Search legal guides

Search MJ Kotze Inc legal guides and articles

EU AI Act

High-risk AI and the December 2027 deadline

If your AI helps decide who gets hired, who gets credit, what an insurance policy costs or who passes an exam — and any of that happens in Europe — this is the part of the Act that will cost you real money to comply with. You have roughly sixteen months.

Written by

Martin Kotze

Attorney, Conveyancer & Notary Public

Last reviewed:

Quick answer

First, the good news about the date

The stage everyone expected on 2 August 2026 did not arrive. The high-risk regime was pushed back by roughly sixteen months, six days before it was due to land.

The reason was practical rather than political. The technical standards that were supposed to tell companies how to meet the requirements had not been published, and the European Commission had missed its own deadline for guidance on classifying high-risk systems. Regulating without telling anyone how to comply was untenable, so the deadlines moved: 2 December 2027 for the stand-alone high-risk uses, 2 August 2028 for AI built into regulated products. Those dates are now fixed and no longer conditional on standards being ready.

For a South African company selling AI into Europe this is a genuine reprieve — and the right way to use it is as a preparation window. The work involved is organisational, not just documentary, and organisations move slowly.

What counts as high-risk

The Act lists the specific uses that qualify. Four clusters matter most to South African exporters — and if you are not in one of them, this whole regime probably does not touch you.

Employment

Recruitment and selection tools, CV screening, candidate evaluation, promotion and termination decisions, task allocation and monitoring of workers.

South African angle: The biggest South African exposure. HR-tech vendors with European employer clients, and any BPO or shared-services operation whose AI touches hiring for European entities.

Essential services and credit

Creditworthiness assessment and credit scoring, and risk assessment and pricing for life and health insurance.

South African angle: South African fintechs selling scoring models to European lenders, and insurtechs supplying pricing engines to European insurers, are building squarely in this territory.

Education

Admissions decisions, assessment and marking, and exam proctoring.

South African angle: Edtech products sold into European institutions. Proctoring in particular attracts attention because it usually involves biometrics as well.

Biometrics

Remote biometric identification, biometric categorisation, and emotion recognition where it is not already prohibited outright.

South African angle: Note the overlap with the banned list — emotion recognition in workplaces and education is prohibited entirely, not merely high-risk.

A South African fintech selling scoring models to European lenders, an HR-tech vendor with European employer clients, or an insurtech supplying pricing engines to European insurers is building in exactly this territory. So is a BPO whose AI-assisted output feeds any of those decisions for a European client. Check whether the Act reaches you at all before working through this page.

If you build it: the provider stack

This is the substantial part of the Act, and it is worth seeing in one place so the scale is honest. Nine obligations, each of which is real work.

ObligationWhereWhat it means
Risk managementArticle 9A documented risk-management process running across the whole life of the system, identifying and reducing risks to health, safety and fundamental rights. Not a once-off assessment.
Data governanceArticle 10Training, validation and test data that is relevant, sufficiently representative, and examined for bias. You have to be able to show what went into the model.
Technical documentation and loggingArticles 11–12A prescribed documentation set kept current, and automatic event logging built into the system.
Instructions for deployersArticle 13Documentation that lets the businesses using your system understand it, supervise it and operate it correctly.
Human oversightArticle 14Designed so trained people can actually supervise, intervene and override. Oversight that exists on paper but cannot be exercised does not count.
Accuracy, robustness, cybersecurityArticle 15Appropriate levels, declared up front and maintained across the system’s life.
Quality management systemArticle 17An organisation-level QMS covering design, development, testing and post-market monitoring. This is the biggest lift for most companies.
Conformity assessment, CE marking, registrationArticles 43, 47–49Mostly a self-assessment against the requirements, then an EU declaration of conformity, a CE mark, and registration in the EU database before you may place the system on the market. Certain biometric systems need a third-party notified body.
EU authorised representativeArticle 22A third-country provider must appoint a representative established in the EU before making the system available. This is the practical anchor for enforcement against you.

The quality management system is the item most companies underestimate. It is not a document you write in a week — it is an organisation-level process covering design, development, testing and post-market monitoring, and it has to be genuinely operating before a conformity assessment means anything. If you expect to be in scope, that is the piece to start on first.

You will need someone in Europe

One requirement deserves separating out, because it is structural rather than procedural and it surprises South African founders.

A provider established outside the EU must appoint an authorised representative established inside it before making a high-risk system available. That representative verifies your documentation, keeps it available for authorities, and cooperates with them. Critically, the representative must resign and notify the regulator if it considers you are not complying — so this is not a mailbox arrangement.

Failing to appoint one is itself finable, and in practice it blocks market access. It is also the answer to the question South African boards keep asking about how Europe could ever enforce against them: the representative requirement gives regulators an address, and market-surveillance authorities can act on the product itself — ordering corrective action, restricting availability, or forcing withdrawal — without ever needing jurisdiction over your company.

If you only use it: deployer duties

Businesses that use a high-risk system rather than build it carry a lighter set of duties. These land on European subsidiaries of South African groups, and on the European customers of South African vendors — which is precisely why those customers push obligations back up the chain to you.

  • Use the system according to the provider’s instructions.
  • Assign human oversight to people who are trained and competent to exercise it.
  • Make sure the input data you control is relevant and sufficiently representative.
  • Monitor how the system operates in practice.
  • Keep the automatically generated logs for at least six months.
  • Inform workers before you use such a system in the workplace.
  • Inform the individuals affected by decisions the system contributes to.

Some deployers go further. Bodies governed by public law, private entities providing public services, and any deployer of credit-scoring or life and health insurance pricing AI must complete a fundamental-rights impact assessment before first use. Note that the last category turns on what the system does, not on what kind of business you are — so it reaches a lender or insurer only because of the AI they deploy. If your South African group has a European insurer or lender in it, that duty is coming for them directly.

The white-label trap

The Act polices the value chain, and this is where South African development houses need to be deliberate.

A distributor, importer, deployer or any other third party that puts its name or trademark on a high-risk system, substantially modifies one, or repurposes a general-purpose system into a high-risk use becomes the provider — and inherits the entire stack above.

In the ordinary white-label arrangement the European client becomes the provider, because they supply the system under their own name, and you are a supplier to them. That is usually the right commercial outcome — but it should be a decision recorded in the contract rather than something discovered later. Deal expressly with who is the provider, who hands over technical documentation and instructions for use, who notifies incidents, who controls substantial modifications, and who provides log access so the deployer can meet its own retention duty.

Sixteen months, in order

The sequencing matters, because the expensive items depend on the cheap ones being done first. There is no point building a quality management system before you know whether your product is even high-risk.

  1. Now – mid 2027Live now

    Classify and assess

    For each system in scope, fix your role — provider, deployer or neither — and classify it against the high-risk list. The European Commission published draft classification guidelines in May 2026, three months after its own deadline; use them, but treat them as draft until the final version lands. If your system is likely high-risk, run a gap assessment against the Article 9 to 15 requirements. Negotiate role allocation into your white-label and development contracts now, while there is still leverage.

  2. Mid 2027Ahead

    Build the machinery

    Stand up the quality management system, plan the conformity-assessment route, and line up an EU authorised representative. The QMS is the long pole — it is an organisational change, not a document.

  3. 2 Dec 2027Ahead

    Annex III high-risk obligations apply

    Full compliance for stand-alone high-risk systems — recruitment, credit, insurance, education, biometrics. Conformity assessment, CE marking, EU database registration, deployer procedures, and fundamental-rights impact assessments where the deployer category requires them.

  4. 2 Aug 2028Ahead

    Annex I product AI obligations apply

    The same regime for AI embedded in regulated products — machinery, medical devices, vehicles, lifts, toys.

Frequently asked

What counts as "high-risk" AI?

Two groups. The first is a list of stand-alone use cases where AI makes or contributes to decisions that seriously affect people. Four clusters matter to South African exporters: employment (recruitment, CV screening, candidate evaluation, promotion and termination, task allocation and worker monitoring); essential services including creditworthiness assessment and risk assessment and pricing for life and health insurance; education (admissions, assessment, proctoring); and biometrics. The second group is AI embedded in products that are already regulated for safety — machinery, medical devices, vehicles, lifts, toys. The first group applies from 2 December 2027, the second from 2 August 2028.

Why did the deadline move?

The high-risk regime was originally due to apply from 2 August 2026. After sustained industry pressure, and because the supporting technical standards and guidance were not ready, the European Commission proposed a "Digital Omnibus on AI" in November 2025. The Parliament approved it on 16 June 2026, the Council on 29 June 2026, and the amending regulation was published in the Official Journal on 24 July 2026 and came into force on 27 July — six days before the old deadline. The new dates are fixed, and no longer tied to standards being available. Treat the extra time as a preparation window, not a reprieve.

We are a South African vendor. Do we really need someone in Europe?

If you provide a high-risk AI system or a general-purpose AI model into Europe, yes. A third-country provider must appoint an authorised representative established in the EU before making the system available. That representative verifies your documentation and cooperates with authorities, and must resign and notify the regulator if you are non-compliant. Failing to appoint one is itself finable and, practically, blocks market access. It is also the mechanism that makes enforcement against a South African company workable — it gives regulators an address in Europe.

We build AI that a European client sells under their brand. Who carries the burden?

Normally the European client becomes the provider, because they supply the system under their own name or trademark, and you are a supplier to them. That is usually the commercially sensible outcome — but it must be dealt with expressly in the contract, because the Act also flips the role in the other direction. Anyone who puts their name or trademark on a high-risk system, substantially modifies one, or repurposes a general-purpose system into a high-risk use becomes the provider and inherits the full obligation stack. Decide which side carries it, then write down who hands over documentation, who cooperates with regulators, and who controls changes.

Full guide: AI Act clauses in EU customer contracts

What do our European customers have to do?

Deployers carry a lighter but real set of duties: use the system as instructed, assign trained human oversight, make sure the input data they control is relevant and representative, monitor operation, keep the automatic logs for at least six months, tell workers before using such a system in the workplace, and inform the individuals affected. Some deployers must go further — bodies governed by public law, private entities providing public services, and any deployer of credit-scoring or life and health insurance pricing AI must complete a fundamental-rights impact assessment before first use. Those duties are exactly why your European customers are pushing AI Act obligations up the chain to you.

Do we need a notified body to certify our system?

Usually not. For most Annex III high-risk systems the conformity assessment is an internal-control exercise — you assess your own system against the requirements, draw up an EU declaration of conformity, apply the CE mark, and register in the EU database before placing it on the market. Third-party assessment by a notified body is required for certain biometric systems. "Internal" does not mean informal, though: it rests on the quality management system and the technical documentation actually existing and being current.

How much of this work is useful outside Europe anyway?

More than you would expect, which changes the business case. Risk assessments, documented human oversight, logging, bias testing and data-lineage records are exactly what makes a POPIA section 71 position defensible when an automated decision is challenged. They serve King IV technology governance. And they line up with the risk-based expectations the SARB Prudential Authority and the FSCA signalled for AI in financial services. South Africa’s own draft AI policy borrowed the EU’s risk-based architecture before it was withdrawn, and the direction of travel has not changed. Building to this standard is not purely a European cost.

Full guide: AI governance under South African law

What does high-risk readiness work cost?

It depends heavily on how much of the machinery already exists. The starting point is the exposure assessment from R15,000 — inventory, European touchpoints, role classification and a first-pass high-risk classification. A gap assessment against the provider obligations, contract remediation for role allocation, and authorised-representative arrangements are quoted on scope once we know what the classification says. For most South African companies the honest first question is not "how do we comply" but "is this system actually high-risk" — and that answer is often no.

Before working through any of this, confirm the Act reaches you at all — three questions and nine South African scenarios. For the whole picture, see the overview of the EU AI Act for South African businesses.

Sources & authorities

  1. 1.AI Act, Annex III — high-risk use cases
  2. 2.AI Act, Article 6 — classification rules for high-risk AI systems
  3. 3.AI Act, Articles 9–15 — requirements for high-risk AI systems
  4. 4.AI Act, Article 22 — authorised representatives of third-country providers
  5. 5.AI Act, Article 25 — responsibilities along the AI value chain
  6. 6.AI Act, Articles 26–27 — deployer obligations and fundamental-rights impact assessment
  7. 7.European Commission — AI Omnibus enters into force (new high-risk dates)
  8. 8.Regulation (EU) 2026/1744 (Digital Omnibus on AI) — EUR-Lex
  9. 9.Protection of Personal Information Act 4 of 2013 (POPIA)

Every authority above was checked against its primary source in August 2026. This page is general information about South African law, not legal advice.

For the businesses we act for

The Keystone Workspace

The attorney-designed platform the businesses we act for use to run their contracts, e-signatures and company secretarial work in one place.

Why you can trust this: Martin Kotze has been an admitted Attorney of the High Court of South Africa, registered Conveyancer, and Notary Public since 2014, practising from Pretoria. The firm is regulated by the Legal Practice Council under firm registration 17444.

This guide is general information, not legal advice for your specific matter.