AVODA Group

If You Sell to Europe, the EU AI Act Still Touches You

The EU AI Act Still Reaches You

On 27 July 2026 the European Union’s Digital Omnibus entered into force, and most of the coverage said the same thing: the AI Act has been delayed. For a Ugandan outsourcing firm, an agri-exporter or a data-services company selling into Europe, that headline is close to the opposite of useful. The high-risk rules were deferred. The rules that bite on ordinary businesses were not, and 2 August 2026 came and went as a live compliance date while almost nobody in this region was watching.

Key Takeaways

  • The Digital Omnibus deferred the high-risk obligations for standalone Annex III systems to 2 December 2027, and for AI embedded in regulated products to 2 August 2028. That is a genuine and significant delay.
  • The Article 50 transparency obligations were not part of the deferral. They took effect on 2 August 2026 and are in force now.
  • The Article 4 AI literacy duty was untouched. It requires providers and deployers to ensure their staff have a sufficient level of AI literacy, and it has applied since February 2025.
  • The Act reaches beyond the EU’s borders. It can apply to a provider or deployer established outside the Union where the output of the system is used inside it.
  • For most East African firms this is a contractual problem before it is a regulatory one. Your European client will push the obligation down the chain long before any regulator writes to you.

What actually changed, and what did not

The European Commission tabled the Digital Omnibus on AI on 19 November 2025, after implementation of the AI Act had visibly fallen behind schedule. Negotiations stalled once in late April 2026, resumed, and produced a provisional political agreement on 6 May. The European Parliament endorsed the final text on 16 June, the Council approved it on 29 June, and it entered into force on 27 July 2026.

What it moved:

ObligationPrevious dateNew date
High-risk systems listed in Annex III, standalone2 August 20262 December 2027
AI embedded in products already regulated under Annex I2 August 20272 August 2028
Article 50 transparency obligations2 August 2026Unchanged. In force
Article 4 AI literacy duty2 February 2025Unchanged. In force

The distinction matters more than it sounds. The high-risk regime is the heavy one: conformity assessments, technical documentation, risk management systems, registration. It applies to a defined list of uses, and most East African companies are nowhere near it. The transparency regime is the light one, and it applies to almost everybody.

Why a company in Kampala is inside the scope at all

The AI Act is not limited to companies established in the European Union. Its scope provisions reach providers who place an AI system on the Union market wherever they are established, deployers inside the Union, and, importantly for this region, providers and deployers in a third country where the output produced by the system is used in the Union.

Read that last clause with an East African business in mind. Consider a Kampala outsourcing firm producing customer-service responses for a European retailer, where an assistant drafts and a human sends. Consider a data-annotation company whose output trains a model deployed in Germany. Consider an agri-exporter whose grading or quality documentation is produced with an AI tool and lands with a buyer in Rotterdam. Consider a marketing agency producing AI-generated copy and images for a client in Paris.

None of those is automatically high risk. All of them are producing output that is used in the Union, which is enough to start the analysis rather than end it.

The transparency rules that are live now

Article 50 is about disclosure rather than restriction. Broadly, it requires that people are told when they are dealing with an AI system rather than a person, unless that is obvious. It requires synthetic audio, image, video and text content to be marked in a machine-readable way. It requires deepfakes to be disclosed as artificially generated or manipulated. It requires disclosure where AI-generated text is published to inform the public on matters of public interest. And it requires people to be informed where they are subject to emotion recognition or biometric categorisation.

For an East African supplier, four of those five are ordinary operational questions:

  • Does your chat or ticket handling tell the customer when a machine is answering? If a European client’s customers are on the other end, this is now their exposure and therefore yours.
  • Is AI-generated media you produce for European clients marked as such? Marking is a technical step, not a legal one, and it is easier to build into your process than to retrofit.
  • Do you publish AI-generated text on matters of public interest? Agencies producing content for European publishers should be asking this now.
  • Are you doing anything that could be read as emotion recognition? Call-centre sentiment analytics is the common one, and most firms running it have never thought of it in these terms.

The AI literacy duty is the one nobody has done

Article 4 requires providers and deployers to take measures to ensure a sufficient level of AI literacy among their staff and among others operating the systems on their behalf, taking into account their technical knowledge, experience and the context of use. It has been in force since February 2025 and it survived the Omnibus untouched.

It is unusual among compliance obligations in that satisfying it costs almost nothing and produces something the organisation actually wants. A day of properly designed training, a written record of who attended, and a policy that tells staff what they may and may not do with these tools. That is the whole thing. Most East African firms with European clients have none of it, and it is the first item a European procurement questionnaire will ask about, because it is the easiest to check.

The commercial reality: this arrives as a contract clause

Almost no East African supplier will hear from a European regulator. Every East African supplier with a European client will hear from that client’s legal team. Obligations flow down supply chains through contracts long before they flow through enforcement, and the AI Act is following the same pattern GDPR did a decade ago.

What that looks like in practice, in roughly the order it arrives:

  1. A questionnaire asking whether you use AI in delivering the service, which tools, and on what data.
  2. A request for your AI usage policy. Firms that have one send it. Firms that do not lose a fortnight and some credibility writing one under time pressure.
  3. A contract amendment adding disclosure, marking and record-keeping obligations, and often an audit right.
  4. A request for evidence of staff training.

The firms that answer those four quickly win work from the firms that cannot. That is the actual competitive dynamic here, and it has nothing to do with fines.

What to do in the next month

StepEffortWhy now
List every AI tool used in delivering work for European clients, including the ones inside tools you already pay forHalf a dayYou cannot answer a questionnaire about what you have not counted, and the embedded ones are the ones people forget
Establish whether any output reaches the UnionAn afternoonThis is the scope question. Answer it once, in writing
Adopt a written AI usage policyA fortnight, using a templateIt is the first document a European client asks for, and it does real work internally regardless of the Act
Run one AI literacy session and record attendanceOne dayArticle 4 is in force, cheap to satisfy, and easy to evidence
Check your disclosure practice on anything customer-facingAn afternoonArticle 50 is live now, not in 2027
Note the December 2027 date and move onFive minutesIf you are not in a high-risk category, that date is a diary entry rather than a project

What not to do

Do not buy a compliance platform. The obligations that apply to a typical East African supplier are satisfied by a policy, a training record and a disclosure habit, none of which needs software. Do not commission a legal opinion before you have listed your tools, because the opinion will cost more and say less than the list. And do not assume the deferral means the topic is closed for eighteen months. The deferral moved the expensive obligations. The cheap ones, which are the ones your clients will ask about, are already here.

The organisations that will handle this well are the ones that treat it as an operational tidy-up rather than a legal event. Know what you use. Say when a machine is answering. Train the people using it. Write it down. That is most of the work, and it is worth doing whether or not anyone in Brussels ever asks.

Sources

  1. European Union, Regulation (EU) 2024/1689 (the AI Act), in particular the scope provisions and Articles 4 and 50.
  2. European Commission, Digital Omnibus on AI, tabled 19 November 2025.
  3. Reporting on the provisional political agreement of 6 May 2026, the European Parliament’s endorsement of 16 June 2026, the Council’s approval of 29 June 2026, and entry into force on 27 July 2026.
  4. Legal analyses of the postponement of high-risk obligations to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I embedded systems, and of the fact that Article 50 and Article 4 were not deferred.

Position stated as at 21 August 2026. This is not legal advice. Verify against the current text and take advice on your own circumstances before acting.

Leave a Comment

Your email address will not be published. Required fields are marked *