Turns out Brussels’ penchant for what is often perceived as overregulation is having a ripple effect well beyond the EU.
Nearly half of the companies referencing the EU’s Artificial Intelligence Act in their governance disclosures are not based in the EU at all, according to new research, suggesting Brussels is beginning to set a global standard for AI governance even before the bloc’s toughest rules take full effect.
The analysis, published by the Thomson Reuters Foundation using data from its AI Company Data Initiative (AICDI), draws on more than 100,000 data points collected from 2,973 companies worldwide.
It found that 47% of firms citing the Act in their disclosures are headquartered outside the EU.
The report describes this as evidence of a “Brussels Effect” in AI governance, the term used to describe the tendency of EU regulation to become a global benchmark, most notably with the GDPR.
According to the findings, the effect “is not yet broad-based, but it is visible, significant, and concentrated where market incentives to align are strongest.”
The Act, fully applicable from August 2026, is the first comprehensive, cross-sector AI law of its kind.
Its reach extends beyond the EU’s own borders, applying to any organisation whose AI systems are used in the bloc or whose outputs affect EU citizens, businesses or public institutions.
Years in the making
The Act itself has been in force since 2024, but its obligations are being phased in gradually rather than all at once.
Bans on the riskiest AI uses and transparency rules for general-purpose AI models were already in effect by December 2025. It is specifically the rules for high-risk systems, covering areas like hiring, credit and healthcare, that become fully binding in August 2026.
As with the GDPR, this extraterritorial scope means that even non-EU firms face the same binding obligations, with penalties reaching €35 million or 7% of global annual revenue for the most serious breaches.
Yet this should not be confused with a widespread trend of companies acknowledging AI use or having AI usage frameworks.
Across all sectors, only 13% of companies have any formal AI governance framework at all, regardless of whether they mention the EU AI Act.
Of that 13% who do have a framework in place, just over half, 53%, specifically reference the EU AI Act. And of that group who reference the Act, 47% are headquartered outside the EU.
Tech sector leads the way
Engagement with the Act varies strongly depending on the industry and geographic location.
Information technology firms alone account for nearly 40% of all non-EU companies citing the Act, with communication services and financial services together contributing a further 29%.
Regionally, North America leads non-EU engagement at just under 40%, driven largely by US technology and healthcare firms with a significant EU market presence.
Non-EU European companies — UK, Swiss and Norwegian firms in particular — follow at around 24%, reflecting close commercial and regulatory ties to the bloc.
Asian firms have a citation rate of roughly 28%, concentrated among technology companies embedded in global AI supply chains.
The United States offers a particularly striking example given its own hands-off approach to AI regulation.
The US has no overarching federal AI law, yet American companies account for 35% of all non-EU citers of the EU Act — the single largest national contributor.
Within the US, 53% of citing companies come from the IT sector, and one in five US IT firms in the dataset references the Act, the highest rate of any sector nationally.
Major US technology firms including Microsoft, Google, OpenAI and xAI have voluntarily aligned with elements of the EU’s AI Code of Practice, according to the report, motivated by the prospect of continued access to the European market.
The gaps behind the good scores
Companies that mention the Act tend to do the basics well. They have a clear AI plan, board-level oversight, transparency about the data they use. Non-EU firms citing the Act even outperform EU companies on this.
On the other hand, EU firms lead on workforce training, with 49.4% offering reskilling or AI literacy programmes, compared with 40.6% of non-EU firms.
But strategy oversight is one thing. Checking what the AI is actually doing, case by case, is another. Only 12.4% of companies worldwide have a policy requiring a human to review individual AI decisions, and even then, nearly half have not figured out how that works in practice.
Rights checks are rarer still. Fewer than one in four companies assess whether their AI could harm employee rights, even among the most engaged with the Act.
That part is about to matter a lot more. From August 2026, companies using high-risk AI, in hiring, credit or healthcare, will be legally required to run that check before rollout, and report the results to regulators.

