinternet event
Augmented staff 0% official ~10-30%, unsupervised ~30-50%, priority roles ~70% of eligible roles ~100% of eligible staff, core orchestrating agents
Cultural adoption & AI literacy None Self-taught, uneven 3-tier training (> 30%) Rolled out, role-specific ~100% culturally adopted, continuous learning, leaders augmented
AI governance None None (Shadow AI) Charter, quarterly committee, AI Act register, prior CSE consultation for internal AI (≥50 staff, Art. L.2312-8) Monthly executive committee, ISO 42001 initiated, structured staff-rep dialogue Golden standard: certified ISO 42001, Responsible AI, senior oversight, permanent staff-rep dialogue
Technical debt Not applicable Hidden (ad hoc scripts) Tracked, backlog identified Controlled (< 10%) < 1%, continuous purge via ultracoding
Security (security score) Attack surface not controlled Possible leaks (Shadow AI) Access control, secret management NIS2-ready, > 95% > 99.5%, PQC-ready, zero untracked incidents
Workflows & agents None One-off assistants 2-5 measured use cases Agents supervised (defined scopes) AI-first, multi-agent orchestration in production, agent-ready IS (A2A/MCP interop)
Value & FinOps None Costs not measured ROI tracked, budget in P&L Mature FinOps (gateway, cost/task) Value on the P&L, “Owned Intelligence”

Full detail and the 12-point self-diagnostic grid: the dedicated article (in French) →

Chapter 3: The 5 fatal mistakes

43% of major AI initiatives are judged doomed to fail, for lack of execution (HCLTech, May 2026)[5]. Gartner, Deloitte and McKinsey converge on similar findings[4][20][6]. And the CIO Playbook 2026 (IDC-Lenovo) drives the point home: only 46% of POCs reach production[27]. Five mistakes are responsible[8]. None is technological. All are mistakes of execution discipline.

Mistake 1: The gadget syndrome

Choosing a tool before formulating a problem. Six months later, the subscription costs more than it delivers.
Antidote: never buy a tool before naming the process, the target users, and the expected, quantified benefit.

Mistake 2: The perpetual-POC trap

More than half of AI POCs remain dead letters: only 46% reach production (CIO Playbook 2026, IDC-Lenovo)[27].
Antidote: define the criteria for the transition to production before the POC begins. No POC without a production plan.

Mistake 3: The lone-leader illusion

The business leader carries the matter alone. Nobody takes up the torch.
Antidote: appoint 2 to 4 internal business champions from the outset.

Mistake 4: The mirage of instant ROI

AI does not create value straight out of the box. It creates value within redesigned processes.
Antidote: every use case begins with simplifying the process. The process audit always precedes the tool selection.

Mistake 5: Data blindness

Without reliable fuel, the most sophisticated engine will not start.
Antidote: audit data quality before choosing the use case. If the data is absent or too noisy, the use case does not go ahead.

Chapter 4: Sovereignty & infrastructure

The adoption of generative AI in SMEs raises three questions of sovereignty that were absent or marginal from the debate two years ago. In 2026, they have become central to the choice of architecture.

4.1 The CLOUD Act and what it means for an SME

The Clarifying Lawful Overseas Use of Data Act (CLOUD Act, United States, 2018, §2713)[22] allows US authorities to compel disclosure of data held by a US-based service provider, even where physically stored in Europe. For a French SME handling confidential B2B data, pricing, margins or intellectual property, this accessibility creates a legal and commercial risk, particularly in healthcare, defence, energy and finance.

The practical MATIA rule: classify data before choosing the provider.

4.2 On-premise vs sovereign cloud: decision matrix

Option Who it is for Cost (50-500 staff) Maturity required
US hyperscaler cloudLow-sensitivity data€5,000-30,000/yearArtisan / Orchestre
European sovereign cloudSensitive data€10,000-50,000/yearOrchestre / Architecte
On-premiseCritical data, OIV/OSE€50,000-250,000 initial + €30,000-80,000/yearArchitecte / Pionnier

On-premise ROI: per MATIA field feedback[8], an industrial SME shifting 80% of its AI calls on-premise (Mistral or Llama-class) recovers its investment in 18 to 30 months above 5 million tokens/month. Quantization (section 4.4) reduces the capex component and can bring this closer to the lower bound for narrow, high-volume use cases, but the determining factor remains adoption, not hardware.

4.3 Open-weight has caught up with the frontier: what this means for sovereignty

For two years, the “sovereignty” argument ran into a technical objection: open models were significantly behind proprietary US models. In 2026, that objection fell away, and the gap has kept narrowing.

  • The capability gap has narrowed to a few points. A year ago, the best open-weight model (DeepSeek V3 0324) topped out at 22 on the Artificial Analysis Intelligence Index, 13 points behind the best proprietary model; by 30 April 2026, the best open models (Kimi K2.6, MiMo V2.5 Pro) reached 54 against 60 for GPT-5.5, a gap of 6 points[33]. On 16 June 2026, GLM-5.2 (Z.ai lab, MIT licence) became the first open-weight model in the index and matched GPT-5.5 on the GDPval-AA agentic sub-benchmark[33].
  • A French laboratory remains in the frontier race under a permissive licence. Mistral Large 3 (2 December 2025) is a Mixture-of-Experts model with 675 billion parameters (41 billion active), released under the Apache 2.0 licence[31]: an SME may legally download, fine-tune and run it on its own hardware, with no royalty and no data leaving its premises. Mistral has since released Mistral Medium 3.5 (30 April 2026, 128B, open-weight, modified MIT licence).
  • The hardware floor has collapsed. Google released Gemma 4 in April 2026 (Apache 2.0): unquantised weights fit on a single 80 GB GPU, quantised versions run offline on a phone, a Raspberry Pi or an NVIDIA Jetson[32].
  • Usage prices are collapsing too. A leading open model such as DeepSeek V4-Flash is priced at ~$0.14 / $0.28 per million tokens (input/output)[43]. Open models remain weaker on factual recall (SimpleQA), hence the importance of grounding (RAG) and verification, matters of method, not model.

Business leader takeaway. Model weights have become a commodity. An SME's lasting advantage can no longer come from the model itself: it comes from how the business organises itself around it. Sovereignty, once a costly performance compromise, is now a genuinely available option.

4.4 Hardware no longer justifies a wait-and-see approach: quantization

Two long-standing objections to on-premise deployment, quality loss and hardware cost, have been largely resolved in 2025-2026 by quantization.

  • Quality holds up at low precision. At 4 bits, degradation falls to only −1.2% to −2.5% on major benchmarks (MMLU, HumanEval, MATH), for retained quality of around 95% in INT4, 97-98% in INT8 and ~99% in FP8[34]. A 70B model goes from ~140 GB to 36-40 GB in INT4[35].
  • Hosting costs have fallen sharply. A 70B model quantised to 4 bits fits on ~48 GB of VRAM, a single-card professional workstation (~€3,000-3,500). “We cannot afford a data centre” no longer holds.

The challenge shifts from hardware to integration, security and change management, confirming, rather than contradicting, this white paper's thesis: transformation is won through method.

4.5 Where European sovereign infrastructure stands

Europe will not win the race for raw computing power: the US accounts for ~74.5% of AI supercomputer performance, China ~14.1%, the EU ~4.8% (Epoch AI, May 2025)[36]; the CNAS Sovereign AI Index (April 2026) confirms: the US and China together control ~90% of frontier computing power[36]. US hyperscalers control more than 85% of the European cloud market[37]. This is precisely why an SME's advantage is organisational, and why choosing a European building block is risk management, not activism.

The sovereign market is scaling up fast: Gartner (February 2026) expects global sovereign cloud (IaaS) spending to reach $80 billion in 2026 (+35.6%), with Europe surging by +83% (from $6.9 to $12.6 billion), overtaking North America as early as 2027[48].

  • Commercial providers available now. OVHcloud AI Endpoints offers 40+ open-weight models via API, EU-hosted, zero data retention; Scaleway operates NVIDIA H100 clusters and OpenAI-compatible APIs, EU data[38].
  • A funded infrastructure trajectory. Mistral targets 200 MW in 2027 and 1 GW in 2030 (€4 billion plan), with a sovereign data centre at Bruyères-le-Châtel (44 MW, ~13,800 NVIDIA GB300 GPUs, mid-2026) backed by an $830 million debt raise led by Bpifrance[39]. At EU level, InvestAI mobilises ~€200 billion towards 2030, including €20 billion for 4-5 “AI Gigafactories”; in June 2026, a French consortium, AION (Scaleway, EDF, Orange, iliad, Capgemini…), bid for one[40][49].

Business leader takeaway. Sovereign capacity usable immediately comes from commercial providers; gigafactories are a 2027+ horizon. An Orchestre-level SME can start today on a European sovereign cloud, keeping reversibility to on-premise for its most critical data.

4.6 ANSSI's PQC timeline (2027-2035)

ANSSI[23] published its guidance on migration to post-quantum cryptography (PQC) as early as 2022, updated in 2024. The timeline is now explicit: 2027, end of certifications for products lacking PQC (confirmed June 2026); 2030, public bodies and businesses should only acquire PQC-ready products; 2035, full transition expected, a deadline set by the EU's coordinated PQC roadmap (June 2025)[23]. AI architecture choices made today (encryption of knowledge bases, model-call channels, logs) must be compatible with this migration.

4.7 NIS2 and the Data Act: concrete obligations

NIS2 (EU Directive 2022/2555)[24] extends cybersecurity obligations to a broader range of businesses. For an SME, two situations to clarify: being an essential/important entity under NIS2, or a supply-chain provider to one (enhanced contractual obligations). The Data Act (EU Regulation 2023/2854)[25], applicable since 12 September 2025, reorganises rights over data generated by connected devices and imposes interoperability and portability obligations.

4.8 Practical recommendation: the 2×2 matrix

Constrained infra budget (< €30,000/yr) Available infra budget (> €30,000/yr)
Low-sensitivity dataHyperscaler cloud with strict access controlEuropean sovereign cloud (recommended)
Sensitive dataEuropean sovereign cloud, excluding US hyperscalersOn-premise for critical data + sovereign cloud for the rest

The MATIA rule: start simple, segment progressively.

Chapter 5: Mastering the cost of AI: FinOps & governance

The cost of generative AI is not linear. Without governance, it spirals out of control. An Artisan-level SME can consume €2,000-10,000/month without measuring the value. An Architecte-level SME that has mastered its FinOps consumes €1,500-3,000/month, and derives measurably more value. The difference is not the technology; it is the governance.

The 2026 FinOps paradox. The price of the token is collapsing: at constant performance, a study revised in March 2026 (Gundlach et al., The Price of Progress) measures a decline of ~5 to 10× per year for frontier models (up to 31× per year for the top segment)[41]. In June 2026, companies paid around $0.72 per million tokens on a weighted average basis, the lightest models falling to $0.07[42]. And yet AI bills are exploding: between January 2025 and April 2026, token consumption jumped by +1,001% while spending rose by +497% (Ramp, June 2026)[42], agentic workflows multiply calls. Early 2026: Uber had exhausted its entire annual AI budget by April[42]. Cheaper tokens do not produce a lower bill: they produce a bill that is harder to steer. The lever is no longer the unit price: it is governance.

5.1 Why AI costs are exploding in SMEs

  1. Proliferation of individual accounts: no consolidated visibility.
  2. Redundant calls: no caching, no intelligent routing.
  3. Absence of a baseline and thresholds: nobody knows how much is being spent.

5.2 LLM Gateway: the primary lever

An LLM Gateway (a centralised proxy between users/apps and models) is the number one operational lever. Open-source options as of May 2026: LiteLLM, Portkey, Helicone, Langfuse. Commercial SaaS: Portkey (paid), TrueFoundry, Cloudflare AI Gateway. Benefits observed on MATIA engagements[8]: cost reduction of 30 to 60%, centralised logging, rate limiting, access control and secret management.

The right reflex for 2026: route to small models. The 2026 consensus favours a heterogeneous architecture: simple tasks go to a small language model (SLM), only complex requests escalate to a large model. For high-volume repetitive tasks, this routing reduces inference cost by up to 90%, NVIDIA now describes SLMs as the “future of agentic AI” (InfoWorld, May 2026)[44].

5.3 ISO 42001: the governance framework

ISO/IEC 42001:2023[21] is the first international AI Management System framework. For an SME, it is not a prerequisite but an 18-36 month target for Architecte and Pionnier levels. Four principles apply immediately from Orchestre onwards: documented AI policy, register of AI systems, risk assessment, six-monthly management review. ~40% of AI tenders in mid-2026 include ISO 42001 in their criteria[8].

5.4 TCO and ROI: the right equation

TCO item Year 1 share Change
Support (transition manager, consulting)35-50%Falls sharply
Licences and API calls10-25%Stable or growing
Infrastructure (cloud, GPU)5-15%Grows with maturity
Integration and development10-20%Falls
Skills (training, recruitment)10-20%Stable, structural
Governance and compliance3-10%Grows with maturity

ROI = measured productivity gains + attributable additional revenue + quantifiable risks avoided. Measure monthly, aggregate quarterly, never quote a ROI figure without the methodology underpinning it.

5.5 Monthly budget governance

  1. Monthly dashboard: total cost, cost per use case, per user, cost/value ratio.
  2. Threshold alerts automatic per use case.
  3. Quarterly review by the AI committee.
  4. Annual review incorporated into the following year's budget.

Key takeaway. The postponement of AI Act obligations after the Digital Omnibus (§1.4) does not mean postponing internal governance, quite the opposite. It is an 18-24 month window to embed FinOps and ISO 42001 practices before compliance becomes binding.

Chapter 6: The 5-phase methodology

The MATIA Method™ approach unfolds over five phases across 12 months. Designed for an SME/mid-cap of 50 to 500 employees, supported by an external transition manager. Total budget (support + licences + tools): €30,000 to €80,000 for an Artisan → Orchestre transition[8].

Phase 1: 360° diagnostic (weeks 1 to 3)

Mapping of critical business processes, data audit, the stance of the business leader and executive committee. Deliverable: a 15-25 page report, presented to the executive committee, concluding with 3 to 5 priority use cases ranked by impact/effort.

Phase 2: Scoping the use cases (weeks 4 to 6)

For each case: scope, target users, data, candidate tools, budget, expected ROI, risks, go-live plan. One hour of scoping saves twenty hours of deployment[8].

Phase 3: Preparing the foundations (weeks 7 to 12)

AI usage charter, data policy, three-tier training plan (executive committee, managers, operational staff), target architecture (cloud, hosting, LLM gateway), priority data structuring, initial ISO 42001 elements.

Phase 4: Pilot deployments (weeks 13 to 26)

Sprints of 4 to 6 weeks, one use case per sprint. End user identified, success indicators defined before launch, monthly executive committee review. No go-live without the success indicators being met.

Phase 5: Consolidation and governance (months 7 to 12)

Industrialisation, AI Act register, quarterly AI committee chaired by an executive committee member, monthly FinOps dashboard, year 2 roadmap.

Commanding AI: from prompting to context engineering

A cross-cutting skill spanning all five phases emerged in 2025-2026: context engineering, or “commanding AI”. Where 2023 required learning to write prompts, 2026 requires building the context in which AI operates. For an Orchestre-level SME or above, this is not an individual skill. It is a team discipline with three tiers: leaders' AI literacy, managers' scoping ability, operational staff's tool mastery[26].

Chapter 7: INDUSTEC case study

INDUSTEC (anonymised name) is a French industrial SME with 78 staff and €23.5 million in revenue[10]. Engagement launched April 2025, measured at 9 months (January 2026).

Starting point: Artisan level

Three individual, uncoordinated uses: a sales rep on ChatGPT, the communications manager on LinkedIn, the technical director testing Mistral. No shared tool, no process affected, no benefit measured[10]. A typical Artisan profile.

Priority use case: drafting technical quotes

600 to 800 quotes per year, 2 to 4 hours of drafting each. Scoping: an internal assistant drawing on a structured product repository, templates, and the history of 1,800 quotes issued since 2022. Indicator: a reduction of at least 50% in drafting time[10].

Results at 9 months

  • 275 hours saved per month (1.7 FTE freed up, redeployed to account management).
  • +18% in revenue across the commercial scope concerned. Quote → order conversion: 38% → 44%.
  • ROI of 182% documented at 9 months, consolidated over 12 months. Total cost of €44,000 recouped by the 5th month[10].

Confirmed shift to a stabilised Orchestre

Beyond the figures: a move from personal curiosity (Artisan) to a process embedded, measured, extendable (Orchestre). Two further use cases scoped for 2026: competitive intelligence, client visit reports. Trajectory towards Architecte mapped out for 2027-2028 (proprietary technical knowledge base).

Anonymised case study. The results derive from a specific engagement and do not constitute a guarantee for other organisations. ROI depends on sector context, initial maturity, team commitment and quality of execution. Past performance is not indicative of future results.

Chapter 8: 12-month roadmap

Standard template for an Artisan → Orchestre engagement. Adapt with the use cases selected in phase 1.

Quarter 1: Diagnostic and foundations

  • 360° diagnostic and scoping of the 3 to 5 priority use cases.
  • AI usage charter approved by the executive committee.
  • Appointment of 2 to 4 internal champions.
  • Three-tier training plan approved.
  • Initial ISO 42001 elements (policy, minimal register).

Quarter 2: First pilot deployment

  • Sprints 1 and 2 on the priority use cases.
  • LLM gateway and initial FinOps dashboard.
  • First monthly executive committee review.

Quarter 3: Industrialisation and expansion

  • Sprints 3 and 4.
  • Industrialisation of the Quarter 2 use case.
  • Full-format AI Act register.
  • Measurable FinOps optimisations (-15% to -25% vs. initial trajectory).

Quarter 4: Consolidation and year 2 roadmap

  • Consolidated measurement of benefits over 12 months.
  • Quarterly AI committee established.
  • Year 2 roadmap approved, including the ISO 42001 trajectory and the Architecte plan.

Chapter 9: Conclusion & taking action

The window is still open

AI transformation is not a matter of technology. It is a matter of execution discipline. The tools are available, the methods are documented. What is lacking in most SMEs is not resources: it is the framework that turns those resources into results.

The 5-level MATIA Method™ Scale and the 5-phase methodology presented here are a response to this gap. They are not magic: they do not do away with scoping work, executive committee commitment, or investment in training. But they chart a path that is practicable, measured and repeatable.

The post-Digital Omnibus timetable (§1.4) offers a window (18 to 24 months) to put governance properly in place before high-risk obligations become binding in late 2027 / mid-2028. SMEs that use this window to move Artisan → Orchestre, then Orchestre → Architecte, will secure an advantage that latecomers will only close in a rush.

Where is the frontier heading? What those building it are saying

A business leader is entitled to wonder whether all this will be swept away by the next wave. Here is what those building the frontier, with no guarantee as to timing, state, as of June 2026:

  • Demis Hassabis (Google DeepMind, May 2026) has narrowed his window for human-level AI (“AGI”) to 2029-2030, from 2030-2035 a year earlier[45].
  • Dario Amodei (Anthropic, January 2026) believes “powerful AI” could be just one or two years away, “although it could also be considerably further off”, he notes himself[46].
  • The Stanford AI Index 2026 documents a genuine acceleration: performance on SWE-bench rose from ~60% to close to 100% of human level in a single year[29].

But the same edition provides the honest counterweight: these models, which win gold at the International Mathematical Olympiad, correctly read an analogue clock only 50.1% of the time[29]. Capability is “jagged”: superhuman on one task, failing on the next.

What conclusion should a business leader draw? The date of AGI is disputed; its trajectory is not. Yet the more the technology becomes a commodity, the more the only lasting advantage becomes organisational. BCG puts a figure on it: a clear AI strategy captures +25 points of impact, against only +5 points for buying better tools alone[47]. The right response to uncertainty is not to wait. It is to be ready.

What comes next? From diagnosis to industrialisation

This white paper answers where do you stand? The next question follows quickly: how do you move from the first pilots to daily, measured, governed use? That is the subject of the second white paper in the series, “From PoC to Industrialisation: Leading AI Change Management in European SMEs” (June 2026 edition, FR + EN). It documents the seven frictions of the “last mile”, the five levers of change management and AgentOps, because only 46% of AI POCs reach production[27], and this wall is 70% human, not technological[28].

→ Read white paper no. 2: From PoC to Industrialisation

AI Express Audit & Roadmap: the first step

To position your company on the MATIA Method™ Scale and chart a 90-day roadmap, the AI Express Audit & Roadmap is designed as a calibrated first step:

  • 60 minutes by video conference, with no obligation.
  • Positioning of your SME on the 5 levels.
  • Identification of 3 priority use cases.
  • An initial 90-day roadmap, delivered in writing within the week.

This first step, short but committing, often makes the difference between projects that get off the ground and those that remain at the intention stage. The approach complies with the Osez l'IA framework (Bpifrance)[14] and may form part of a public funding pathway.

Sources: verifiable, June 2026

  1. [1] Bpifrance Le Lab / Rexecode, biannual business-climate barometers for micro-businesses and SMEs. 82nd biannual barometer (January 2026): 55% reported AI use at end of 2025; Q2 2026 barometer (fieldwork 13-26 April 2026, 1,135 respondents, published 19 May 2026): 58% reported use, of which almost half daily; 43% of business leaders report a productivity gain; leading barrier = difficulty identifying relevant use cases (~54%). presse.bpifrance.fr
  2. [2] KPMG, Global AI Pulse, Q1 2026 (survey 17 February to 17 March 2026, 2,110 business leaders, 20 countries), 31 March 2026. kpmg.com: 11% of organisations are “AI leaders”; 82% of leaders report significant business value versus 62% of others; 32% deploy or scale AI agents.
  3. [3] Bpifrance Le Lab, AI in French SMEs and mid-caps (fieldwork October-December 2024, 1,209 business leaders). Supplemented by INSEE Première n°2061, ICT in businesses in 2024 (July 2025): 10% of businesses with 10+ employees used AI in 2024. insee.fr
  4. [4] Gartner, Hype Cycle for Agentic AI (April 2026): at least 50% of generative AI projects abandoned after the pilot phase; more than 40% of agentic AI projects abandoned by 2027. AI Maturity Model Toolkit (5-level model), 2025-2026. gartner.com
  5. [5] HCLTech, AI Impact Imperatives 2026 (20 May 2026, survey of 467 business leaders at companies with revenue above $1 billion): 43% of major AI initiatives are judged likely to fail, mainly due to an organisational “execution gap”. hcltech.com
  6. [6] McKinsey, The State of AI Trust in 2026 (25 March 2026, ~500 organisations): average score 2.3 out of 4, only one organisation in three at level 3 or above. mckinsey.com
  7. [7] Denis Atlan, AI & ROI Barometer for French SMEs 2022-2025, 2026. More than 200 B2B AI deployments analysed: median ROI of 159.8% measured over 24 months, 73% success rate. denisatlan.fr (DOI: 10.5281/zenodo.17795133).
  8. [8] Croissance et Transitions, consolidated field feedback: more than 30 documented AI engagements in French SMEs and mid-caps since 2024.
  9. [9] Regulation (EU) 2024/1689 of 13 June 2024 (Artificial Intelligence Act). eur-lex.europa.eu: timeline updated by the Digital Omnibus [15].
  10. [10] INDUSTEC case study (anonymised name): MATIA Method™ engagement, April 2025 to January 2026, figures consolidated over the last 6 months of live production use (July-December 2025). Data from the client's internal reporting, validated by the monthly executive committee.
  11. [11] ADP Research, People at Work 2026 (nearly 40,000 workers, 36 countries; France n = 1,051, June 2026): in France, 11% use AI almost daily, 24% several times a week, 29% never, versus 20% near-daily use globally. adpresearch.com
  12. [12] DGE / France Num, Baromètre France Num 2025, 6th edition, September 2025, 11,021 businesses. francenum.gouv.fr: 26% used at least one AI tool in 2025 (×2 vs 2024); by size: 23% (1-4), 31% (10-19), 35% (20-49), 42% (50-249).
  13. [13] Microsoft, Work Trend Index 2026: Annual Report, 5 May 2026. microsoft.com/worklab: “Frontier Firms” (19% at Frontier organisations, 16% “Frontier Professionals” orchestrating agents), gap between leaders and employees on agents (67% vs 40%), Owned Intelligence.
  14. [14] Bpifrance, Plan Osez l'IA, July 2025; Diag Data IA. bpifrance.fr: €200 million envelope, target 80% of SMEs/mid-caps at Orchestre+ by 2030. Since 1 January 2026: flat-fee diagnostic of €10,000 excl. VAT subsidised at 25% (mid-caps not eligible); IA Booster funds up to 80%.
  15. [15] Council of the European Union, Digital Omnibus: political agreement, press release of 7 May 2026. consilium.europa.eu: high-risk AI Act deferred to end of 2027 / 2 August 2028.
  16. [16] Gartner, AI Maturity Model: 5 levels (Awareness, Active, Operational, Systemic, Transformational), 2025-2026.
  17. [17] PwC, The AI-Native Enterprise: 5-level maturity model, 2026. pwc.com.au
  18. [18] Microsoft, Agentic AI Adoption Maturity Model (Copilot Studio): L100 to L500, 2025-2026. learn.microsoft.com
  19. [19] BCG, AI Radar 2026: As AI Investments Surge, CEOs Take the Lead (15 January 2026, 2,360 business leaders including 640 CEOs, 16 markets). bcg.com: Trailblazers ~15% / Pragmatists ~70% / Followers ~15%; 72% of CEOs the primary AI decision-maker; > 30% of AI budget on agentic AI.
  20. [20] Deloitte, State of AI in the Enterprise 2026: The Untapped Edge (21 January 2026, 3,235 business leaders, 24 countries). deloitte.com: only 30% redesign key processes around AI, 37% use it superficially; only 21% have mature agent governance.
  21. [21] ISO/IEC 42001:2023, Artificial Intelligence Management Systems: Requirements, ISO, December 2023. iso.org
  22. [22] CLOUD Act (United States, 2018), §2713: Clarifying Lawful Overseas Use of Data Act. congress.gov
  23. [23] ANSSI, Guidance on migration to post-quantum cryptography, first published 2022, updated 2024 and 2026. cyber.gouv.fr: national timeline 2027/2030. The 2035 deadline follows the EU's coordinated PQC roadmap (June 2025).
  24. [24] Directive (EU) 2022/2555 (NIS2) of 14 December 2022. eur-lex.europa.eu
  25. [25] Regulation (EU) 2023/2854 (Data Act) of 13 December 2023. eur-lex.europa.eu: main provisions applicable since 12 September 2025.
  26. [26] Croissance et Transitions / MATIA Method™, article The end of prompt engineering: from prompt to context engineering, May 2026 (28 sources).
  27. [27] IDC / Lenovo, CIO Playbook 2026: The Race for Enterprise AI (January 2026, n = 800): only 46% of POCs reach production; 94% anticipate a positive ROI, $2.78 of expected value per dollar invested. news.lenovo.com
  28. [28] BCG, AI Transformation Is a Workforce Transformation (2026). The 10-20-70 rule: 10% algorithms, 20% technology and data, 70% redesigning the human factor and processes. bcg.com
  29. [29] Stanford HAI, The 2026 AI Index Report, 20 April 2026: 88% use AI in ≥1 function, <10% at scale; SWE-bench ~60% → ~100% of human-level in one year; “jagged” capability (gold at the IMO, analogue clocks read correctly only 50.1% of the time). hai.stanford.edu
  30. [30] OECD, AI adoption by small and medium-sized enterprises (December 2025): OECD adoption from 5.6% (2020) to 14% (2024); only 29% of SMEs using generative AI apply it to their core business. oecd.org
  31. [31] Mistral AI, Mistral Large 3 (2 December 2025, MoE 675B/41B, Apache 2.0). mistral.ai; since: Mistral Medium 3.5 (30 April 2026, 128B, open-weight, modified MIT).
  32. [32] Google DeepMind, Gemma 4 (2 April 2026, Apache 2.0): unquantised weights on a single 80 GB GPU; quantised versions offline on phone, Raspberry Pi or NVIDIA Jetson. blog.google
  33. [33] Artificial Analysis, Intelligence Index: 30 April 2026, best open models at 54 vs 60 for GPT-5.5 (6-point gap); 16 June 2026, GLM-5.2 (Z.ai, MIT) leads the open-weight index. artificialanalysis.ai
  34. [34] Sesame Disk, Quantization Techniques for AI Inference in 2026 (14 May 2026). Quality retained vs BF16: ~99% (FP8), ~97-98% (INT8), ~95% (INT4); 4-bit degradation −1.2% to −2.5% (MMLU/HumanEval/MATH). sesamedisk.com
  35. [35] VRLA Tech, LLM Quantization Explained: INT4, INT8, FP8, AWQ and GPTQ in 2026 (April 2026). vrlatech.com
  36. [36] Epoch AI, AI supercomputers performance share by country (May 2025): US ~74.5% / China ~14.1% / EU ~4.8%. epoch.ai; confirmed by CNAS, Sovereign AI Index (April 2026): US and China ~90% of frontier compute. interactives.cnas.org
  37. [37] EU Perspectives, Europe bets on EuroStack (February 2026): US hyperscalers > 85% of the EU cloud market; EuroStack ~€300 billion. euperspectives.eu
  38. [38] OVHcloud, AI Endpoints (40+ open models, zero retention, EU hosting) ovhcloud.com ; Scaleway, Generative APIs (H100 clusters, OpenAI-compatible, EU data) scaleway.com
  39. [39] Maddyness, Mistral AI targets one gigawatt of computing capacity by 2030 (28 May 2026): 200 MW in 2027, 1 GW in 2030, €4 billion; sovereign data centre at Bruyères-le-Châtel ($830 million debt round led by Bpifrance, March 2026). maddyness.com
  40. [40] European Commission, InvestAI / AI Gigafactories: ~€200 billion towards 2030, €20 billion for 4-5 gigafactories. digital-strategy.ec.europa.eu
  41. [41] Gundlach, Lynch, Mertens & Thompson, The Price of Progress: Price Performance and the Future of AI (arXiv:2511.23455, revised 23 March 2026): inference cost at constant performance divided by ~5-10×/year (up to 31×/year for the top segment). arxiv.org
  42. [42] Ramp, The cost of AI tokens for businesses (8 June 2026): token consumption +1,001% vs spend +497% (Jan 2025-Apr 2026); average price $0.72/M tokens. ramp.com; see also TechCrunch, The token bill comes due (5 June 2026): Uber exhausted its 2026 AI budget by April. techcrunch.com
  43. [43] DeepSeek, API pricing (2026): DeepSeek V4-Flash at ~$0.14 / $0.28 per million tokens, MIT licence. api-docs.deepseek.com
  44. [44] InfoWorld, Small language models: rethinking enterprise AI architecture (4 May 2026): SLM routing cuts inference cost by up to 90% on high-volume repetitive tasks. infoworld.com
  45. [45] Demis Hassabis (Google DeepMind), AGI window narrowed to 2029-2030 (statements May 2026, Google I/O / Axios interview).
  46. [46] Dario Amodei (Anthropic), The Adolescence of Technology (January 2026): “powerful AI” possible within 1-2 years, with an explicit caveat. darioamodei.com
  47. [47] BCG, AI at Work 2026: Why Strategy Matters More Than Tools (3 June 2026, 11,749 employees, 14 markets): a clear AI strategy = +25 points of impact, vs ~+5 points for better tools alone. bcg.com
  48. [48] Gartner, Worldwide Sovereign Cloud IaaS Spending (9 February 2026): $80 billion in 2026 (+35.6%); Europe from $6.9 to $12.6 billion (+83%), overtaking North America in 2027. gartner.com
  49. [49] AION (Ardian, Artefact, Bull, EDF, Capgemini, iliad, Orange, Scaleway), bid for a French AI Gigafactory under InvestAI (5 June 2026). storagenewsletter.com

The percentage breakdown by level (~50% Spectateur, ~30% Artisan, ~13-15% Orchestre, ~2-3% Architecte, < 0.5% Pionnier), like the “≈11% of genuinely documented value” ratio, are estimates built by cross-referencing sources [1], [2], [11], [12] and [19], calibrated against field feedback [8]. They do not come from a single survey but from an integrated reading of the indicators available as of June 2026.

White paper “AI Maturity of French SMEs 2025-2026: MATIA Method™”, by Paul-Antoine TUAL, AI Transformation Leader · Croissance et Transitions. Initial edition May 2026 (golden standard, v2.0). Published: 23 May 2026. Revision v2.1: 12 June 2026. Revision v2.2: 22 June 2026 (deep research: correction of attributions, enrichment of sovereignty & FinOps content, AGI horizon section). Last revision: 23 June 2026. June 2026 Edition, v2.3: strict freshness pass (all AI market sources older than six months replaced with their 2026 equivalents; regulations and foundational evidence retained, dated). Next revision scheduled: November 2026. English translation published 8 July 2026. Master document: maintained in Markdown (content/livre-blanc-maturite-ia-pme-EN.md), generated as canonical HTML here and distributed as PDF.