Quick Summary
Covering the latest research from top Wall Street investment banks

Global AI regulation is accelerating, making governance capability a key driver of corporate risk differentiation

Institution
HSBC
Date
2026-08-04
Authors
Yaryna Kobel, Zoe Knight
Company
-
Ticker
-
Industry
Artificial Intelligence and Information Technology Services
Rating
-
BearishLow confidenceGlobal AI regulation is shifting from principles-based guidance to more comprehensive and binding obligations. Companies will face rising compliance costs, legal liabilities, and reputational risks; companies with trustworthy AI control systems and effective board oversight are relatively more resilient.
AuthorsYaryna Kobel, Zoe Knight
Business segmentsAI regulation、Corporate governance、Healthcare and life sciences
Research firm divisions/subsidiariesHSBC(Other)、HSBC Bank plc(Other)

AI summary card

Global AI regulation is accelerating, making governance capability a key driver of corporate risk differentiation

Regulatory approaches across markets remain divergent, but rules are generally becoming more comprehensive and mandatory. The healthcare sector faces a heavier burden, while board oversight, content labeling, and cross-regime compliance will become key investor focus areas.

This report is a global industry and sustainability-themed research report and does not provide stock ratings, target prices, or expected upside.
AI regulationEU AI ActCorporate governanceBoard oversightHealthcare and life sciencesGenerative AI content labelingShareholder proposalsCompliance risk
  • More policymakers are expected to advance comprehensive and more prescriptive AI regulatory measures, requiring companies to allocate expertise and resources for parallel compliance across multiple regimes.
  • The 2026 U.S. proxy season saw 20 AI-related shareholder proposals, up from 18 in 2025 and 12 in 2024, but no proposal received majority support, with median support of around 10%.
  • Boards are adding directors with AI and technology backgrounds. Nearly half of Fortune 100 companies mention AI in director qualification descriptions, compared with 26% in 2024.
  • Healthcare and life sciences are considered among the sectors facing the heaviest regulatory burden under the EU AI Act, as multiple types of applications may be classified as high-risk systems.
  • EU disclosure obligations for certain AI-generated content have already taken effect, but the dedicated icon recommended by the European Commission is not mandatory.
  • Companies that can demonstrate trustworthy AI control systems and effective board oversight will have a relative advantage as regulatory scrutiny intensifies.

Report interpretation

Overview

The report uses seven investor questions as a framework to analyze the evolution of global AI regulation, uncertainties related to training data and licensing, shareholder proposals, changes in boards and executive compensation, legislative differences across markets, the impact of the EU AI Act on the healthcare sector, and labeling obligations for AI-generated content. The core view is that regulation is moving from principles to more comprehensive legal obligations, while different markets still adopt clearly divergent horizontal or vertical regulatory approaches.

Core views

The number of global AI rules continues to rise, with regulatory focus typically covering model testing, transparency, bias mitigation, synthetic content labeling, industrial development, and workforce impacts. Markets such as China and Brazil may introduce more comprehensive and prescriptive measures in the future. Compliance will require AI technology companies and enterprises embedding AI into products and processes to invest substantial resources. Investors should ask companies to explain the operational impact of regulation, preparation progress, required expertise and budgets, and should focus on assessing board oversight, data privacy, human rights, misinformation, bias, and employee transition management. Healthcare and life sciences face more pronounced product adjustment, compliance cost, and liability risks because many applications may be classified as high-risk.

Analysis framework

The report combines investor Q&A, cross-market policy comparison, corporate disclosure cases, and governance indicator tracking. At the regulatory level, it compares the number of laws across markets and horizontal versus vertical regulatory approaches; at the governance level, it analyzes AI shareholder proposals, board technology experience, and executive compensation metrics; at the industry level, it uses healthcare and life sciences as a case study to assess high-risk system classification and compliance impacts.

Methodology notes

  • Policy and regulatory analysisCross-market regulatory comparison

    Horizontal regulation and vertical regulation

    Horizontal regulation covers broad AI issues, with the EU as the main example; vertical regulation focuses on specific AI applications or industries, an approach more commonly adopted in markets such as the UK. The report assesses regulatory differences by considering each market's socio-political context and policy tools.

  • Corporate governance analysisBoard oversight and incentive mechanism assessment

    AI governance capability

    The report assesses whether companies have governance capabilities to identify, oversee, and mitigate AI risks by examining directors' technology backgrounds, AI-related shareholder proposals, and AI metrics in executive compensation.

  • Industry impact analysisRisk classification and compliance burden assessment

    High-risk AI systems

    Based on the EU AI Act and medical device-related rules, the report identifies medical AI systems that may be classified as high-risk and assesses impacts on product adjustments, compliance costs, fines, and civil liability.

  • Case analysisCorporate disclosure evidence method

    Transmission of regulatory risk

    The report cites risk disclosures from companies including Eli Lilly & Co, Intuitive Surgical, and Fresenius Medical Care to observe how AI regulation is transmitted into operational restrictions, cost increases, litigation liability, and financial performance.

Asset mapping & comparison

Structured mapping from thesis to named assets (strengths, weaknesses, peers, risks).

  • AI technology companies and AI-integrating enterprises
    Directly face global AI regulation and obligations related to training, deployment, and content disclosure
    Strengths
    Companies with stronger technological capabilities may be able to establish model testing, transparency, and risk control systems more quickly.
    Weaknesses
    Compliance across multiple regimes requires substantial professional talent, governance investment, and operational resources.
    Comparison
    Pure AI technology companies face direct regulation of models and training, while traditional companies bear more application-level responsibilities after integrating AI into products and business processes.
    Risks
    Copyright and licensing uncertainty, data privacy, bias, misinformation, content labeling, fines, and reputational damage.
  • Healthcare and life sciences companies
    Belong to sectors facing a relatively heavy regulatory burden under the EU AI Act
    Strengths
    Mature medical device compliance capabilities can provide a foundation for AI governance and conformity assessments.
    Weaknesses
    Many AI applications may be classified as high-risk, making product adjustments and regulatory coordination more complex.
    Comparison
    Compared with most sectors, medical AI is more likely to be subject to both the EU AI Act and medical device regulations.
    Risks
    Increased compliance costs, restrictions on product development or use, regulatory penalties, civil claims, and impaired operating and financial performance.
  • Governance and compensation systems of large listed companies
    AI risk is gradually entering board composition, shareholder agendas, and executive incentives
    Strengths
    Adding directors with technology backgrounds and setting measurable AI performance metrics helps strengthen oversight and accountability.
    Weaknesses
    Clear and quantitative AI compensation metrics remain relatively rare, and there may be a gap between governance disclosure and actual outcomes.
    Comparison
    The United States has a relatively high number of AI shareholder proposals, while such proposals are less common in other markets; the share of directors with technology backgrounds at Hong Kong, China companies is also rising.
    Risks
    Insufficient board expertise, unclear oversight responsibilities, incentive metrics that emphasize inputs rather than outcomes, and heightened scrutiny from shareholders and regulators.

Key data

  • Number of AI-related shareholder proposals in the United States20 proposals in 2026There were 18 in 2025 and 12 in 2024; no proposal received majority support in 2026.
  • Median support for AI-related proposals in the United StatesAround 10%Proposals mainly involved board oversight, data privacy, human rights, misinformation, bias, and the impact of automation on the workforce.
  • Share of Fortune 100 companies mentioning AI in director qualificationsNearly halfThis is close to double the 26% level in 2024, showing increased board emphasis on AI and technology experience.
  • Share of HSI company directors with technology backgrounds18% in 2025The figure was 14% in 2023, with the upward trend especially evident in the industrials, consumer, and utilities sectors.
  • Share of S&P 500 companies disclosing AI-related compensation metrics5.9% in 2025Relevant metrics are mostly included in individual performance assessments rather than used as standalone assessment indicators.
  • Share of large companies adopting explicitly weighted AI compensation metricsAround 0.2%The sample comprises approximately the world's 2,500 largest companies; most companies still focus on rewarding AI adoption, capability building, and transformation investment.
  • AI-related laws passed in the United States from 2016 to 202525 lawsOver the same period, South Korea passed 17, while Japan, France, and Italy each passed around 9 to 10, indicating significant differences in legislative activity across markets.
  • Effective date of EU AI-generated content disclosure provisionsAugust 2, 2026Article 50(4) of the EU AI Act requires disclosure of AI use for certain deepfake content and public-interest text that has not undergone human or editorial review; the recommended icon itself is not mandatory.
  • Key compliance date for medical AIAugust 2, 2028The report states that the timeline for relevant requirements has been delayed, and investors should monitor companies' progress in completing AI governance and product adjustments before this date.

Impact & implications

Tightening regulation may increase costs for model testing, documentation, transparency, content labeling, bias governance, and product compliance, while also bringing fines, civil claims, business restrictions, and reputational damage. Companies operating across markets also need to address fragmented rules and differing implementation timelines. Healthcare companies have particularly significant risk exposure, as some medical devices, diagnostics, patient triage, and biometric applications may be classified as high-risk. By contrast, companies that can establish trustworthy control systems, allocate specialized resources, and ensure effective board oversight are more likely to reduce compliance shocks and gain investor recognition.

Risks

  • Regulatory approaches and policy tools vary significantly across markets, increasing the complexity and cost of cross-regime compliance.
  • Legal and commercial uncertainty remains around fair use, copyright licensing, and the scalability of licensing for AI training.
  • Medical AI may be classified as high-risk systems, facing strict conformity assessments, product adjustments, and ongoing governance requirements.
  • Data privacy, human rights, bias, misinformation, and deepfakes may trigger regulatory, litigation, and reputational losses.
  • Companies lacking board AI expertise, clear responsibility allocation, and effective control systems may fail to meet new rules in a timely manner.
  • The impact of AI automation on the workforce may increase employee relations, social responsibility, and shareholder pressure.
  • AI metrics in compensation that reward only adoption and investment without verifiable outcomes may create incentive misalignment.

What to watch

  • The timetable and specific requirements for markets such as China and Brazil to advance more comprehensive and prescriptive AI laws.
  • The enforcement scope of EU AI-generated content disclosure obligations, and corporate practices in adopting icons, disclaimers, or other perceptible labels.
  • Progress by healthcare and life sciences companies in making AI governance and product compliance adjustments before August 2, 2028.
  • Corporate disclosures on the impact of multi-regime compliance, budgets, professional talent needs, and operational readiness.
  • Trends in boards adding members with AI and technology backgrounds, and whether oversight responsibilities form verifiable governance mechanisms.
  • Whether the number, themes, and support levels of AI-related shareholder proposals in the United States continue to rise.
  • Whether AI metrics in executive compensation shift from capability building and adoption levels toward quantifiable outcomes such as revenue, profit, productivity, and cost efficiency.
  • Developments in AI training copyright litigation, fair-use case law, and individual licensing and collective licensing mechanisms.
Zhejiang ICP No. 2022035445-5
Disclaimer: Market data, charts, indicators, research views, and other information provided on this website are intended solely for information display, research communication, and educational reference. They should not be regarded as personalized investment advice, securities recommendations, trading instructions, solicitations, or guarantees of return. While we strive to improve the reliability of our data and content, such information may still be subject to delays, errors, incompleteness, or untimely updates due to source differences, methodological limitations, system processing, or market volatility. Users should exercise independent judgment based on their own circumstances and bear all risks and responsibilities arising from the use of this website.

Settings

Sign in to view recent logins