Artificial Intelligence (AI) should be embraced, but deception should not be, and South African businesses should understand that Europe’s AI rules may apply even if they have no office in Europe.
The European Union has introduced something that, at first glance, seems remarkably modest. It is a set of icons identifying content as AI-generated or AI-modified. However, look more closely, and the idea is much bigger than the icon. Europe is attempting to establish a new social convention for the age of AI.
People should not have to guess whether what they see, hear or read is authentic, artificially generated or materially manipulated.
The EU system provides labels indicating that AI was involved, content was fully AI-generated or existing material was partially AI-modified. The icons themselves are optional. However, that must not be confused with the legal obligations underlying them.
Article 50 of the EU Artificial Intelligence Act imposes mandatory transparency requirements concerning specified AI-generated and manipulated content. Those requirements became applicable on 2 August 2026.
For South Africa, two immediate lessons deserve attention. The first is philosophical and regulatory – AI should be embraced, but deception should not. The second is commercial and potentially urgent. A South African business does not necessarily need a European subsidiary, branch or office. The EU AI Act can still apply to it.
What must actually be disclosed?
There are different sides to the European regime, and understanding the distinction is important.
Providers of AI systems that generate synthetic audio, images, video or text must ensure that outputs carry machine-readable markings. However, specified qualifications and exceptions apply. The markings must make outputs detectable as artificially generated or manipulated. Furthermore, technical measures must, so far as technically feasible, be effective, interoperable, robust and reliable.
There are separate obligations for those who deploy AI professionally. An AI system may create or manipulate an image, audio recording or video constituting a deepfake. In such cases, the person must disclose that it has been artificially generated or manipulated.
Similarly, AI-generated or manipulated text informing the public on matters of public interest may require disclosure. However, an important qualification applies where the material has undergone human review or editorial control. A person or organisation must also assume editorial responsibility for it.
The disclosure should not be buried in pages of terms and conditions or hidden in obscure technical documentation. Instead, it must be clear and distinguishable when the person first encounters the relevant content. Therefore, the thinking behind the EU icon system is as important as the artwork itself. Transparency should become readily visible rather than something discovered only after careful investigation.
There are also sensible limitations intended to prevent the regime from becoming disproportionate. Europe does not require a warning label for every use of spell-check, automated editing, photographic enhancement or AI-assisted sentences. Furthermore, artistic, creative, satirical and fictional works receive particular treatment. Ordinary AI assistance that does not substantially alter the source material is also treated differently. It is not treated in the same way as synthetic impersonation or a deceptive deepfake.
Adopt the principle, don’t copy the law
In my view, South Africa should develop something similar, but in a manner appropriate to our constitutional and economic circumstances. We should not mechanically import European legislation or regulate AI merely because Europe has done so. However, the principle underlying the European approach deserves serious consideration. AI should be embraced, but deception should not be.
South Africa should consider establishing a simple, nationally recognisable disclosure standard for materially AI-generated or AI-manipulated content. This should cover photographs, video, audio and significant public-interest communications. Such a system should be technologically neutral, understandable to ordinary people and compatible with international provenance standards. It should also be accessible to people with disabilities and sufficiently proportionate. Therefore, it should not burden harmless or routine uses of AI.
This is not an argument against AI, and we should never present it as one. AI will, in my view, bring extraordinary benefits to medicine, education, science, law, literature, business and human creativity. Good regulation should allow those benefits to flourish. At the same time, it should protect society against impersonation, manipulation and deliberate deception.
Start with the Constitution
There is also a particularly compelling South African constitutional dimension to this debate. Our Constitution protects human dignity, privacy and freedom of expression. However, sophisticated synthetic media can engage all three simultaneously. Lawmakers, courts, businesses and citizens will increasingly have to confront these challenges.
A cloned voice can interfere with identity and dignity. Meanwhile, a manufactured intimate or defamatory image can devastate privacy and reputation. A political deepfake can also distort public discourse. Yet lawmakers must take great care not to suppress legitimate expression, satire, creativity or technological innovation when responding to those dangers.
Therefore, the difficult policy question is not whether South Africa should permit AI, because plainly it should. The real challenge is how we maximise the extraordinary benefits of AI. At the same time, we must preserve the ability of human beings to distinguish authentic communication from manufactured reality. A transparent labelling framework could become one important part of that answer.
No European office, no exemption
This is perhaps the most important practical issue for South African boards, executives, lawyers and compliance officers.
The EU AI Act has extraterritorial reach. Therefore, a South African company should not assume that European AI legislation is irrelevant. The business may be incorporated in Johannesburg, Cape Town, Durban or elsewhere in South Africa. It may also have no European subsidiary or physical establishment.
The Act can apply to providers placing AI systems or general-purpose AI models on the EU market. This applies regardless of whether those providers are established within the European Union. The Act also applies to deployers situated within the EU. Importantly, it can apply to providers and deployers established outside the EU. This applies where the output produced by the AI system is used within the European Union. Consequently, this changes the compliance conversation considerably.
A South African company selling an AI-enabled service into Europe may therefore potentially be affected. Similarly, a South African technology developer offering its AI system to European customers may potentially fall within scope. A South African group producing AI-generated material in Johannesburg for use by a European subsidiary may likewise be affected. Depending upon the circumstances, the relevant AI output may ultimately be used within Europe. Even this fact can become legally significant.
Boards should therefore stop asking only whether the organisation has an office in Europe. Instead, they should ask broader questions about where they place AI on the market. They should also establish where its outputs are ultimately used. Furthermore, they should ask who is using those systems and whether European customers, subsidiaries, employees or audiences are involved. Finally, they should establish what regulatory role the organisation performs under the EU AI Act. This may include provider, deployer, importer, distributor or another regulated participant.
EU compliance – what should you do now?
Every South African organisation with meaningful European-facing activities should consider conducting an EU AI Act applicability assessment. First, organisations should establish precisely where they develop, supply, purchase and use AI. Compliance cannot be managed effectively if the organisation itself does not know where AI is operating.
Companies should inventory their AI systems and use cases. They should determine whether they are acting as providers or deployers. They should also identify AI-generated customer communications, advertising, images, audio, video and public-interest content. Then, they should establish which Article 50 transparency requirements apply. This exercise should also identify the persons responsible for approving, monitoring and documenting the organisation’s use of AI-generated content.
A South African company may develop or supply its own generative AI system into the European market. In that case, it should examine the requirements concerning machine-readable marking and detectability. Alternatively, it may use third-party generative AI professionally in marketing, publishing, social media, advertising and corporate communications. It should then assess whether deepfake or other disclosure obligations arise. Furthermore, it should establish procedures ensuring that required disclosures accompany the relevant content.
Companies should also consider customer-facing conversational AI and similar systems. People may interact directly with an AI system in circumstances covered by the legislation. In such cases, companies may need to inform them that they are interacting with AI. However, this does not apply when it is already obvious to a reasonably well-informed and observant person. Therefore, transparency is relevant not only to media content but also to the broader customer experience.
Compliance beyond the technology
Contractual arrangements deserve particular attention because companies cannot simply assume that regulatory responsibility belongs to the technology supplier. AI procurement agreements should allocate responsibility for regulatory compliance, provenance information, technical marking and disclosure capability. They should also allocate responsibility for documentation, audit rights and cooperation with regulators. A company should not discover after publication that its AI supplier cannot determine whether content can reliably be identified as synthetic.
Internal governance is equally important and should extend well beyond the IT department. Organisations should create a clear policy governing AI-generated content and establish human-review processes. They should identify who is accountable for public communications and train marketing and communications teams. Furthermore, they should preserve evidence of compliance and provide an escalation process for uncertain cases before publication. This makes AI-generated content an issue for legal, compliance, risk management and board governance.
Financial consequences make it a board issue
Failure to comply with Article 50 transparency obligations falls within the EU AI Act’s penalty regime. Therefore, the potential consequences are significant enough to demand board attention. For undertakings, penalties can reach €15 million or 3% of total worldwide annual turnover in relevant circumstances. However, the legislation includes detailed provisions and differentiated treatment of smaller enterprises.
The words worldwide annual turnover should therefore attract the attention of every board operating internationally. Organisations should not delegate European AI compliance entirely to a marketing department because someone occasionally uses an image generator. Instead, compliance requires governance structures capable of determining where organisations use AI and what regulatory role they occupy. These structures should also determine which jurisdictional obligations follow from that role.
King V and the governance of trust
There is also a natural South African governance dimension to the debate, particularly through the philosophy of King V. Responsible governance cannot end with technical legal compliance. Governing bodies must understand how emerging technologies affect ethics, stakeholders, reputation, risk, accountability and legitimacy. AI illustrates those responsibilities particularly well.
An organisation may be technologically capable of creating a convincing synthetic spokesperson, fabricated customer testimonial or artificially generated executive video. However, the deeper governance question is whether it should do so without clearly telling its audience what they are seeing. Technology may permit such actions, but responsible leadership may require something different. This distinction may become one of the defining governance questions of our generation.
The Stoics would have recognised the problem
Marcus Aurelius could never have imagined generative AI, but he understood something fundamental about human judgment. Appearances are not necessarily reality. Therefore, we must exercise reason before accepting what appears before us as truth. This lesson seems remarkably contemporary in an environment of synthetic photographs, cloned voices and manufactured video.
Ancient Egyptian civilisation similarly placed enormous value on Ma’at: truth, balance, justice and right order. Meanwhile, Roman thought placed great importance on fides: trust, good faith and reliability in human and civic relationships. Thousands of years later, AI has not made these principles obsolete. On the contrary, it has arguably made them more important.
We now possess technology capable of creating a voice belonging to someone who never spoke. It can create a photograph of an event that never happened. It can also create a video of a person doing something they never did. The technological achievement is astonishing, but the ethical responsibility accompanying that capability must be equally significant. Otherwise, public confidence in information, institutions and organisations may not survive.
The icon is really about trust
Perhaps that is the larger lesson from Europe. The EU icon is ultimately a small visual device representing an enormous idea. Human beings deserve to know when technology has materially altered the reality presented to them. Organisations that understand this may ultimately earn more trust by being open about their use of AI.
Therefore, the most successful organisations of the AI age may not be those that disguise how extensively they use AI. Instead, they may confidently tell stakeholders that AI helped create particular content and that they disclosed its use. Nevertheless, a human being or accountable organisation remains responsible for what has been published.
We should not regard that approach as weakness or embarrassment about using AI. Transparency and innovation are not enemies. Instead, they can reinforce one another. South Africa should consider adopting that principle before a major scandal, deepfake crisis or loss of public confidence. Otherwise, these events may force us to act reactively.
We should therefore embrace AI, encourage innovation and use the technology boldly. However, transparency should follow when AI crosses the boundary from assistance into manufacturing or materially altering apparent reality. Ultimately, AI should be embraced, but deception should not be.

Credit: European Commission, EU Icons for labelling AI-generated content, and Regulation (EU) 2024/1689 – the European Union Artificial Intelligence Act.
This article is intended for general information and discussion and does not constitute legal advice. South African organisations supplying into, operating within, or producing AI outputs for use in the European Union should obtain advice concerning the application of the EU AI Act to their particular circumstances.
Michael Judin | Partner | Judin Combrinck Inc | mail me |

























