AI

Regulating AI in Practice - Europe's AI Act Amendments

By Frederick Ofwono

For much of the past two years, the EU’s AI Act has been held up internationally as proof that AI can be regulated without strangling the innovation it governs. Today, a different question is emerging. What happens when a law's ambition outpaces the capacity of the institutions meant to enforce it?

That question sits at the heart of the European Parliament's decision, on 16 June 2026, to amend the AI Act, a law it had only just finished negotiating. The amendment delays several of the Act's toughest requirements. At the same time, it introduces one new and stricter rule. An outright ban on AI tools that generate non-consensual sexual images of real people.

From Precaution to Pragmatism

When the AI Act was adopted in 2024, it embodied a precautionary regulatory model: set comprehensive rules early and trust that the institutions and technical standards required for implementation would be ready in time. By 2026, however, it had become clear that this was not entirely the case. Important technical standards were still being developed, while some national oversight bodies remained underprepared for the responsibilities assigned to them.

This implementation challenge coincided with a broader political shift. In a 2024 competitiveness report commissioned by former Italian Prime Minister Mario Draghi, Europe was warned that it was falling behind the United States and China in advanced technologies because of underinvestment, slow decision-making, and an increasingly burdensome regulatory environment.

Measures that had been presented as responsible governance only a year earlier increasingly came to be viewed as obstacles to innovation and competitiveness. Industrial firms such as Siemens and ASML called for AI-enabled machinery to be excluded from the Act's scope, while major US technology companies pressed for regulatory concessions.

The debate intensified further when Washington reportedly linked tariff relief for European exports to changes in the EU's technology rules, a move that the European Commission's deputy chief publicly described as "blackmail." Civil society organisations, including Amnesty International, argued with equal force that key safeguards were being diluted before they had been properly tested. The result was not a retreat from regulation, but a shift towards a more adaptive approach. Rather than treating compliance deadlines as fixed, the amended framework aligns regulatory obligations more closely with institutional readiness and implementation capacity.
Under the revised timetable, obligations for high-risk AI systems used in areas such as recruitment, lending, education, law enforcement, immigration, and critical infrastructure have been deferred until December 2027 for standalone systems, and August 2028 for AI integrated into safety-critical products. Requirements to label AI-generated content have similarly been moved to December 2026. AI-enabled industrial machinery has been brought under existing machinery safety legislation, while small and medium-sized enterprises have been given simplified compliance pathways.

One notable exception is the treatment of AI-generated non-consensual sexual content and child sexual abuse material. Here, the law moved in the opposite direction, introducing an outright prohibition with a December 2026 compliance deadline. The message is clear: adaptive regulation may allow flexibility in implementation, but it does not mean that every safeguard is open to compromise.

Is This Unique to Europe?

Europe is not the only jurisdiction discovering that AI regulation written years in advance struggles to survive contact with reality. The United States never attempted a comprehensive federal framework at all, leaving AI governance to a patchwork of state-level rules that some critics point to as a cautionary example of fragmentation.

China has taken the opposite path, regulating specific AI applications, generative content, recommendation algorithms, and deepfakes as they emerge, rather than legislating comprehensively in advance. The United Kingdom has avoided a dedicated AI law altogether, relying instead on existing sector regulators to apply general principles. Seen against that backdrop, the EU's amendment looks less like a retreat and more like a correction toward the kind of flexibility other jurisdictions built in from the start.


What This Could Mean for African AI Governance

For African governments currently drafting their own AI legislation, much of this matters less for what changed, and more for what it confirms: that the gap between writing ambitious legislation and building the institutions to enforce it is not a uniquely European problem. This argues for AI frameworks that build adaptiveness in from the start rather than retrofitting it under pressure, as Europe has had to do. Risk categories defined around durable principles, rather than an exhaustive list of use cases, are better placed to absorb new technologies and new objections without requiring renegotiation each time one arises, the kind of renegotiation that produced Europe's machinery carve-out.

Enforcement built around shared regional capacity, akin to the EU model pursued through its centralised AI Office, is more realistic than expecting more than fifty individual African states to each build expert AI regulators from scratch. An approach that the African Union's own Continental AI Strategy already gestures toward. Therefore, compliance deadlines tied explicitly to institutional readiness, rather than fixed independently of it, would spare African legislators the same backtracking Europe is now undertaking.

The Pressure Question

Adaptive regulation carries its own risks. The same flexibility that allows laws to be aligned with institutional capacity can also make them more vulnerable to lobbying and political pressure. Europe's amendments were shaped not only by implementation challenges but also by pressure from industry, technology firms, and external trading partners. The EU's strong institutions and negotiating leverage enabled it to absorb those pressures while preserving the core structure of the AI Act.

Many African states, however, operate with less influence in trade negotiations and greater dependence on foreign-owned cloud and AI infrastructure. As a result, they may be more exposed to the same pressures.

The deeper lesson is that adaptability is only valuable when its boundaries are defined in advance. Regulatory adjustments should be guided by clear and consistent principles, not by the relative influence of competing interests. This requires policymakers to identify from the outset which safeguards are non-negotiable. As the EU demonstrated with its prohibition of AI-generated sexual exploitation material, some protections must remain beyond compromise, even as other aspects of the regulatory framework evolve.

Sovereignty and the New AI Order

This amendment has implications far beyond Europe. For African states, it provides a useful example of how AI regulation can be tailored to local circumstances through phased implementation, flexible risk frameworks, and the centralisation of scarce regulatory expertise.

The EU's experience also serves as a reminder that AI regulation does not develop in a vacuum. There is always a risk that legislation may be shaped by the interests of powerful technology firms or foreign governments rather than domestic policy priorities. For African states, many of which are more dependent on foreign cloud and AI services than the EU, that risk is even greater. Building data and AI sovereignty into legislative frameworks from the outset is therefore not simply desirable; it is essential.

A Defining Moment for AI Governance

Europe's amendment to the AI Act reflects a broader shift in AI governance, one that recognises regulation not as a finished legislative project, but as an ongoing process of adapting rules to practical and institutional realities.