2 August deadline: Brussels Will Regulate Your AI Before Pretoria Does
- Johan Steyn

- 4 hours ago
- 4 min read
European enforcement began on 2 August while South Africa's own AI policy remains a draft, and the gap is where standards get set.

Sign up for my Substack daily AI newsletter here.
See my AI Training course portfolio for corporate Business Leaders here.
Follow me on LinkedIn: https://www.linkedin.com/in/johanosteyn/
There is a version of regulatory caution that looks like prudence and functions as abdication. South Africa has spent three years consulting on artificial intelligence while the European Union has moved from legislation to enforcement. The consequence is not that South African firms remain unregulated. It is that they will be regulated by someone else.
CONTEXT AND BACKGROUND
As of 2 August 2026, the European AI Act enters its enforcement phase. The Commission’s AI Office, together with national authorities, is now responsible for implementing, supervising and enforcing the Act, with power to request technical documentation, evaluate models, require corrective measures and issue fines. New transparency rules apply from the same date, requiring chatbots and other interactive systems to tell users they are dealing with AI rather than a human, deepfakes to be labelled, and AI-generated or altered content to carry machine-readable marks.
Existing systems have until 2 December to adapt, and penalties for banned practices reach seven percent of worldwide annual turnover or 35 million euros, whichever is higher. South Africa’s position is less advanced. Cabinet approved a draft National AI Policy for public comment, gazetted on 10 April 2026, and Minister Solly Malatsi withdrew it on 26 April after an internal investigation confirmed that its reference list contained fictitious sources, which he attributed to AI-generated citations included without proper verification.
INSIGHT AND ANALYSIS
The assumption that European rules are a European problem does not survive contact with the text. Article 2 applies to providers placing systems on the Union market irrespective of whether they are established in a third country, to deployers located in the Union, and to providers and deployers established in a third country where the output produced by the system is used in the Union.
That third category carries no intent requirement. A South African firm need not target Europe, market there or know its output will arrive there. Where the output is used in the Union, the Act applies. Legal analysis notes that this threshold sits below that of the General Data Protection Regulation, which turns on whether a firm actively targeted European individuals, and that non-EU providers of high-risk systems must additionally appoint an authorised representative inside the Union. The practical effect is that South African exporters, business process operations, financial services firms and software vendors will build their AI governance to a European specification, because Europe is the only regime that can fine them. When Pretoria eventually legislates, it will be legislating over an industry already built to somebody else’s requirements, and rebuilding is expensive in a way that first building is not.
I have previously written about this in an article examining South Africa’s AI strategy, where I argued that policy development had been slower than anticipated because of multi-layered consultation processes, that a policy without a budget is effectively a press release, and that Rwanda, Kenya, Egypt and Mauritius had already moved from strategy to implementation while South Africa continued deliberating.
IMPLICATIONS
Two things follow. For business, the immediate task is a scope assessment rather than a compliance programme. Most organisations cannot currently say whether any output of any system they run reaches the Union, because nobody has traced it, and the answer determines whether the seven percent figure is theoretical or real. That assessment belongs to the board rather than to a project team, because the penalty base is worldwide turnover. For policymakers, the lesson is that delay does not preserve sovereignty; it transfers it. Every month without domestic rules is a month in which local practice is shaped by a regime designed for European conditions, European risk appetites and European market structures, none of which were calibrated for an economy with our constraints. A withdrawn draft is not a neutral pause. It is time in which the standard-setting happens elsewhere.
CLOSING TAKEAWAY
The uncomfortable part is not that Europe legislated first. It is that South Africa’s most visible contribution to the field this year was a policy document undone by the technology it proposed to govern. Minister Malatsi was right that the episode proves why vigilant human oversight of AI is critical, and the lesson lands harder because it landed on the department meant to teach it. The country still has the talent, the institutions and the working groups to produce something better. What it does not have is time, because the rules governing South African AI are being written now, and at present they are being written in Brussels.
Johan Steyn is a prominent AI thought leader, speaker, and author with a deep understanding of artificial intelligence’s impact on business and society. He is passionate about ethical AI development and its role in shaping a better future. Find out more about Johan’s work at https://www.aiforbusiness.net



Comments