Five days from now, the most significant set of AI compliance obligations in the world’s first comprehensive AI law will formally take effect. On August 2, 2026, the EU AI Act’s requirements for high-risk AI systems — covering AI used in employment decisions, credit scoring, educational access, essential services, and law enforcement — become enforceable, completing the transition from the prohibited practices regime that took effect in February 2025 and the GPAI model obligations that took effect in August 2025. The companies that should theoretically be most directly affected are the approximately 10,000 companies that develop or deploy AI systems in the EU market. The companies that are actually preparing for it are a substantially larger group.
A Thomson Reuters Foundation analysis of nearly 3,000 global companies, conducted in partnership with UNESCO, has documented what AI policy researchers have been arguing theoretically for years: the EU AI Act is generating a Brussels Effect — a pattern in which EU regulation becomes the effective global standard because multinational companies find it economically rational to apply the EU’s requirements everywhere rather than maintaining separate compliance architectures for EU and non-EU markets. The most striking finding is the share of non-EU companies in the early compliance cohort, with US-headquartered firms representing the largest single source of proactive adopters outside Europe.
Key Developments
- A Thomson Reuters Foundation and UNESCO “Responsible AI in Practice” analysis of nearly 3,000 global companies found that companies proactively aligning with EU AI Act standards represent a significant share of non-EU multinationals — with the United States as the largest source of non-EU early compliance adopters.
- The Brussels Effect is confirmed as operative: companies adapting to EU AI Act requirements are doing so globally, not only for EU-market-facing products, because the cost of maintaining separate AI systems for EU and non-EU markets typically exceeds the cost of applying the stricter standard universally.
- The most significant EU AI Act obligations for global companies take effect on August 2, 2026 — five days from the article publication date — covering high-risk AI systems in employment, credit, education, and essential services, alongside GPAI model obligations already in effect since August 2025.
- Companies aligning early with the EU AI Act framework showed higher operational resilience and investor confidence in assessments, consistent with the pattern from GDPR where early adopters gained a reputational and governance advantage over laggards.
What the Brussels Effect Actually Is
From GDPR to AI Act
The Brussels Effect describes the mechanism by which EU regulations acquire global de facto application through market forces rather than legal jurisdiction. It was first systematically documented by Columbia Law professor Anu Bradford in 2012 with respect to EU product safety and data privacy regulation, and it is most commonly cited in the context of GDPR — the EU’s General Data Protection Regulation — which effectively became a global privacy standard not because EU law applies globally, but because companies with any EU market presence found it cheaper to implement GDPR’s requirements across their entire customer base than to maintain separate data handling systems for EU and non-EU users. The same economic logic now applies to the EU AI Act. A company that operates an AI-assisted hiring tool, a credit scoring system, or an AI-powered customer service platform for both EU and US customers faces a binary choice: build and maintain two versions of that system — one compliant with EU AI Act requirements and one not — or apply the EU’s requirements to the global product and operate one system. For most companies, the answer is the same one that drove GDPR adoption: one compliant system is cheaper than two divergent ones, and the compliance cost is at least partially offset by the market access and reputational benefits of being demonstrably compliant.
De Facto vs De Jure Brussels Effect
Researchers distinguish between two forms of Brussels Effect in AI. The de facto effect operates through the market: companies change their products to meet EU requirements, and because those product changes are often technically simpler than building two separate versions, the EU standard becomes the global default product standard. The de jure effect operates through law: other jurisdictions adopt regulatory frameworks that resemble or directly mirror the EU approach, bringing the EU standard into their own legal requirements. Both are visible in the EU AI Act’s first year of significant enforcement. The de facto effect is documented in the Thomson Reuters Foundation analysis — companies changing their practices globally, not just for EU-facing products. The de jure effect is visible in the AI governance frameworks being drafted in the UK, Singapore, Canada, India, and South Korea, all of which share structural elements with the EU AI Act even where their specific requirements differ.
What the Report Documents
The Thomson Reuters Foundation and UNESCO ‘Responsible AI in Practice’ analysis, covering nearly 3,000 global companies across multiple industry sectors, examined corporate AI governance disclosures to assess how companies are actually approaching AI compliance and governance relative to the EU AI Act’s requirements. The core finding on the Brussels Effect is directional: the companies proactively citing EU AI Act compliance in their disclosures include a substantial proportion headquartered outside the EU, and US-headquartered companies represent the largest single source among non-EU early adopters. That finding is significant because it reverses the rhetorical framing that has dominated the EU-US AI governance debate — the narrative in which the EU’s regulatory approach is a competitive disadvantage for European companies relative to a less-regulated US market. The data suggests that large US companies with EU market exposure are in fact adopting EU AI Act standards globally, and some are doing so voluntarily ahead of enforcement deadlines.
The report also documents a performance correlation: companies that aligned early with the EU AI Act framework showed higher operational resilience and investor confidence scores in the analysis. That finding echoes a consistent pattern from GDPR research — companies that invested in data governance ahead of GDPR enforcement performed better on operational resilience metrics in the years that followed, partly because good data governance improves operational quality independent of its regulatory compliance value, and partly because early adopters avoid the distraction and cost of emergency compliance programmes when enforcement actions begin.
The August 2, 2026 Enforcement Date: What Actually Takes Effect
High-Risk AI System Obligations
The August 2, 2026 milestone is the most comprehensive enforcement date in the EU AI Act’s phased implementation timeline. From this date, organizations deploying AI systems classified as high-risk under Annex III of the Act must have completed the full compliance programme: conformity assessments demonstrating their systems meet the Act’s requirements; technical documentation covering the system’s design, training data, intended purpose, and risk management approach; registration in the EU’s public database of high-risk AI systems; transparency obligations ensuring users are informed they are interacting with or subject to AI-assisted decision-making; and human oversight mechanisms ensuring that consequential AI outputs are subject to human review before taking effect. The sectors covered include employment and HR — AI used in recruitment, performance monitoring, promotion, and termination decisions; credit and financial services; education and vocational training; essential services including healthcare, public benefits, and utilities; law enforcement and border control; and AI systems used in critical infrastructure.
What Has Already Been in Effect
The August 2 date adds to, rather than replacing, obligations that have already been in force. Since February 2025, prohibited AI practices have been banned across the EU: real-time remote biometric surveillance in public spaces by law enforcement (with limited exceptions), social scoring systems by public authorities, subliminal AI manipulation, and exploitation of personal vulnerabilities. Since August 2025, general-purpose AI model obligations have applied to foundation model providers — including OpenAI, Google, Anthropic, and Meta — requiring transparency, copyright compliance documentation, and for models above the systemic risk compute threshold, adversarial testing, incident reporting, and cooperation with the EU AI Office. The EU AI Act’s implementation has therefore not arrived all at once but has been a progressive tightening of obligations across 18 months, with August 2, 2026 as the broadest single-day expansion.
The US Response: Compliance Without a Law
Why American Companies Are Adopting EU Standards
The US federal government has not enacted a comprehensive AI law. President Biden’s Executive Order on AI from October 2023 established voluntary commitments from frontier AI developers and directed federal agencies to assess AI risks, but it was partly reversed by the Trump administration in early 2025. The United States currently has a patchwork of AI-related provisions across sector-specific regulation — EEOC guidance on AI in hiring, FTC enforcement against deceptive AI applications, FDA oversight of AI medical devices — alongside a rapidly growing set of state laws covering areas from algorithmic discrimination to deepfakes. The result is that large American companies operating globally face an inversion of the expected regulatory dynamic: the EU has clearer, more comprehensive AI regulation than the US does, and US companies with EU operations have more detailed AI compliance obligations from European law than from American law. As documented in our earlier coverage of state-level AI regulation developments across the US in 2026, the US legislative response to AI governance remains fragmented across 48 state laws with divergent requirements, making the EU AI Act the more coherent compliance target for multinational companies seeking a single standard to build their global AI governance against.
The GPAI Code of Practice
The EU AI Act’s General-Purpose AI Code of Practice, developed through a multi-stakeholder process involving AI developers and civil society, provides the most immediate practical compliance vehicle for US-headquartered frontier AI companies. OpenAI, Google, Microsoft, Anthropic, Meta, and others participated in the Code of Practice drafting process, with the Code published in final form in July 2025. Signatories committed to transparency measures, safety evaluations, and incident reporting in advance of the statutory August 2025 GPAI obligations. The voluntary Code of Practice signatories include a majority of frontier AI developers, providing the EU with an early signal that the industry was prepared to accept the regulatory framework’s basic premise even while negotiating the specific requirements. Meta’s refusal to sign — which has exposed it to a higher risk of enforcement attention under the systemic risk provisions — is the notable exception.
The Dispute: Is the Brussels Effect Overstated?
Not all analysts accept the Brussels Effect as robustly as the Thomson Reuters Foundation report suggests. The Brookings Institution published research arguing that the EU AI Act will have global impact but a more limited Brussels Effect than proponents claim, because many AI systems are localised or individualized enough that they do not need to meet a single global standard — companies can and will build different AI systems for different markets when the economic calculus favours it. The distinction matters for the regulation’s actual global influence: a Brussels Effect that operates through high-visibility frontier AI products affects a relatively small number of companies; a Brussels Effect that operates through the full range of enterprise AI deployments — hiring tools, credit systems, customer service AI — affects a much larger population. The Thomson Reuters Foundation data suggests the effect is operating more broadly than the Brookings analysis expected. As explored in our earlier reporting on the Anthropic export control episode and the US government’s AI regulatory posture, the intersection of AI regulation, geopolitics, and market access is creating a more complex dynamic than any single regulatory framework’s advocates or critics anticipated.
What Happens After August 2
August 2, 2026 is an enforcement date, not an enforcement event. The EU AI Act does not create an automatic penalty for non-compliance on August 2; it creates the legal basis for national market surveillance authorities in each EU member state to take enforcement action against non-compliant systems. Those authorities — which in most member states are still building their technical expertise and investigation capacity — are unlikely to initiate enforcement actions against the highest-risk or most visible non-compliant systems until they have the internal capability to conduct effective investigations. The EU AI Office, responsible for GPAI model enforcement at the EU level, published its enforcement priorities in June 2026 and indicated it would focus initially on systemic risk models and the most concerning prohibited practice cases, leaving national authorities to handle high-risk system enforcement at member state level. The practical consequence is that companies which have begun compliance work but have not completed it by August 2 face legal exposure rather than immediate penalty — a position that is less comfortable than complete compliance but more manageable than having not started.
The Digital Omnibus agreement of May 2026, which proposed extending some compliance deadlines to December 2027 and August 2028, has created additional uncertainty about the precise enforcement timeline for specific categories of high-risk AI in regulated products and embedded systems. Those extensions, if they take effect, provide additional runway for companies in manufacturing and product-embedding sectors. They do not extend the August 2 dates for standalone high-risk AI in services, which remains the primary obligation taking effect this week.
Why It Matters
The EU AI Act’s Brussels Effect, documented by the Thomson Reuters Foundation analysis at the 3,000-company scale, represents the most important evidence yet that the EU’s ambition — to make its AI regulation the global default, as GDPR became the global default for privacy — is materialising rather than remaining a theoretical possibility. If non-EU companies, and specifically US companies, are proactively adopting EU AI Act standards globally ahead of enforcement deadlines, they are doing so because the economics of a single global compliance standard are more favourable than maintaining parallel architectures. That calculation, aggregated across thousands of companies, produces the de facto global standard that EU policymakers designed the regulation to create. The August 2, 2026 enforcement date is therefore not only a compliance milestone for companies with EU AI deployments. It is the moment at which the Brussels Effect becomes visibly operational — when the regulation that was theoretical until now begins generating real enforcement cases, real penalties, and real market signals about the cost of non-compliance — and, for the companies that prepared early, real competitive advantage.
Sources
Thomson Reuters Foundation and UNESCO ‘Responsible AI in Practice’ analysis, based on data from nearly 3,000 global companies. Thomson Reuters Institute EU AI Act Forum (thomsonreuters.com), 2026. Brookings Institution EU AI Act Brussels Effect research. EU AI Act full text and implementation timeline (digital-strategy.ec.europa.eu). Foley & Lardner global AI regulation compliance analysis, July 2026.