In August, a reader outside the EU asked me under one of my Notes whether the EU AI Act could become “another Brussels effect.”
I answered in two sentences. The AI Act already applies to companies outside the EU if they put systems on the EU market, so reach isn’t the interesting question. The interesting question is whether anyone maintains two versions. That’s where the Brussels effect actually gets decided, and it comes down to cost per obligation rather than principle.
It deserved a longer answer, because underneath it sits a practical question for any company outside the EU: should we just build everything to the EU standard, the way we did with GDPR?
It depends on which part of the AI Act you mean. Some of it will follow you home whether you like it or not. Some of it stays at the EU border. And some of it gets decided before your product ever reaches the border.
What the Brussels Effect Is
Anu Bradford, a law professor at Columbia, gave the idea its name in 2012 and wrote the book on it in 2020. It comes in two versions.
The de facto version happens inside companies. A company applies EU rules everywhere because running one version of a product is cheaper than running two. No other government has to do anything. GDPR is the famous example: plenty of companies wrote one privacy program for the world rather than one for Europe and another for everyone else.
The de jure version happens in parliaments. Other countries write EU-style rules into their own law, often because their companies are already following them.
Both depend on the same condition, and it’s the one the literature calls non-divisibility: how expensive is it to split your product into an EU version and a rest-of-world version? For data systems in 2018, very. For software in 2026, it depends on what you’re splitting.
Bradford herself is less sure the old logic still holds. In an interview in March, she said: “In the past, companies often chose to comply globally with the toughest standard to keep things simple, but now the toughest standard might earn them punishment elsewhere. If fragmentation intensifies, some firms may run region-specific configurations to meet conflicting requirements.”
Region-specific configurations. Two versions, from the person who named the effect.
Other Countries Copied the Words
If the AI Act were spreading the way GDPR did, you’d expect other countries to adopt something close to it. Three have adopted something that sounds close.
South Korea’s AI Basic Act has applied since 22 January 2026. It has “high-impact” AI, labeling of generative AI output, and a local representative for foreign providers above certain thresholds. It has no list of prohibited practices, and the maximum fine is KRW 30 million, about $20,000. The government has promised at least a year without fines.
Vietnam’s AI law has applied since 1 March 2026, with high, medium and low risk tiers. Baker McKenzie’s summary is that it “contains many terms and references resembling those under the EU AI Act,” along with “many discrepancies and vague issues.” Kazakhstan’s law, in force since 18 January 2026, has risk levels, machine-readable labels on synthetic content, and the list of banned practices closest to the EU’s: manipulation, social scoring, emotion detection without consent. Its fines run to hundreds of dollars, low thousands for a repeat offense.
All three borrowed the shape. Only Vietnam borrowed a version of the machinery: high-risk systems there need a conformity assessment before they’re put into use. None of them borrowed fines calculated as a percentage of worldwide turnover.
Others didn’t follow at all. Japan passed an AI Promotion Act with no monetary penalties. The UK’s King’s Speech in May came and went without an AI bill. And Colorado, which had the most EU-like AI law in the US, postponed it and then, in May, replaced it with a much narrower law focused on notice and human review.
Two researchers, Sina Hoch and Daniel Mügge, concluded that because the EU’s rules are vague, harmonization across borders “remains shallow at best.” The vocabulary traveled. Most of the obligations didn’t.
Inside Companies, It Splits by Obligation
For your company, the de facto version is the one that matters, and it doesn’t come out the same for the whole AI Act. I see three outcomes.
What Travels
Some obligations change something you build once for the whole world. Those travel, because there’s no cheap way to keep them in Europe.
General-purpose AI models are the clearest case. A model is trained once. The rules for general-purpose models in Article 53 require a copyright policy that honors text-and-data-mining opt-outs, so the training data changes for every user of that model, in every country. They also require a public summary of the training content, and a published summary is public everywhere. Preparing EU paperwork about a global model isn’t the Brussels effect. Changing the model because of an EU rule is.
The Code of Practice for these models has 21 signatories, per the Commission’s list as updated on 31 July 2026, including Amazon, Anthropic, Google, IBM, Microsoft, Mistral AI and OpenAI. xAI signed one of its three chapters. Meta declined, saying the Code “introduces a number of legal uncertainties for model developers, as well as measures which go far beyond the scope of the AI Act.” It may. The Code is voluntary. Article 53 isn’t, and it applies to Meta either way.
One timing detail matters here. These obligations have applied since 2 August 2025. Models already on the market before that date have until 2 August 2027 under Article 111(3). Models released since then have had to comply from release, and that’s where many of today’s flagship models sit.
What Stays in the EU
Other obligations attach to systems that were local to begin with. Those stay at the border, because a second version costs almost nothing extra.
Credit scoring is the clean example. A US lender’s model for its American customers and the model it uses for EU customers are rarely the same model. They run on different data, under different credit laws, for different customers. When the high-risk rules in Annex III start applying to credit scoring in December 2027, nothing about them will force the US model to change. The same goes for risk assessment and pricing in life and health insurance, the other financial use on the list.
Hiring is less clean. A recruitment tool built for one country’s market stays there. A global HR platform running one model for customers worldwide may well end up applying the EU rules everywhere, simply because a second version of the platform would be the expensive option.
What Skips the EU
Bradford’s theory assumes companies can’t afford to walk away from the EU market. For a single product, sometimes they can. If complying costs more than the EU market is worth for that product, it doesn’t launch in the EU.
You can’t cheaply train an EU-only model. You can cheaply not ship one. Meta held back its multimodal model from the EU in 2024, over data protection questions. Apple is holding back Siri AI this year, over the Digital Markets Act. Neither is about the AI Act, but the mechanism is the same: the rule stays in Europe because the product never arrives.
A Note on Watermarks
Another likely global default is the machine-readable marking of AI-generated content under Article 50, which has applied since 2 August 2026. Systems that were already on the market have until 2 December 2026. A mark is added where content is generated, and marking only the outputs that end up in Europe is harder than marking all of them.
Brussels can’t take all the credit, though. China’s labeling rules for AI-generated content have been in force since September 2025, with visible labels and metadata. Korea and Kazakhstan require labels too. When both the EU and China want a mark, a global mark is the obvious engineering decision, whichever government asked first.
My reading of all this, which is close to what Marco Almada and Anca Radu warned about back in 2024: what travels is the engineering. Training choices, published summaries, watermarks. What mostly stays home is the part about people, the high-risk rules on credit, insurance and hiring decisions, which is where the AI Act’s fundamental rights protections sit.
Your First AI Act Contact Probably Won’t Be a Regulator
Every Member State had to designate market surveillance authorities by 2 August 2025. Per the Commission’s list as updated on 7 September 2026, nine have a designation that isn’t marked as pending. Twelve are still waiting for the national decision to be finally adopted, and six have no authority listed at all. Slovakia, where I live, is one of the six (a bill naming the digital ministry is in parliament). I’d tell you who to call, but the list doesn’t know either.
The AI Act applies everywhere in the EU. The machinery for enforcing it is still being assembled. So for many companies outside the EU, the AI Act won’t first arrive as a letter from an authority. It will arrive as a questionnaire, or a clause, from an EU customer. Which questions come depends on what that customer is.
If your EU customer uses your tool as supplied, it’s a deployer. Its questions come from its own obligations: AI literacy, GDPR, third-party risk rules if it’s a bank or insurer, and from 2 December 2027 the duties of a deployer of a high-risk system under Article 26. It needs things from you to meet them, and it will ask.
If your EU customer builds your model or component into a high-risk system it sells under its own name, it’s a provider, and Article 25(4) applies from December 2027. The two of you will have to agree in writing what information, capabilities and technical access you hand over. Since the Digital Omnibus, that explicitly includes AI models. And if what you supply is a general-purpose model, you don’t have to wait for 2027: Article 53 already requires you to give downstream providers documentation about it (on the same timeline as above).
Neither of these is a threat. It’s the AI Act arriving in a form you can prepare for, from someone who wants to keep buying from you. The questions I’d expect are the ones in my vendor questions piece, and a vendor who has the answers ready makes those conversations a lot shorter.
Four Assumptions I See Most Often
None of these comes from a survey. They’re the four I run into most, in comments and questions from readers outside the EU.
“It all starts in 2027.” Only the high-risk rules moved. The Digital Omnibus deferred them to 2 December 2027 (and August 2028 for AI built into regulated products like medical devices). The prohibitions and the AI literacy duty have applied since February 2025, the rules for general-purpose models since August 2025 (with the transition for older models noted above), and the transparency rules in Article 50 since August 2026. Some of the AI Act is already your problem.
“No EU entity, no problem.” This one is plainly wrong. If you offer your system to customers in the EU, Article 2(1)(a) catches you as a provider “irrespective of whether those providers are established or located within the Union or in a third country.” One EU customer you knowingly serve can be enough.
If you don’t offer it in the EU, Article 2(1)(c) can still catch you “where the output produced by the AI system is used in the Union.” Recital 22 points toward output “intended to be used in the Union,” but a recital guides interpretation, it doesn’t rewrite the article. Whether someone opening your output in Dublin makes it output used in the Union is not settled. I wouldn’t bet a product on either answer.
“The risk is a fine.” It is, eventually. Breaching the prohibitions can cost up to €35 million or 7% of worldwide turnover, and the transparency rules up to €15 million or 3%. But with a third of the authorities designated, the first cost for many companies is more ordinary: a deal that stalls because the answers to a customer’s questionnaire weren’t ready.
“We’ll comply globally, like we did with GDPR.” That was a reasonable default for data. For the AI Act it’s a decision you make per obligation. Global for anything baked into the model or the output. EU-only for systems that were local anyway. And for high-risk systems, one more date: providers outside the EU will need an authorized representative in the EU before making the system available there, from December 2027 (August 2028 for AI in regulated products), under Article 22. For general-purpose models, the equivalent rule in Article 54 already applies, with the same transition for older models.
Did the Omnibus End It?
The Digital Omnibus deferred the high-risk rules and softened the AI literacy duty. It’s easy to read that as Brussels losing its nerve, and Bradford thinks “the high-water mark of Europe’s regulatory leadership is behind us.”
The US pressure is real, but it has been aimed at EU digital rules generally rather than the AI Act specifically. When the US Trade Representative threatened retaliation in December 2025, it named European companies as possible targets rather than EU laws. One of them was Mistral AI, which had signed the Code of Practice.
And the Omnibus didn’t only delay. It left the prohibitions and the general-purpose model rules in place, and Article 50 largely in place. It added two new prohibitions (on AI-generated non-consensual intimate imagery and child sexual abuse material, from 2 December 2026). And it gave systems already on the market only four months’ grace for marking AI-generated content, less than the Commission had proposed. It mostly changed the dates. It didn’t change which obligations are cheaper to apply once than twice.
What to Do With This
Sort your AI Act obligations by the three outcomes before anyone asks you to. Anything that changes the model or the output (training data choices, published summaries, marking) you’ll probably end up applying everywhere, so design it once. Anything tied to a system that serves EU customers only, keep separate and scope it to the EU. Anything that would need a product built only for Europe, decide early whether the EU market is worth it, because that decision gets harder once customers are waiting.
Find out what your EU customers are. For each one, know whether it uses your system or builds it into its own, because that tells you which questions are coming.
Check the dates that apply now rather than the one in the headlines. The prohibitions and the AI literacy duty apply. The general-purpose model rules apply. Article 50 applies. The high-risk rules don’t yet.
The Brussels effect for AI won’t be decided in Brussels. It’ll be decided one obligation at a time, by whoever in your company compares the cost of one version with the cost of two.
Like this article? The AI Governance Roadmap is something you can use in practice. It’s a company’s roadmap with steps and working documents. It includes the classification, the inventory spreadsheet, the role assignment, the vendor questions, the AI policy template. Everything a company needs to govern AI, at one place.

