EU AI Act drives global corporate governance shift: Data from Washington to Tokyo

2

Brussels likes to think it’s the world’s regulator-in-chief.

Usually, that comes with a side of eye-rolling.

But the data says something else.

A new analysis from the Thomson Reuters Foundation shows the EU AI Act is already rewriting corporate rules far beyond Europe’s borders.

It’s not just compliance theater. It’s a structural shift.

Nearly half of the companies mentioning the EU AI Act in their governance disclosures are not headquartered in the EU.

That is the “Brussels Effect” in motion.

Same as it was with the GDPR, only faster.

Why global firms cite the EU AI Act now

The report, based on the AI Company Data Initiative, scanned more than 100,00 data points from 2,973 firms worldwide.

The result?

47% of firms referencing the Act in their public disclosures are outside the bloc.

This isn’t universal adoption.

Only 13% of all companies surveyed have a formal AI governance framework. Period.

But of that small, serious 13%, 53% specifically cite the EU AI Act.

And within that group, the international share is massive.

Why are they doing this?

Incentives.

The Act applies extraterritorially.

If your AI system is used in the EU, or if its output affects EU citizens, you are liable.

Penalties hit hard: €35 million or 7% of annual global revenue for serious breaches.

No EU presence required.

For multinationals, ignoring Brussels isn’t an option. It’s a business risk they can’t afford.

“The effect is not yet broad-based, but it is significant, concentrated where market incentives to align are strong.”

Where is this happening most?

Geography matters.

Industry matters.

IT firms alone account for 40% of non-EU companies citing the Act.

Communication and financial services add another 29%.

Look at the regions:

  • North America: Nearly 40% of non-EU engagement. Driven by US tech and healthcare firms with EU market exposure.
  • Non-EU Europe: Around 24%. UK, Swiss, and Norwegian firms have tight commercial ties to the bloc.
  • Asia: Roughly 28%. Concentrated in tech firms embedded in global AI supply chains.

The United States is the most striking outlier.

It has no federal AI law.

Yet US companies make up 35% of all non-EU citers of the Act.

The single largest national contributor.

Within the US, 53% are from the IT sector.

One in five US IT firms in the study references the Act.

Highest rate of any sector in any country.

Who is leading this?

Microsoft. Google. OpenAI. xAI.

They aren’t waiting for Washington to act.

They are voluntarily aligning with elements of the EU’s AI Code of Practice.

Access to the European market is the driver.

Period.

The gap between policy and practice

Mentioning the Act is the easy part.

Actually doing the work is where it gets messy.

Firms that cite the Act generally have the basics covered.

They have an AI strategy.

Board-level oversight.

Transparency around data usage.

Non-EU firms actually outperform EU counterparts here.

EU companies lead on workforce training.

49.4% offer reskilling or AI literacy programs.

Non-EU firms lag at 40.6%.

But oversight isn’t enough.

You need to check what the AI is doing.

Case by case.

Right now, only 12.4% of global companies require a human to review individual AI decisions.

And nearly half of those haven’t figured out how to implement it in practice.

Rights checks are even rarer.

Fewer than 25% of companies assess whether their AI harms employee rights.

Even among those most engaged with the Act.

This gap is about to close.

Or rather, be enforced.

From August 2026, the Act’s full weight kicks in.

High-risk systems—hiring, credit, healthcare—must undergo these checks before rollout.

Results must be reported to regulators.

Voluntary alignment won’t save you then.

The timeline for full enforcement

The Act has been in force since 2021, with obligations phased in since 2024.

Bans on the riskiest uses and transparency rules for general-purpose models take effect by December 2025 already.

But August 2026 is the real cliff edge.

That is when the high-risk rules become fully binding.

For sectors like healthcare and finance, the scrutiny intensifies.

For others, the pressure is already building.

Companies in Washington, Tokyo, and London are watching.

They are seeing that regulation doesn’t stop at borders.

It follows the money.

And it follows the risk.

The US approach of “move fast and break things” is meeting a wall in Europe.

A wall that non-US companies are building into their own foundations.

Whether the rest of the world follows suit depends on whether they want to play in the European market.

For now, the blueprint is clear.

The question is execution.

Because writing a policy is one thing.

Stopping an algorithm from discriminating is another.