The EU AI Act may first reach a business through a procurement form, not a regulator.
A customer may ask for an inventory of the AI systems used by its suppliers, while a request for proposal raises questions about impact assessments and human oversight. The sales team wants to say that a product is aligned with the Act, but legal cannot establish precisely which systems, obligations or controls that statement covers.
Research published by the Thomson Reuters Foundation on 28 July shows that these are no longer hypothetical edge cases. EU-based customers are incorporating AI Act expectations into requests for proposals, due diligence and contracts. Among companies that cite the Act in their governance disclosures, 47% are headquartered outside the EU, with the United States providing the largest non-European group.
The Act’s international influence is therefore developing through two routes. Its legal scope can apply beyond Europe, including where non-EU providers place AI systems on the EU market or where the output of a system is used in the Union. Its language is also passing through commercial relationships, giving customers and suppliers a shared framework for asking how AI is governed.
For marketing and compliance leaders, this changes the status of responsible-AI language. Terms such as human-led, transparent and aligned with the EU AI Act are not harmless corporate decoration. They describe an operating reality that the organisation may be asked to evidence.
The European Union has long influenced business practice beyond its borders by setting standards that multinational companies find easier to apply consistently than to confine to one market. The Thomson Reuters Foundation describes its latest findings as evidence of a measurable “Brussels Effect” in AI governance.
The research does not suggest universal adoption. Across the underlying AI Company Data Initiative report, 13% of companies publicly say that their AI strategy adheres to a formal governance framework. Of that group, 53% cite the EU AI Act, compared with 12% citing the US National Institute of Standards and Technology’s AI Risk Management Framework and 10% citing ISO/IEC AI standards.
The denominator matters here: the result does not mean that 53% of companies comply with the EU AI Act, only that the Act is the leading named reference among the relatively small proportion of companies that publicly associate their AI strategy with an external framework.
Even this limited form of alignment can shape markets. A company designing one governance process for customers in Europe, another for the United States and a third for the rest of the world creates duplication and inconsistency. Using a demanding framework as a common baseline may be operationally simpler, particularly where AI products, vendors and data move through global supply chains.
The Act is becoming influential because it supplies a common set of questions about what the system is intended to do, who is responsible for it, which risks were assessed, what information a human reviewer receives and which decisions and changes are recorded. Those questions can travel through a contract long before an enforcement action occurs.
The data measures evidence, not compliance
The research repeatedly distinguishes governance from disclosure. The AI Company Data Initiative’s final global dataset covers nearly 3,000 companies and draws on annual reports, ESG disclosures, governance and responsible-AI webpages, cybersecurity and privacy policies and responses supplied directly by participating companies. A large language model was used to map explicit statements against the initiative’s framework, with analyst review during development and manual spot checks covering at least 10% of the production sample. Companies were invited to validate or supplement the findings.
The results should not be read as an audit of every internal practice. A company may operate a control that it has not disclosed. Equally, publishing an impressive policy does not show that the policy is consistently applied.
This limitation matters commercially because customers, investors and procurement teams can assess only the information an organisation can produce. A control that exists but cannot be found, explained or connected to a particular system may offer little assurance outside the team that designed it.
Governance therefore has an evidential layer: organisations need to do the work and be able to reconstruct it. The research reveals a sharp decline in disclosed evidence as governance moves from ambition towards daily operation.
Some 43.7% of companies communicate that they have an AI strategy or guidelines. Forty per cent report board or committee oversight and 31% identify an additional team or resource dedicated to AI governance.
The figures fall considerably when the analysis reaches the systems, responsibilities and interventions needed to put those commitments into practice. Only 15.4% say they can trace the ethical impacts of AI systems to a responsible person or organisation at relevant stages of the lifecycle. Some 12.4% report a policy intended to ensure human oversight. Just 2.7% publicly report a formal AI model registry.
A registry may be incomplete, a named committee may lack authority and a detailed policy may be ignored, so none of these measures proves governance quality on its own. Together, however, the figures expose a persistent problem: companies find it easier to describe their intentions than to show how responsibility follows an AI system through its working life.
That gap should concern senior leaders because systems rarely remain still. Models are updated, vendors change, internal drafting tools begin to influence customer decisions and workflows designed for one market are extended to another, while the original assessment remains on file after the conditions supporting it have disappeared.
Responsible AI is becoming a claims discipline
The EU AI Act makes marketing unusually relevant to AI governance because an AI system’s “intended purpose” includes the context and conditions of use described by its provider in instructions, technical documentation and promotional or sales materials and statements. Marketing can therefore help define how the provider says the system should be used.
Every product page need not become a regulatory filing, but loose claims can create a mismatch between a system’s documented purpose, its promotion and its deployment.
Consider the phrase “every output is reviewed by a human”. It could mean that a person approved the original template, checks a sample after publication, reviews every item before use or sees only outputs that exceed a risk threshold. The words sound specific while concealing several materially different controls.
The phrase “aligned with the EU AI Act” is similarly imprecise. It might refer to a legal scoping exercise, voluntary adoption of selected principles, controls implemented for one product or a full programme covering several applicable obligations. Without a defined subject and supporting evidence, the statement communicates confidence without explaining its basis.
Regulated marketing teams already know how to manage claims. They establish what is being asserted, identify substantiation, define the audience and preserve necessary qualifications. Responsible-AI language requires the same discipline.
The approval record should connect the precise wording to the system and use case it describes, the evidence available at the time, the accountable owner and the conditions that would require another review. A new model version, market, audience or level of autonomy may each change the answer.
Organisations should be able to talk about their AI governance, provided those statements are as dependable as the other material claims they publish. The AICDI findings show why “human in the loop”, one of the most common assurances in corporate AI language, rarely provides enough information on its own.
Only 12.4% of companies in the global sample disclose a human-oversight policy. The Thomson Reuters Foundation’s subsequent analysis found that 48% of that group had not documented the operating processes needed to make oversight meaningful, including monitoring tools, intervention mechanisms and human-in-the-loop workflows.
A person can be present without being in control if they receive too much material to assess, see an answer without its sources, assumptions or uncertainty, or cannot reject the system’s recommendation within the workflow. Escalation may exist in policy but remain absent from the interface where a decision is made.
Meaningful oversight describes a job. It establishes what the reviewer is expected to notice, which information they receive, when they must intervene and whether they can challenge, override, pause or withdraw the system.
The same principle applies to content approval. Routing an AI-generated communication to compliance creates human presence, but the reviewer can exercise informed judgement only when the relevant product information, audience, evidence, policy constraints and material changes are available with the work.
As explored in AI governance in financial services needs a human test, oversight is a designed capability rather than a person placed at the end of a process.
AI supports expert judgement when it brings the right context to the reviewer, rather than creating the appearance of accountability while leaving the expert to reconstruct that context manually.
The spread of the EU AI Act does not mean that other governance frameworks become irrelevant.
The AICDI report found that 43.6% of companies citing a framework referred to an internal or “other” approach rather than one of the initiative’s named external standards. Among companies claiming framework adherence, the average number cited was 1.37 and more than three quarters cited only one.
Different frameworks serve different purposes. The EU AI Act creates legal obligations within its scope. The NIST AI RMF offers a voluntary risk-management structure. ISO standards can support management systems and technical practices. Sector regulation, privacy law, internal policy and professional standards may add further requirements.
Running each as a separate compliance exercise is unlikely to produce coherent governance. The same system can become subject to several overlapping assessments, classifications and approval routes, each using different language and storing its evidence elsewhere.
A better internal model connects those requirements to one operating record. The organisation can see which provisions apply, how they have been interpreted, which controls answer them and where further expert judgement is required.
This is organisational intelligence in a practical form: the ability to retrieve and apply the organisation’s accumulated understanding at the point of decision, rather than simply maintaining a larger library of documents.
August 2026 is not a universal AI-labelling rule
The AI Act entered into force in 2024 and applies in stages. Its Article 50 transparency obligations begin to apply on 2 August 2026. These include requirements covering direct interaction with certain AI systems, machine-readable marking of synthetic outputs, emotion recognition, biometric categorisation, deepfakes and certain AI-generated or manipulated text published to inform the public on matters of public interest.
The start date does not impose a public label on every advert, email or webpage assisted by AI. In practice, Article 50 turns AI transparency into a workflow decision because the relevant obligation depends on the organisation’s role, the system and the output. The Commission’s guidance distinguishes, for example, between provider obligations to make certain synthetic content machine-readable and deployer obligations to disclose deepfakes and specified public-interest material. It also recognises exceptions, including for relevant text subject to human review or editorial control.
The recent AI Omnibus also extended the application dates for the Act’s high-risk rules. Requirements for Annex III high-risk systems now apply from 2 December 2027, while rules for AI embedded in regulated physical products apply from 2 August 2028. Article 50’s August 2026 transparency date remains.
Marketing and compliance teams should resist translating a complex, risk-based law into a blanket instruction such as “label all AI content”. Broad internal rules may feel safe but can obscure which legal requirement is being addressed and produce controls that are difficult to maintain.
Teams should begin with classification: what system is involved, what role does the organisation perform, what content has been produced and which use brings it within scope?
The Thomson Reuters Foundation’s research shows the EU AI Act becoming the dominant external reference among companies that name a formal AI framework, while also revealing how scarce operational evidence remains. Another policy will not resolve that gap by itself; an organisation needs to preserve the route from requirement to interpretation, from interpretation to control and from control to decision. When circumstances change, it should be possible to identify which assessments, communications and approvals may need to change with them.
Most regulated organisations already possess much of this knowledge. Experienced reviewers have interpreted difficult provisions, agreed acceptable wording, identified recurring risks and learned where a standard answer ceases to be reliable. The weakness is that this judgement often disappears into completed documents, email exchanges and the memories of individual specialists.
AI can make that expertise easier to retrieve, compare and apply. It can identify relevant requirements, assemble evidence and surface comparable decisions. Accountability remains with the people authorised to exercise judgement.
This is the operating challenge behind the EU AI Act’s global influence. Preparedness will be visible in organisations that can show how a claim, control or approval was reached, what evidence supported it and when the reasoning should no longer be reused.
The global standard will be established in those records, one decision at a time.
What teams need to know
Does the EU AI Act apply to companies outside the EU?
It can. The Act covers certain non-EU providers placing AI systems or general-purpose AI models on the EU market, as well as providers and deployers outside the EU where the output produced by an AI system is used in the Union. Companies can also encounter its requirements indirectly through customers, supply chains and procurement.
Does the research show that 53% of companies comply with the EU AI Act?
No. Thirteen per cent of the AICDI sample publicly say that they adhere to a formal AI governance framework. Of those companies, 53% cite the EU AI Act. The dataset measures disclosed evidence and company responses, not verified legal compliance.
Does every piece of AI-generated marketing content need to be labelled?
No. Article 50 contains specific obligations for particular providers, deployers, systems and outputs. Whether disclosure or machine-readable marking is required depends on the content and use case, with defined exceptions.
What should a responsible-AI claim approval record contain?
It should identify the exact claim, the system and use case it covers, the supporting evidence, the accountable owner, relevant limitations, the approval date and the changes that would trigger reassessment.
What is organisational intelligence in AI governance?
Organisational intelligence is the connected body of approved requirements, interpretations, evidence, previous decisions and operating context that helps people and systems reach dependable, company-specific decisions. It makes expert judgement reusable without treating past approval as permanent precedent.