Key facts
- Nearly half of companies citing the EU's AI Act in governance disclosures are based outside the EU.
- The EU AI Act is considered the first comprehensive, cross-sector AI law.
- The Act applies to AI systems used in the EU or whose outputs affect EU citizens.
- High-risk AI system rules become fully binding in August 2026.
- US companies are the largest national contributor among non-EU firms citing the Act.
The European Union's Artificial Intelligence Act is demonstrating a significant global influence, extending its regulatory reach far beyond the bloc's borders. New research indicates that nearly half of the companies referencing the Act in their governance disclosures are not based in the EU, suggesting Brussels is establishing a de facto global standard for AI governance.
The analysis, conducted by the Thomson Reuters Foundation using data from its AI Company Data Initiative (AICDI), examined over 100,000 data points from 2,973 companies worldwide. It found that 47% of firms citing the EU AI Act in their disclosures are headquartered outside the EU. This phenomenon, termed the 'Brussels Effect,' mirrors the global impact of the EU's General Data Protection Regulation (GDPR).
The EU AI Act, which has been in force since 2024 with obligations phasing in gradually, is the first comprehensive, cross-sector AI law. Its extraterritorial scope means it applies to any organization whose AI systems are used within the EU or whose outputs affect EU citizens, businesses, or public institutions. Penalties for serious breaches can reach up to €35 million or 7% of global annual revenue.
Despite the Act's influence, only 13% of companies globally have any formal AI governance framework. Of those with a framework, 53% specifically reference the EU AI Act, and of that subset, 47% are located outside the EU. The tech sector leads engagement, with information technology firms accounting for nearly 40% of non-EU companies citing the Act.
Regionally, North America leads non-EU engagement with nearly 40%, driven by US technology and healthcare firms. European companies outside the EU, particularly from the UK, Switzerland, and Norway, follow at around 24%. Asian firms represent about 28%, concentrated in technology companies within global AI supply chains.
The United States, despite lacking a federal AI law, shows the most significant non-EU engagement, with American companies comprising 35% of all non-EU citers. Within the US, the IT sector is most active, with one in five US IT firms referencing the Act. Major US tech giants like Microsoft, Google, OpenAI, and xAI have voluntarily aligned with aspects of the EU's AI Code of Practice, motivated by market access.
While companies referencing the Act generally exhibit strong AI practices, including clear plans and board oversight, gaps remain. Workforce training is more prevalent among EU firms. Globally, only 12.4% of companies require human review of individual AI decisions, and fewer than a quarter assess AI's potential harm to employee rights, a requirement that will become legally binding for high-risk systems in August 2026.
