EU AI Act
Do EU data centres put you under the AI Act?
The short answer is no. Running your systems in AWS Ireland or Azure Frankfurt does not bring your South African business under Europe’s AI law. Here is why — and what actually does.
Written by
Martin Kotze
Attorney, Conveyancer & Notary Public
Last reviewed:
Why hosting is not the trigger
Many South African companies run production systems, store data and consume AI services from European cloud regions — AWS in Ireland and Frankfurt, Microsoft Azure and Google Cloud in their EU regions, and increasingly EU-hosted AI endpoints such as Azure OpenAI or Amazon Bedrock in Frankfurt. The question boards keep asking is whether that footprint, on its own, brings Europe’s AI law down on them.
It does not, and the reasoning is straightforward once you lay the Act’s triggers against the facts. Such a company:
- Places nothing on the European market and puts nothing into service there. Both of those concepts turn on supplying a system for distribution or use in Europe — not on where the machinery running it physically sits.
- Is not a deployer established or located in the EU. It is a South African company.
- Does not produce output that is used in the EU. Its output is used in South Africa.
- Is neither an importer — which is a European role by definition — nor a distributor, because it makes nothing available on the European market.
There is a neat structural point that confirms this. The Act deliberately extends outward — reaching systems physically outside Europe whose results flow in. There is no mirror provision pulling in systems that sit physically inside Europe but whose results flow out. The drafters thought about direction of travel, and they chose outputs, not machines.
Two honest caveats
First, this rests on absence rather than authority. There is as yet no European Commission guidance and no court decision squarely addressing the “European cloud region, zero European users” fact pattern. The conclusion rests on there being no statutory trigger that these facts engage. That is strong ground — but it is not the same as positive authority saying so, and you should know the difference. At least one Africa-focused commentary has suggested that EU hosting alone could amount to placing a system on the European market. In our view that reading is not supported by the Act’s own definitions and runs against the weight of authority — but you should know it exists.
Second, the conclusion is only as durable as the facts. The day a European user logs in, a European customer signs, or output starts flowing to a European counterparty, the analysis changes. Treat “no European connection” as a state to be monitored, not a permanent status — and name the person responsible for noticing.
The London trap — and Zurich, and the EEA
A geographical footnote with real consequences: not everything a cloud provider labels “Europe” is in the European Union.
AWS Europe (Ireland), AWS Europe (Frankfurt), Azure and Google Cloud EU regions
Inside the EUStill not a trigger. Hosting there does not bring you under the Act. But if you also have European customers or users, that is what catches you — not the region.
AWS Europe (London) — eu-west-2
United KingdomThe name says Europe; the country is the UK, which left the EU in 2020. The EU AI Act does not apply there at all. For AI Act purposes, London hosting is identical to Cape Town or Johannesburg hosting.
Zurich regions
SwitzerlandOutside both the EU and the EEA. Switzerland is going its own way — ratifying the Council of Europe AI Convention with targeted sectoral changes rather than an EU-style act.
Norway, Iceland, Liechtenstein
EEA, but not yetThe Act is marked as EEA-relevant but had not been brought into the EEA Agreement as at early August 2026, so it does not yet apply there of its own force. Incorporation is expected — check the position at the time of any specific deal.
The London point deserves emphasis because of how often it is missed. AWS calls the region “Europe (London)” and gives it the code eu-west-2. It is in the United Kingdom. The EU AI Act does not apply in or to the UK, which as at mid-2026 has no equivalent statute of its own — the government has continued its “pro-innovation”, existing-regulators approach with targeted measures rather than a comprehensive AI law. This is not a technicality for South Africa: the UK is by far our largest international business-services market, so a great deal of AI-assisted work sits outside the Act entirely.
Do not confuse the AI Act with GDPR
Most of the anxiety about European data centres is really imported from data-protection law, so the contrast is worth drawing precisely.
| EU AI Act | GDPR | |
|---|---|---|
| Does using a European data centre bring you under it? | No. There is no jurisdictional trigger anywhere in the Act based on where computing or storage happens. | No, and this surprises people. A non-EU company does not become subject to GDPR just by using an EU-based processor. The EU processor itself must comply with its own processor obligations, but that does not pull the non-EU controller in. |
| So what does trigger it? | Placing AI on the European market, being established in the EU, or producing AI output that is used in the EU. | Offering goods or services to people in the EU, or monitoring their behaviour — plus processing EU-resident personal data in other qualifying ways. |
| What does data location actually control? | Nothing, for scope purposes. It is a commercial and operational decision, not a jurisdictional one. | A great deal of the mechanics — processor contracts, transfer safeguards, and the fact that sending data back out of the EU is a restricted "transfer" needing its own legal basis. |
| Can both apply at once? | Yes. A South African company selling an AI product to European customers will usually face both — GDPR for the personal data, the AI Act for the system. | Yes. Complying with one is not complying with the other. They regulate different things. |
The practical synthesis for a South African board: data location drives data-protection mechanics; the AI Act’s reach runs on markets and outputs. Neither regime is triggered by server geography alone, and complying with one is not complying with the other. A South African company serving European customers with an AI product will often face both at once — GDPR for the personal data, the AI Act for the system.
Where EU cloud AI does bind you — by contract
There is one effect of using European AI services that applies regardless of jurisdiction, and it is the one most likely to catch a South African business out: your contract.
The major AI vendors have written AI Act norms into their global terms. OpenAI has published usage requirements telling customers not to use its services for any of the Act’s prohibited practices. AWS states that none of its AI services may be used for prohibited practices under its acceptable use and responsible AI policies. These apply to you as a customer, wherever you are.
So a South African company using these services for purely domestic business is not regulated by the Act — but it is contractually bound to AI-Act-shaped conduct, and a breach is a breach of contract with its most important infrastructure supplier. That is a commercial risk with a very short fuse.
The same allocation runs through all three hyperscalers. Microsoft casts itself as the upstream provider of AI tools, services and components, and its enterprise customers as the downstream regulated actors it has to support. Google Cloud signed the general-purpose AI code of practice as a model provider and tells customers they are the deployers or providers of whatever they build. The pattern is consistent: using their European regions neither creates AI Act exposure nor discharges it. More on how the Act arrives through contracts.
Frequently asked
We run production in AWS Ireland. Does the EU AI Act apply to us?
Not because of that. If your customers and users are all in South Africa and your AI output is used only outside Europe, hosting in Ireland does not bring you under the Act. You place nothing on the European market, you are not established in the EU, and your output is not used there. You are also neither an importer nor a distributor, because you make nothing available on the European market. There is simply no trigger in the Act that your facts engage.
Is that a settled answer or a best guess?
It is strong ground, but be clear about what kind of ground it is. There is no European Commission guidance and no court decision squarely addressing the "EU cloud region, zero EU users" fact pattern. The conclusion rests on the absence of any statutory trigger, which is a solid basis but is not the same as positive authority saying so. The weight of commentary supports it. At least one Africa-focused commentary has suggested EU hosting alone could amount to placing a system on the European market — in our view that reading is not supported by the Act’s own definitions, and it runs against the general weight of authority.
What about calling an AI model hosted in Frankfurt — Azure OpenAI or Bedrock?
Same answer, same reasoning. Calling a model that happens to run on European infrastructure is not supplying anything into Europe, and it does not make you established there. If the output comes back to South Africa and is used here, no trigger is engaged. What does apply is POPIA section 72 if personal information is going there, and your provider’s acceptable use policy, which now bans the Act’s prohibited practices as a matter of contract wherever you are.
Does the London region count as Europe?
Geographically yes, legally no. AWS calls it "Europe (London)" and it carries the eu-west-2 code, but it sits in the United Kingdom, which left the EU in 2020. The EU AI Act does not apply in or to the UK. As at mid-2026 the UK has no equivalent statute either — the government has stuck with its "pro-innovation" approach of leaving AI to existing regulators, with targeted measures such as deepfake offences rather than a comprehensive AI law. For AI Act purposes a South African company using London data centres is in exactly the same position as one using Cape Town.
If hosting is irrelevant, why does everyone worry about it?
Because the worry is imported from data-protection law, where data location genuinely does drive a lot of the mechanics — processor agreements, transfer safeguards, residency commitments to customers. People reasonably assume the new AI law works the same way. It does not. GDPR regulates data; the AI Act regulates AI systems as products placed on a market. Neither is triggered by server geography alone, but only one of them makes data location matter operationally.
Does using an EU region help us with anything?
Yes, but with data protection rather than the AI Act. EU-region hosting simplifies the POPIA section 72 analysis for personal information going offshore, because a GDPR-bound European recipient clears the "substantially similar protection" bar comfortably. It also answers data-residency questions European customers ask during procurement. What it does not do is create AI Act exposure — and equally, it does not discharge any AI Act obligation you already have. Using a European region neither creates nor cures.
What should we actually do about this?
Write your conclusion down, and record the facts it depends on. "We are out of scope because all our customers and users are South African and no AI output flows to Europe" is a perfectly good position — but it is a position about facts that can change without anyone noticing. Name the person who will flag it when a European customer signs, when a European user signs up, or when an output stream starts flowing to a European counterparty. That written record is also what you hand a European customer when their AI due-diligence questionnaire arrives.
Can you review our position?
Yes. The exposure assessment runs from R15,000: an AI inventory, a map of every European touchpoint, a written scope conclusion recording the facts it rests on, and a screen against the banned practices and the transparency duties. For businesses with genuinely no European nexus it is a short piece of work that produces a document you can hand to customers and auditors.
If hosting is not what catches you, what does? Work through the three scope questions and nine South African scenarios, or start with the overview of the EU AI Act for South African businesses.
Sources & authorities
- 1.AI Act, Article 2 — scope
- 2.AI Act, Article 3 — definitions, including "placing on the market"
- 3.AI Act, Recital 22 — output used in the Union
- 4.EDPB Guidelines 3/2018 on the territorial scope of the GDPR
- 5.EFTA — EEA-Lex factsheet for Regulation (EU) 2024/1689
- 6.Swiss Federal Council — AI regulation: Federal Council to ratify Council of Europe Convention (12 February 2025)
- 7.AWS — building trust in AI: the AWS approach to the EU AI Act
- 8.Microsoft — innovating in line with the European Union’s AI Act (15 January 2025)
- 9.Google Cloud — commitment to EU AI Act support
- 10.Protection of Personal Information Act 4 of 2013 (POPIA)
Every authority above was checked against its primary source in August 2026. This page is general information about South African law, not legal advice.
For the businesses we act for
The Keystone Workspace
The attorney-designed platform the businesses we act for use to run their contracts, e-signatures and company secretarial work in one place.
Why you can trust this: Martin Kotze has been an admitted Attorney of the High Court of South Africa, registered Conveyancer, and Notary Public since 2014, practising from Pretoria. The firm is regulated by the Legal Practice Council under firm registration 17444.
This guide is general information, not legal advice for your specific matter.