EU AI Act
Does the EU AI Act apply to my business?
Three questions settle it. Then nine real South African situations — from a Cape Town call centre serving French clients to a Stellenbosch software house with one German customer — each with a straight answer.
Written by
Martin Kotze
Attorney, Conveyancer & Notary Public
Last reviewed:
Three doors in
Article 2 of the Act sets out its reach. Three of its limbs matter to a company established only in South Africa. Everything else in this guide follows from them.
Do you supply AI into Europe?
Licensing AI-enabled software to a German customer. Shipping an app with AI features that Europeans use. Putting an AI tool on the European market under your own name or brand.
If yes: You are a provider. No European office, entity or server is needed — supplying in is the trigger on its own.
Is any company in your group established in the EU?
An Irish subsidiary, a Dutch sales office, a German branch — and it uses AI in its own operations.
If yes: That entity is a deployer and is caught directly, regardless of who owns it. Its South African parent may also be caught for supplying AI to it.
Do the results your AI produces get used in Europe?
AI-scored calls delivered to a French client. Credit assessments sent to an EU lender. A candidate shortlist emailed to an EU employer. AI-drafted reports a Belgian customer relies on.
If yes: You are caught even though everything and everyone is in South Africa. This is the door most local businesses miss.
The third door is the one built for South Africa
The first two doors are intuitive. Sell into a market and that market’s rules apply; set up a company somewhere and that country’s law binds it. The third is different, and it is the one South African businesses walk through without noticing.
Why does that rule exist? The Act’s own explanatory recital answers it — and the example it gives could have been written about the South African outsourcing industry.
Be aware of what nobody yet knows. Neither the Act nor any European Commission guidance defines what “output used in the Union” actually means, and there is no case law. Any adviser who gives you a confident line here is overstating the position.
What commentators do agree on is the shape of it. “Output” means predictions, recommendations, decisions, scores and generated content. The rule engages where those results are consumed by people or businesses in Europe — a credit decision delivered to a European lender, a shortlist sent to a European employer, a diagnostic result for a European patient, a report generated for a European client. The word doing the limiting work is intended. Output produced deliberately for European consumption is a strong case. A South African report that someone later forwards to a Brussels affiliate is a much weaker one. Until guidance arrives, plan on this basis: if you produce AI results knowing they will be used in Europe, treat that work as in scope.
What is not a trigger
Equally important is what Article 2 does not say. There is nothing in it about:
- where the computing happens
- where your data is stored
- where the AI model you call is hosted
- which cloud region serves your application
- whether your website can be reached from Europe
The Act’s logic runs on markets, establishments, outputs and affected people — not infrastructure. That single design choice is why the data-centre question, which worries so many South African boards, has a reassuring answer. The full analysis of EU hosting.
Nine South African situations, mapped
These are the fact patterns we see most often. Treat this as a triage tool rather than an answer for your specific facts — each classification assumes the ordinary version of the situation, and assumes the European counterparties are in EU member states. Substitute a UK client and the Act falls away entirely.
You host workloads, data and AI processing in AWS Ireland, Azure Frankfurt or Google Cloud Europe. All your customers and users are in South Africa.
Position: Outside the Act. Where your servers sit is not a trigger.
What to watch: Your vendor terms still impose AI-Act-shaped conduct rules by contract. Reassess the moment any European user, customer or output stream appears.
You call EU-hosted AI APIs — Azure OpenAI in Frankfurt, Bedrock in Frankfurt — for internal tools or South African-facing products.
Position: Outside the Act, for the same reason. Calling a model hosted in Europe is not supplying anything into Europe.
What to watch: POPIA section 72 still governs the personal information going there, and your provider’s acceptable use policy still bans the prohibited practices contractually.
Your website chatbot, mobile app or AI features are used by customers in the EU.
Position: In scope. You are making the system available to people in Europe, and the output is used there. The transparency duties apply to you now.
What to watch: Chatbot disclosure, machine-readable marking of AI-generated content, deepfake labelling. Fines to €15 million or 3% of worldwide turnover.
You are a South African software or SaaS company licensing an AI-enabled product to European business customers.
Position: In scope as a third-country provider placing an AI system on the European market. You do not need a European entity for this to be true.
What to watch: Classify the product against the high-risk list now. If it is high-risk you need the full provider stack, an EU authorised representative and registration by 2 December 2027.
You are a BPO, shared-services or analytics provider delivering AI-assisted output — transcripts, quality scores, credit or KYC assessments, chat handling — to European clients.
Position: In scope through the output route. This is the exact example the Act’s own drafting notes use.
What to watch: Separate your UK clients from your EU clients — the UK is not covered. Check for banned practices (workplace emotion analytics is the common one) and for high-risk uses like credit and employment.
Your development shop builds or white-labels an AI system that a European client sells under the client’s own brand.
Position: The European client normally becomes the provider, because they supply it under their own name. You are a supplier to them.
What to watch: Get this into the contract — who is provider, who hands over documentation, who cooperates with regulators. And avoid accidentally supplying under your own mark, which would flip the role to you.
You fine-tune an open model — Llama, Mistral — and offer it in Europe.
Position: You are a provider of an AI system in any event. You become a general-purpose model provider only if your modification significantly changes the model — for which the European Commission’s guidelines use an indicative threshold of a third of the original model’s training compute.
What to watch: Ordinary enterprise fine-tuning does not come close to that threshold. Treat it as a rule of thumb rather than a bright line — it sits in non-binding guidance, not the Act. If you cross it, the model-provider duties and an EU authorised representative follow.
Your South African group has European operating subsidiaries — an insurer, a health platform, a fintech in Ireland, Germany or France.
Position: The European subsidiary is directly in scope as a deployer or provider. The South African parent supplying AI to it is caught through the supply or output routes.
What to watch: From December 2027, deployer duties for high-risk tools. Any deployer of credit-scoring or life and health insurance pricing AI must run a fundamental-rights impact assessment before first use.
You use AI recruitment screening, for South African roles only.
Position: Outside the AI Act — there is no European connection. But POPIA section 71 and South African employment law apply squarely.
What to watch: If the same tool ever screens candidates located in Europe, the output route is engaged — and recruitment AI is high-risk, which is the heaviest category there is.
The pattern to take away
Infrastructure choices — scenarios 1 and 2 — create no exposure. Commercial reach into Europe — scenarios 3 to 8 — does.
The most under-appreciated channel in South Africa is scenario 5. On industry figures published by BPESA in 2024, our global business-services sector employed over 270,000 people, of whom roughly 65,000 served international clients — and AI is now standard in how that service is delivered: chatbots, agent assist, transcription, automated quality scoring. Those same figures put the UK at around 62% of the international market served from South Africa, the US at 17% and Australia at 10%, against a continental-European share of about 1%. Since the UK sits outside the Act, the sector’s direct exposure today runs through that small European slice, plus any UK-routed engagements that ultimately serve European groups or European consumers. Treat the percentages as a 2024 snapshot of a fast-moving market, not a current reading.
The share is small. The principle is not. Where AI-assisted work product is consumed by European clients, that work is inside the Act’s reach even though the provider, the staff and the servers are all in South Africa — and the exposure grows exactly as fast as the sector diversifies into Europe.
A five-minute self-check
You can do a first pass yourself, today, without a lawyer. Six steps:
- 1List every AI tool your business uses — including the free ones your staff signed up for themselves.
- 2List every AI feature in anything you sell.
- 3For each one, write down where the result ends up: who reads it, who acts on it, and in which country they are.
- 4Mark anything where that answer is an EU member state. Note that the UK, Switzerland, Norway and Iceland are not EU member states for this purpose.
- 5For anything marked, decide whether you built and supplied it (provider) or simply use it (deployer).
- 6Write the conclusion down in a paragraph — including the facts it depends on, and who will notice if those facts change.
That last step matters more than it looks. A written scope conclusion is what you hand a European customer when their AI due-diligence questionnaire arrives, and it is what tells you which facts to watch so you notice when your answer stops being true.
Frequently asked
We have no European customers. Are we definitely out?
If no AI system you supply reaches the European market, no company in your group is established in the EU, and nothing your AI produces is used in Europe, then yes — the Act does not apply to you. That is a real conclusion, not a technicality. But treat it as a status to be monitored rather than a permanent fact: a single European customer, a European user signing up, or one report flowing to a European counterparty changes the answer.
What does "output used in the Union" actually mean?
Nobody has authoritatively defined it yet — there is no European Commission guidance and no case law, and any adviser who tells you otherwise is overstating things. What commentators agree on is a broad working reading: output covers predictions, recommendations, decisions, scores and generated content, and the rule is engaged where those results are consumed by users, customers or counterparties in Europe. The limiting principle sits in the word "intended". Output produced deliberately for European consumption is a strong case. A South African report that someone later forwards to a Brussels affiliate is a much weaker one. Until guidance arrives, the safe planning assumption is that if you produce AI results knowing they will be used in Europe, that work is in scope.
Does selling to UK customers count?
No. The United Kingdom left the EU in 2020 and the EU AI Act does not apply there. As at mid-2026 the UK has no equivalent statute — the government has stayed with its "pro-innovation" approach of leaving AI to existing regulators, with targeted measures rather than a comprehensive AI law. This matters more than it sounds for South Africa: the UK dominates our international business-services market, so a large share of the sector’s AI-assisted work sits outside the Act entirely. Map your client list country by country rather than treating "Europe" as one thing.
What about Switzerland, Norway and Iceland?
Switzerland is outside both the EU and the EEA and is going its own way, so Zurich cloud regions and Swiss clients sit outside the Act on the same logic as the UK. Norway, Iceland and Liechtenstein are in between: the Act is marked as EEA-relevant but had not yet been brought into the EEA Agreement as at early August 2026, so it does not yet apply there of its own force. That is expected to change, so check the position at the time of any specific deal.
Does using ChatGPT or Claude in our business put us in scope?
Not by itself. Using a general-purpose AI tool inside a South African business, for South African work, engages none of the three triggers. The model builders carry their own obligations for the models — that is their problem, not yours. What using those tools does do is bind you contractually: their terms now prohibit using the service for any of the Act’s banned practices, wherever you are. And if you build a customer-facing chatbot on top of one of those models and Europeans use it, you become the provider of that chatbot — the disclosure duty is yours, not the model vendor’s.
Are we a "provider" or a "deployer"?
You are a provider if you develop an AI system, or have one developed, and supply it under your own name or trademark. You are a deployer if you use an AI system under your own authority in a professional context. Providers carry the heavy duties; deployers carry lighter ones. The complication is that you can switch roles without intending to: if you put your brand on someone else’s high-risk system, change it substantially, or repurpose a general-purpose system into a high-risk use, you become the provider and inherit the full obligation stack. That is a contractual issue as much as a legal one, and it belongs in your development and white-label agreements.
Should we write down why we think we are out of scope?
Yes — and this is the single most useful thing a business can do this quarter. A short written record of your AI inventory, every European touchpoint, and the reasoning behind your scope conclusion does three jobs at once. It gives you an answer when a European customer sends an AI due-diligence questionnaire. It tells you which facts to monitor, so you notice when the conclusion stops being true. And it demonstrates the kind of governance POPIA, King IV and the financial-sector regulators increasingly expect regardless of Europe.
What does a scope assessment cost?
From R15,000 for the exposure assessment: an AI inventory, a map of every European touchpoint, a written scope conclusion recording the facts it depends on, and a screen against the banned practices and transparency duties. For businesses that turn out to be in scope, the follow-on work — role classification, high-risk assessment, contract remediation — is quoted on scope.
Start with the overview of the EU AI Act for South African businesses, or go straight to the rules that are already enforceable: the banned AI practices and the transparency duties.
Sources & authorities
- 1.AI Act, Article 2 — scope
- 2.AI Act, Recital 22 — output used in the Union
- 3.AI Act, Article 3 — definitions of provider and deployer
- 4.AI Act, Article 25 — responsibilities along the AI value chain
- 5.Regulation (EU) 2024/1689 (the AI Act) — full text, EUR-Lex
- 6.European Commission — artificial intelligence questions and answers
- 7.ENSafrica — extraterritorial application of the EU AI Act
- 8.Protection of Personal Information Act 4 of 2013 (POPIA)
Every authority above was checked against its primary source in August 2026. This page is general information about South African law, not legal advice.
For the businesses we act for
The Keystone Workspace
The attorney-designed platform the businesses we act for use to run their contracts, e-signatures and company secretarial work in one place.
Why you can trust this: Martin Kotze has been an admitted Attorney of the High Court of South Africa, registered Conveyancer, and Notary Public since 2014, practising from Pretoria. The firm is regulated by the Legal Practice Council under firm registration 17444.
This guide is general information, not legal advice for your specific matter.