As 2026 unfolds, the interplay between data, AI, and infrastructure is shaping strategic decisions across markets. South Africa’s focus on vertical AI integration and infrastructure resilience contrasts with the UK and EU’s tightened regulatory frameworks for AI and data governance. Here’s how businesses must adapt.
---
Telkom’s multi-year investment in OSS/BSS (operations support systems/business support systems) overhaul, as reported by TechCentral in “Why Telkom Is Pouring Capex into IT”, signals a strategic shift toward enabling converged selling of fibre, mobile, and fixed-wireless products. This infrastructure upgrade not only aims to increase average revenue per user (ARPU) but also paves the way for AI integration in demand forecasting and network optimization. For enterprises, this highlights the importance of aligning AI tools with legacy systems that require modernization to unlock scalability.
The four-year standoff between Telkom and the Special Investigating Unit (SIU), detailed in “Telkom’s Four-Year SIU Standoff Awaits a Final Ruling”, underscores the risks of prolonged legal battles on data governance. While the case hinges on whether the SIU can reopen its investigation, it indirectly pressures companies to build redundant governance frameworks—as warned by Moneyweb in “When Governance Becomes Optional…”—to mitigate reliance on external regulatory environments.
---
The EU’s AI Act and the UK’s GDPR (plus the Employment Rights Act 1996 for data in HR systems) are converging to create a compliance-centric AI landscape. The AI Act’s risk-based classification of AI systems—ranging from unacceptable risk (banned) to minimal risk (self-declared compliance)—demands that businesses in both regions map AI use cases to regulatory tiers. For instance, UK firms deploying AI in customer service must ensure data minimization and transparency under GDPR, while EU entities must address high-risk AI systems (e.g., biometric tracking) with strict documentation.
South Africa’s Protection of Personal Information Act (POPIA) shares similarities with GDPR but introduces unique requirements, such as data subject rights tied to local law enforcement and stricter cross-border data transfer rules. This divergence means global enterprises must tailor compliance strategies for each region, potentially increasing operational costs but reducing legal exposure.
---
Microsoft’s end of support for Windows 10 (October 2025, per MyBroadband’s “Windows 10 Is Now a Business Risk…”) is a security and compliance crisis for organisations across markets. Unpatched vulnerabilities expose businesses to cyberattacks and regulatory scrutiny under both GDPR and POPIA. For example, a UK fintech firm running Windows 10 could face fines under GDPR Article 83 for failing to implement “state of the art” security measures.
---
---
**