AI
Navigating the Evolving Landscape of AI Regulation: From the EU's AI Act to Global Implications
By Veronica Shiroya
The European Union’s AI Act and the South Korea AI Basic Act stand as the world’s first comprehensive legal frameworks dedicated to AI. Focusing on the EU AI Act, it's primary objective is to foster trustworthy AI by categorising systems according to risk and imposing corresponding obligations. However, the regulatory trajectory is not static. The European Commission’s recent Digital Omnibus proposal on AI published in November 2025 signals a significant shift towards reducing the compliance burden to developers and deployers and addressing practical implementation challenges. This article analyses the evolving structure of the AI Act, the implications of its amendments, and the consequent strategic considerations for other regions, particularly African nations developing their own governance approaches.
The risk-based system
The AI Act establishes a four-tiered risk hierarchy, each with distinct regulatory consequences.
At the apex lies the category of Unacceptable Risk, where AI systems considered a clear threat to safety, livelihoods, and fundamental rights are outright banned. Since February 2025, this has prohibited eight specific practices, including harmful manipulation, social scoring, untargeted facial recognition database scraping, and real-time remote biometric identification in public spaces by law enforcement. The Commission has supplemented these prohibitions with practical guidelines to clarify definitions and provide examples, aiding stakeholders in understanding and complying with these foundational bans.
Beneath this are High-Risk AI systems, which can pose serious threats to health, safety, or fundamental rights. This category encompasses AI used in critical domains such as migration and border control, law enforcement, biometric identification, critical infrastructure, education, employment, and the administration of justice. These systems are subject to strict ex-ante obligations, effective from August 2026 and 2027, including mandatory conformity assessments, robust risk management systems, the use of high-quality datasets to mitigate bias, comprehensive documentation, and provisions for human oversight before they can enter the market.
The third tier addresses Transparency Risk, referring to obligations designed to preserve human trust through disclosure. This does not concern the inherent safety of the system but the need for clarity in human-AI interaction. The Act mandates that users must be clearly informed when they are interacting with an AI system, such as when encountering chatbots, emotion recognition systems, or AI-generated content like deepfakes. These transparency rules, set to apply from August 2026, ensure that humans are not deceived about the nature of their interaction, maintaining informed consent and autonomy.
Finally, the broad base of the pyramid consists of AI with Minimal or No Risk. The vast majority of AI applications, such as AI-enabled video games, spam filters, or recommendation systems, fall into this category. For these systems, the AI Act introduces no specific new regulatory requirements. This intentional lack of intervention aims to promote continued innovation and adoption across the economy, ensuring that the regulatory burden is proportionate and focused squarely on addressing identifiable harms rather than stifling technological development.
A shifting regulatory landscape
Acknowledging implementation hurdles, the November 2025 Digital Omnibus proposal introduces targeted simplifications to ensure a proportionate and workable regulatory regime.
Addressing Unworkable Deadlines - The proposal recognises that the lack of published harmonised standards, common specifications, and compliance tools for high-risk AI creates significant uncertainty for businesses. The suggested delays aim to align obligations with the availability of these essential technical resources.
Softening of AI Literacy Obligations - The binding mandate for providers and deployers to enhance AI literacy has been transformed. Responsibility now lies with the Commission and Member States to "foster" and "encourage" such measures, effectively moving from a hard obligation to a soft, promotional approach.
Reducing Disclosure Burdens for Exceptions - The Article 6(3) exception, which allows providers to self-assess that a system is not high-risk due to its narrow function, no longer requires public disclosure of the reasoning. While the assessment must be provided upon request, this change mitigates the legal and reputational risks previously associated with invoking the exception.
Broadening Bias Detection Provisions - A new Article 4a expands the legal basis for processing special categories of personal data (e.g., biometric data) beyond just providers of high-risk systems. Now, both providers and deployers can process such sensitive data solely for the purpose of detecting and correcting bias, a crucial flexibility for improving fairness.
Expanding Regulatory Sandboxes - The proposal facilitates broader real-world testing of high-risk AI under supervision and grants the AI Office the authority to establish an EU-level regulatory sandbox, promoting innovation within controlled safeguards.
Strategic implications for AI regulation in African countries
The EU AI Act is often viewed as a global template. However, its evolving trajectory suggests caution rather than haste for other regions, including African countries, currently developing AI strategies and policy frameworks.
Given the early-stage deployment of AI systems in many African economies, there is a compelling argument against rushing into binding, comprehensive AI legislation. Overregulation risks stifling innovation, limiting local capacity-building, and entrenching dependence on foreign AI systems.
Instead, African countries can pragmatically leverage existing legal frameworks to govern AI risks, including:
Data Protection and Privacy Laws, particularly provisions on automated decision-making and profiling, which grant individuals the right not to be subject to solely automated decisions with significant effects.
Consumer Protection Laws, including unfair and deceptive trade practices regimes, to address misleading AI-driven advertising, deepfakes, and harmful content.
Anti-Discrimination and Employment Laws, which can be applied to biased AI outcomes in hiring, lending, and access to services.
Criminal and Cybersecurity Laws, which already regulate malicious uses of AI, such as fraud, impersonation, cyberattacks, and non-consensual synthetic media.
This layered, adaptive approach allows African states to address real harms while preserving regulatory flexibility and encouraging innovation.
The EU AI Act demonstrates that AI regulation is not static but iterative. The shift from rigid timelines to adaptive implementation, the softening of certain obligations, and the emphasis on sandboxes and guidance underscore a broader lesson: effective AI governance requires regulatory humility, technical realism, and institutional learning.