The Numbers That Matter
The Thomson Reuters Foundation report — titled The Global Impact of the EU AI Act and drawn from its AI Company Data Initiative (AICDI), the world's largest open dataset on corporate AI adoption — is not an opinion survey. It is built from public disclosures, governance filings, and corporate reporting across 11 sectors and five regions. The sample covers companies that collectively define what "enterprise AI" looks like in 2026.
Here is what stands out, point by point:
47% of citers are non-EU. The United States is the single largest source of non-EU companies engaging with the regulation. This is not companies being forced — this is companies choosing. When a regulation is written in Brussels and adopted by boardrooms in California, Singapore, and Tokyo before the enforcement hammer even drops, the mechanism is working as designed.
Fundamental Rights Impact Assessments are the biggest gap. Article 27 of the AI Act requires deployers of high-risk systems to conduct FRIAs before deployment. Fewer than 1 in 4 companies — even among those that cite the regulation — disclose a Human Rights Impact Assessment. Only 1 in 3 disclose an Ethical Impact Assessment. The legal exposure here is stark: FRIAs are not optional paperwork. They are a statutory condition for deployment.
Human oversight policy: 12.4%. That is the global number. Twelve point four percent of all companies in the dataset have a documented Human Oversight Policy. Even among those that do, 48% have not documented the operational processes — monitoring tools, intervention mechanisms, human-in-the-loop workflows — that make the policy enforceable. A policy without an implementation mechanism is a press release.
AI Model Registries are nearly non-existent outside the EU AI Act orbit. Among companies that cite the regulation, 21% of non-EU and 19% of EU firms maintain an AI Model Registry. Among non-citers? One to two percent. A model registry — a structured inventory of what models you run, what data they touch, and what decisions they make — is the minimum viable compliance infrastructure. Most companies do not have one.
The Brussels Effect, Quantified
The "Brussels Effect" — the idea that EU regulation tends to become a global standard because companies find it cheaper to comply everywhere than to maintain separate regimes — was first articulated by Anu Bradford in 2012. With the AI Act, we now have something we rarely get: a large-N dataset that measures it.
The numbers confirm the direction. Companies that cite the EU AI Act score measurably higher on every governance dimension — oversight, transparency, risk assessment, documentation — than companies that do not. The gap is not subtle. Katie Fowler, TRF's Director of Responsible Business, put it directly: "Engagement with the EU AI Act is increasingly a useful signal of governance maturity, operational readiness, and long-term resilience."
But here is what the data also shows, and what every compliance professional needs to sit with: the gap between citing the regulation and complying with it is wide. The "policy-to-practice gap," as the report names it, is the defining weakness. Companies talk about AI governance; few have built the machinery to deliver it.
Supply Chain as Transmission Belt
One finding that will matter most to mid-sized European companies: EU-based customers are already incorporating AI Act provisions into RFPs, due diligence questionnaires, and supplier contracts. Expectations around conformity assessments, documentation, and compliance timelines are appearing in procurement language now — not in 2027.
This means the Act is not just an obligation on the company that deploys the AI. It is becoming a contractual requirement passed down the supply chain. If you sell software or services to a large EU enterprise, their compliance department will ask you what AI models you use and whether they are documented. This has been true of GDPR for years; the AI Act extends the same logic to algorithmic systems.
For a small AI company based in Prague or Brno — and we run one — this is a mixed signal. On one hand, the supply chain dynamic creates market pressure that rewards early movers. On the other, the compliance burden scales poorly. A €400,000 (approximately $456,000) compliance cost per high-risk product, as estimated in European Commission impact assessments cited by the TechTimes analysis of the Digital Omnibus, hits a 20-person startup differently than a publicly traded enterprise.
What Enforcement Actually Looks Like — Starting August 2
The AI Act is not a single deadline. It is a staggered set of obligations, and several major tracks land on August 2, 2026 — this coming Sunday.
GPAI enforcement powers activate. The European AI Office gains the authority to audit general-purpose AI model providers, demand documentation, run its own technical evaluations, order corrective measures, and — at the far end — pull a model from the EU market. Fines reach 3% of global annual turnover or €15 million, whichever is higher. Providers have been obligated to comply since August 2025; starting August 2, 2026, the Commission can enforce that obligation.
Article 50 transparency obligations. Any AI system interacting with a person must disclose that it is AI. Generative AI outputs — images, audio, video, text — must carry machine-readable markers. Deepfake content depicting real people must be visibly labeled. These rules apply to any company whose AI outputs reach EU users, regardless of where the company is incorporated.
Fines for non-compliance. The penalty framework has not changed: prohibited practices (social scoring, subliminal manipulation, real-time biometric surveillance) carry fines of up to €35 million or 7% of global turnover. Transparency and GPAI violations carry up to €15 million or 3%. For context, on a business with $10 billion in annual revenue, a single GPAI violation can reach $300 million — and multiple violation routes can stack independently.
The full high-risk AI obligations — conformity assessments, CE marking, quality management systems, human oversight — for standalone systems (Annex III) now land on December 2, 2027, following the Digital Omnibus deferral. Embedded systems in regulated products land August 2, 2028. The calendar has moved, but the technical standards needed to demonstrate compliance — about 35 of them, developed by CEN-CENELEC's JTC 21 — are still not finished. The original April 2025 target slipped to a rolling horizon; analysis from Morrison Foerster suggests the full suite may not arrive before December 2026, leaving roughly 12 months of standards-backed runway.
Comparison: EU AI Act Compliance Readiness at a Glance
| Compliance metric | EU AI Act citers | Non-citers | What the Act requires |
|---|---|---|---|
| Human Rights Impact Assessment | < 25% | N/A | Mandatory FRIA under Article 27 for high-risk deployers |
| Ethical Impact Assessment | ~33% | N/A | Expected as part of governance documentation |
| Human Oversight Policy | 12.4% (global, all companies) | Required for high-risk AI systems | |
| Operational oversight processes | 52% of those with a policy have documented processes | ||
| AI Model Registry | 19% EU / 21% non-EU | 1–2% | Critical for lifecycle tracking and audit readiness |
What This Means If You Run AI in Europe
We operate production AI services from servers in the EU — article generation pipelines, transcription, TTS, benchmarking — and the compliance clock is real. Here is what we are watching:
1. Model provenance matters now. Every GPAI model placed on the EU market since August 2, 2025 is immediately auditable. Models from before that date have until August 2, 2027. If you upgraded from an early-2025 model to a late-2025 version, the enforcement clock moved with it — silently, with no contract change and no announcement.
2. The transparency rules are the first test. Chatbot disclosure, deepfake labeling, and machine-readable content marking all go live August 2. These are not delayable. If your website runs a customer-facing chatbot and you have not added a disclosure, you have six days.
3. The compliance cost is real, but the alternative costs more. Non-compliance fines at 3–7% of global turnover make a €400,000 compliance program look like a rounding error. Companies that treat the December 2027 deferral as a pause button are recreating the GDPR scramble of 2018 — except this time the fines come from the same playbook.
4. The Article 85 complaints channel is a wildcard. Any person, organization, or competitor can lodge a complaint about a specific model to the AI Office. Copyright disputes over training data are the most obvious first wave. The complaints mechanism adds unpredictability to enforcement: you cannot model the regulator's docket when anyone can fill it.
5. Smaller companies need a strategy, not an exemption. The Digital Omnibus created a "small mid-cap" category with simplified documentation templates, proportionate quality-management expectations, priority sandbox access, and a 30-day warning window before fines. These are useful simplifications, but they are not exemptions. If you deploy AI in the EU, the Act applies.
The Bottom Line
The Thomson Reuters Foundation dataset tells two stories simultaneously: one about influence, and one about readiness. The influence story is that the EU AI Act is already the global default for AI governance — 47% non-EU engagement is a number that would have been dismissed as aspirational three years ago. The readiness story is that the companies citing the regulation have not finished building the infrastructure the regulation demands.
August 2, 2026 is not the end of anything. It is the day the European Commission stops asking and starts auditing. The compliance gap — between what companies say about AI governance and what they can demonstrate — is about to become much more expensive.
Does the EU AI Act apply to US companies with no EU office?
Yes. Article 50 transparency obligations follow the same extraterritorial logic as GDPR: the trigger is market access, not incorporation. If your AI system's output reaches people in the EU, the rules apply regardless of where your servers or headquarters are located. The GPAI obligations follow the same principle.
What happens on August 2, 2026?
Three things: (1) The EU AI Office gains enforcement powers over general-purpose AI model providers — it can audit, demand documentation, and impose fines up to 3% of global turnover or €15 million. (2) Article 50 transparency obligations become enforceable: chatbots must disclose they are AI, generative outputs need machine-readable markers, and deepfakes must be labeled. (3) Article 5 prohibited practices continue unchanged.
How much does EU AI Act compliance actually cost?
European Commission impact assessments have cited approximately €400,000 (about $456,000) per high-risk product. This covers risk management systems, technical documentation, data governance, human oversight mechanisms, and conformity assessments. Costs vary by system complexity; a narrow-use recruitment screening tool costs less than a multi-purpose credit scoring platform. The Digital Omnibus introduced simplified templates for SMEs and small mid-caps that should reduce the baseline.