Share with your CISO
The EU AI Act, entering full effect in August 2026, is already reshaping AI governance well beyond Europe’s borders, according to new Thomson Reuters Foundation analysis of nearly 3,000 global companies. Almost half (47%) of firms voluntarily citing the Act in disclosures are headquartered outside the EU, with U.S. companies leading that group. The data shows a widening gap between stated policy and operational reality: only 12.4% of companies globally have a Human Oversight Policy, and nearly half of those lack the documented workflows to back it up.
What this means for your business
The compliance gap here isn’t evenly distributed, and where you sit on it depends less on geography than on whether your organization has EU customers or EU-domiciled vendors in its supply chain. EU buyers are already embedding AI Act requirements, including conformity assessments and deployment timelines, directly into RFPs and contracts. That means a U.S.-headquartered company with a meaningful European revenue line is functionally subject to this regulation whether or not it self-identifies as a target. The question isn’t whether the Act applies; it’s whether your procurement and vendor governance processes already reflect that reality.
The Fundamental Rights Impact Assessment (FRIA) requirement, an Article 27 obligation requiring deployers of high-risk AI systems to formally assess civil rights exposure before deployment, is where legal exposure concentrates and where almost no one is ready. Fewer than one in four companies, even among those actively citing the Act, disclose a Human Rights Impact Assessment. That number should alarm any CISO whose organization deploys AI in hiring, credit, benefits, or access decisions, all categories the Act treats as high-risk. The gap isn’t a misunderstanding of the regulation; it’s an operational maturity problem that a policy document alone can’t fix.
AI Model Registries, the internal systems that track which models are deployed, what they do, and how they’re updated across their lifecycle, remain rare even among the most Act-aware companies (around 20% for citers, 1-2% for everyone else). That’s a meaningful leading indicator: organizations that haven’t built the logging infrastructure to track model behavior can’t credibly demonstrate human oversight, and they can’t satisfy an audit. The budget decision this reframes isn’t whether to comply, it’s whether your current AI governance stack is being sized for a world where the EU standard is the global floor, not an optional export.
Concept deep-dive: Brussels Effect
The Brussels Effect describes the dynamic where EU regulations become de facto global standards because multinationals find it cheaper to apply a single compliance framework everywhere than to maintain separate ones by jurisdiction. It’s the same logic that made GDPR a worldwide privacy baseline. For AI governance, the effect is accelerating because EU customers are encoding Act requirements into contracts, meaning non-EU vendors inherit compliance obligations through commercial relationships rather than by regulatory mandate.
Based on reporting from EU AI Act Drives Global AI Governance Beyond Europe, originally published 2026-07-27 21:01:00.

