Submit your papersSubmit Now
For Enquiries: [email protected]
IIARD LogoIIARD

A Systematic Review of Organizational Readiness for The EU Artificial Intelligence Act in Multinational Enterprises

Michael Ominyi, Cyril Chimelie Anichukwueze, Ngozi Samuel Uzougbo

Abstract

Regulation (EU) 2024/1689, the EU Artificial Intelligence Act, entered into force on 1 August 2024 and established the first comprehensive, horizontal, risk based legal framework for artificial intelligence. Because the Act applies to any provider or deployer placing an AI system on the EU market regardless of where that organization is headquartered, its obligations reach far beyond the EU and fall squarely on multinational enterprises that operate AI systems across multiple regulatory jurisdictions at once. This paper presents a systematic review of the literature published no later than 2024 on the question of organizational readiness among MNEs. Sources were identified through structured searches of academic databases and grey literature repositories, screened against inclusion criteria centered on organizational or enterprise level readiness, and synthesized thematically. Because the Act had only just entered into force at the time of this review, and its most operationally demanding obligations, covering AI literacy, general purpose AI models, and high risk systems, are not due to bind until February 2025, August 2025, and August 2026 respectively, the reviewed literature captures an early and still forming picture of readiness rather than a mature evidence base. The single large-scale survey located for this review, conducted in September 2024, found that only around a quarter of organizations were actively preparing for compliance, while close to half had not yet meaningfully engaged with the Act's requirements at all. MNEs appear to face readiness challenges that are structurally distinct from those of domestic firms, including regulatory fragmentation across jurisdictions, anticipated friction between the AI Act and the General Data Protection Regulation, and structural asymmetries within global value chains, though the literature available as of 2024 addresses these challenges largely at a conceptual rather than empirical level. No dedicated AI Act specific readiness framework had yet appeared in the literature located for this review. The paper synthesizes the frameworks and recommendations available in the literature to date and concludes with a discussion of the review's limitations, foremost among them the fact that the evidence base will necessarily grow as the Act's binding deadlines arrive through 2025 and 2026.

References

Afrihyia, E., Akinse, S. G., & Ojukwu, P. U. (2024). Comparative governance of AI-driven healthcare management: Executive oversight, regulatory structures, and accountability in the United States and developing countries. International Journal of Advanced Multidisciplinary Research and Studies, 4(6), 3087–3102. https://doi.org/10.62225/2583049X.2024.4.6.5920 Agu, M. U., Akomolafe, O., & Bello, A. (2023a). A comparative review of SOX compliance frameworks in cross-border financial auditing. International Journal of Advanced Multidisciplinary Research and Studies, 3(6), 2297–2306. https://doi.org/10.62225/2583049X.2023.3.6.5362 Akomolafe, O., Agu, M. U., & Bello, A. (2023b). A quantitative conceptual model for assessing compliance risk in emerging economies. International Journal of Advanced Multidisciplinary Research and Studies, 3(6), 2287–2296. https://doi.org/10.62225/2583049X.2023.3.6.5360 Aliliele, C., Mbonu, I. S., & Iwuanyanwu, U. (2024a). A conceptual framework for enterprise data sensitivity classification and regulatory traceability mechanisms. International Journal of Advanced Multidisciplinary Research and Studies, 4(6), 3103–3124. https://doi.org/10.62225/2583049X.2024.4.6.5991 Amayo, E. B., Owulade, O. A., & Isi, L. R. (2023a). Optimizing project governance in multinational infrastructure projects: Insights from General Electric's global operations. International Journal of Multidisciplinary Research and Growth Evaluation, 4(1), 975–983. https://doi.org/10.54660/.IJMRGE.2023.4.1.975-983 Amayo, E. B., Owulade, O. A., & Isi, L. R. (2023b). Risk management strategies and compliance frameworks in healthcare infrastructure projects: Case studies from West Africa. International Journal of Management and Organizational Research, 2(1), 161–168. https://doi.org/10.54660/IJMOR.2023.2.1.161-168 Amayo, E. B., Owulade, O. A., & Isi, L. R. (2024a). Best practices for managing data center lifecycle projects: Ensuring security, efficiency, and compliance in U.S. enterprises. Iconic Research and Engineering Journals, 7(7), 598–617. Amayo, E. B., Owulade, O. A., & Isi, L. R. (2024b). Effective project governance in multinational infrastructure projects: A case study from General Electric. Iconic Research and Engineering Journals, 8(5), 1305–1324. Annan, A. O. (2022). Data privacy governance models for cross-border digital platforms. International Journal of Multidisciplinary Research and Growth Evaluation, 3(6), 949–964. Annan, A. O. (2023). Intellectual property ownership and authorship in AI-generated works. Gyanshauryam, International Scientific Refereed Research Journal, 6(3), 425–450. Annan, A. O. (2024). Algorithmic accountability and trade secret protection in artificial intelligence. Shodhshauryam, International Scientific Refereed Research Journal, 7(5), 315–347. Bello, A., Akomolafe, O., & Agu, M. U. (2023). A conceptual framework for data-driven procurement risk management in multinational enterprises. International Journal of Advanced Multidisciplinary Research and Studies, 3(6), 2307–2316. https://doi.org/10.62225/2583049X.2023.3.6.5363 Cancela-Outeda, C. (2024). The EU's AI Act: A framework for collaborative governance. Internet of Things, 27, 101291. https://doi.org/10.1016/j.iot.2024.101291 Deloitte Legal Germany. (2024, September). AI Act survey: Preparedness of German companies for the EU Artificial Intelligence Act [Survey report]. DiMaggio, P. J., & Powell, W. W. (1983). The iron cage revisited: Institutional isomorphism and collective rationality in organizational fields. American Sociological Review, 48(2), 147– 160. Dosunmu, A. A., & Ogundele, P. O. (2024b). Cyber risk quantification models for prioritizing enterprise security investment decisions. International Journal of Multidisciplinary Research and Growth Evaluation, 5(6), 1777–1785. https://doi.org/10.54660/.IJMRGE.2024.5.6.1777-1785 Eboh, E. E., & Aliliele, C. (2024). AI-driven data analytics framework for risk assessment and detection of venture capital and private equity investment fraud in U.S. capital markets. International Journal of Scientific Research in Computer Science, Engineering and Information Technology, 10(6), 2624–2665. https://doi.org/10.32628/CSEIT2410787 Ebhojie, O., Dogbatsey, E. A., & Oyeleye, A. O. (2023a). Audit liaison, corrective action planning, and control compliance in multinational organisations: A systematic literature review. International Journal of Advanced Multidisciplinary Research and Studies, 3(6), 2839– 2850. https://doi.org/10.62225/2583049X.2023.3.6.6200 European Parliament and Council of the European Union. (2024). Regulation (EU) 2024/1689 of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union. EY. (2024, July). The European Union Artificial Intelligence Act [White paper]. https://www.ey.com/content/dam/ey-unified-site/ey-com/en-gl/insights/public- policy/documents/ey-gl-eu-ai-act-07-2024.pdf IAPP. (2024). AI governance in practice report 2024. International Association of Privacy Professionals. https://iapp.org/resources/article/ai-governance-in-practice-report IAPP, & EY. (2023). Professionalizing organizational AI governance report. International Association of Privacy Professionals. Kumuyi, O., Akeju, B., Uzoka, E., & Ozowara, D. E. (2023). Framework for blockchain-based cross-border data exchange and regulatory transparency. International Journal of Multidisciplinary Futuristic Development, 4(1), 99–113. Ladapo, O. O., Dosunmu, A. A., Jooda, D., & Abolaji, T. O. (2024). Keeping humans in the loop: Human-centered automated annotation with generative AI. International Journal of Multidisciplinary Futuristic Development, 5(1), 81–95. https://doi.org/10.54660/IJMFD.2024.5.1.81-95 Mbonu, I. S., Aliliele, C., Iwuanyanwu, U., & Oluoha, O. M. (2018). A conceptual framework for legal and ethical risk modeling in enterprise data protection governance systems. Iconic Research and Engineering Journals, 2(2), 207–226. https://doi.org/10.64388/IREV2I2- 1714911 Mbonu, I. S., Aliliele, C., Uzoka, E., & Oluoha, O. M. (2019). A review of comparative data protection regulations and secure cloud implementation strategies across jurisdictions. Iconic Research and Engineering Journals, 2(9), 482–501. https://doi.org/10.64388/IREV2I9-1714912 Mbonu, I. S., Iwuanyanwu, U., Aliliele, C., & Uzoka, E. (2022). A conceptual framework for AI enabled IT general controls and SOX audit automation processes. Gyanshauryam, International Scientific Refereed Research Journal, 5(5), 384–414. https://doi.org/10.32628/GISRRJ2256239 Teece, D. J. (2007). Explicating dynamic capabilities: The nature and microfoundations of (sustainable) enterprise performance. Strategic Management Journal, 28(13), 1319–1350.