Search legal guides

Search MJ Kotze Inc legal guides and articles

Technology Law

The EU AI Act and South African businesses

Europe now has a law that tells businesses what they may and may not do with AI — and parts of it reach South African companies that have never set foot in Europe. This is the plain-English version: whether it applies to you, what already bites, and what to do about it.

Written by

Martin Kotze

Attorney, Conveyancer & Notary Public

Last reviewed:

Quick answer

What the EU AI Act actually is

It is a product-safety law for artificial intelligence. That framing explains most of it. The EU already regulates data through GDPR and platforms through other laws. This one treats AI systems the way it treats machinery or medical devices: as things placed on a market, which must meet standards before they get there.

It sorts AI into four levels by how much harm it could do:

  • Banned. A short list of uses Europe has decided are simply not acceptable. Illegal since February 2025.
  • High-risk. AI used for decisions that seriously affect people — who gets hired, who gets credit, what an insurance policy costs, who passes an exam. Heavy obligations, arriving December 2027.
  • Transparency only. AI that talks to people or makes content. You mostly just have to say so. Already in force.
  • Everything else. The vast majority of business AI — spam filters, forecasting, recommendation engines, internal productivity tools. Essentially unregulated.

Alongside that pyramid sits a separate set of rules for the companies that build the big foundation models — GPT, Claude, Gemini, Llama. Almost no South African business is in that group. You use those models; you do not build them.

Two words that decide your obligations

The Act does not care whether you call yourself a vendor, a supplier or a customer. It cares about two roles, and they carry very different loads.

Provider

You build an AI system — or have one built — and supply it under your own name or brand. Providers carry the heavy duties. If you sell an AI product, this is you.

Deployer

You use an AI system in your business. A bank running a scoring tool, an employer running a screening tool. Lighter duties, but real ones.

The trap is that you can change roles without meaning to. If you take someone else’s high-risk AI system, put your brand on it, change it substantially, or use a general-purpose tool for a high-risk purpose, you become the provider — and you inherit the full stack of provider obligations. South African development houses building white-label AI for European clients should decide this deliberately, in the contract, rather than discovering it later.

Does it reach your business? Three questions

Everything about scope comes down to three yes/no questions. If you answer no to all three, the Act does not apply to you.

Do you sell or supply AI into Europe?

You licence an AI-enabled product to a German customer. Your app has AI features and Europeans use it. You put an AI tool on the European market under your own name or brand.

If yes: You are a "provider" and the Act applies to you. You do not need a European office, a European company or a European server. Selling in is enough.

Do you have a company or office inside the EU?

Your group has an Irish subsidiary, a Dutch sales office or a German branch, and it uses AI tools in its own business — recruitment screening, credit scoring, customer chat.

If yes: That European entity is a "deployer" in its own right. It is caught directly, whoever owns it. Being South African-owned changes nothing.

Does the result your AI produces get used in Europe?

Your call centre uses AI to score calls for a French client. Your analytics team sends AI-generated credit assessments to an EU lender. Your AI drafts reports that a Belgian customer relies on.

If yes: This is the door most South African businesses walk through without noticing. The people, the staff and the servers stay in South Africa — the Act still applies to that work.

Answered yes to any of them? Work through the nine common South African scenarios to see what it means in practice.

What is not a trigger

This is worth stating plainly, because it is the most common misunderstanding. The Act contains no trigger based on:

where your computers run · where your data is stored · where the AI model you call is hosted · which cloud region serves your application.

A South African company running everything in AWS Ireland or Azure Frankfurt, serving only South African customers, is not subject to the EU AI Act because of that hosting. The Act’s logic runs on markets, establishments and where AI output lands — not on infrastructure diagrams.

There is a caveat worth taking seriously: “no European connection” is a state to be monitored, not a permanent status. The day a European user signs up, a European customer signs a contract, or AI output starts flowing to a European counterparty, the answer changes. The data-centre question in full.

What already applies — and what is still coming

The Act does not arrive all at once. It has been switching on in stages since 2025, and one big stage was pushed back at the last minute. Here is where things actually stand, as at August 2026.

  1. 2 Feb 2025Live now

    Banned AI uses became illegal

    A short list of AI uses is prohibited outright — including inferring employees’ emotions from their voice or face at work. These carry the largest fines in the Act, and they have been enforceable for over a year.

  2. 2 Aug 2025Live now

    Rules for the big AI model builders started

    Obligations for the companies that build general-purpose models — the GPT, Claude, Gemini and Llama tier. Almost no South African company is in this group. You use these models; you do not build them.

  3. 2 Aug 2026Live now

    Transparency duties, and enforcement switched on

    You must tell people when they are talking to AI, mark AI-generated content, and label deepfakes. National regulators can now act, and the European Commission can fine model builders. This is the date that matters most for ordinary businesses.

  4. 2 Dec 2026Ahead

    Two catch-up deadlines

    A new ban on AI that generates non-consensual intimate images or child sexual abuse material takes effect. Generative AI systems that were already on the market before August 2026 must be marking their output by this date.

  5. 2 Aug 2027Ahead

    Older AI models must catch up

    General-purpose models that were already on the market before August 2025 must comply by now. Every EU country must also have at least one AI regulatory sandbox running.

  6. 2 Dec 2027Ahead

    The heavy regime: "high-risk" AI

    The full compliance stack lands for AI used in recruitment, credit scoring, insurance pricing, education and biometrics. This was originally August 2026 — it was pushed out by roughly sixteen months in July 2026. If you sell this kind of AI into Europe, this is your deadline.

  7. 2 Aug 2028Ahead

    High-risk AI built into physical products

    The same heavy regime for AI embedded in regulated products — machinery, medical devices, vehicles, lifts, toys.

The stage everyone expected on 2 August 2026 — the high-risk regime — did not arrive. An amending regulation known as the “Digital Omnibus on AI” came into force on 27 July 2026, six days before the old deadline, and moved those obligations out to December 2027 and August 2028. Those are now fixed dates, no longer tied to technical standards being ready.

What it costs to get wrong

The fines are structured like GDPR’s — a fixed ceiling or a percentage of global turnover, whichever is higher. Smaller businesses get the gentler reading: for them the cap is whichever is lower.

What went wrongMaximum fineIn practice
Using a banned AI practice€35 million or 7% of worldwide turnoverWhichever is higher. The top tier, and the one already live.
Breaking the other operator duties — including the transparency rules€15 million or 3% of worldwide turnoverThis is the tier most ordinary businesses would land in.
Giving a regulator wrong or misleading information€7.5 million or 1% of worldwide turnoverA reminder that how you answer a regulator is itself regulated.

How a fine would actually reach you

A reasonable question is how any of this bites a company with no assets in Europe. Four mechanisms do the work, and none of them requires a European court to have personal jurisdiction over you.

  1. 1If you supply high-risk AI or general-purpose models into Europe, you must appoint an authorised representative established there. That gives regulators a local address — and failing to appoint one is itself finable, and in practice blocks market access.
  2. 2European market-surveillance authorities act on the product, not the person. They can order corrective action, restrict or prohibit your system being made available, or force a withdrawal or recall.
  3. 3Your European customers carry their own liability. Importers and distributors must verify compliance before selling, and European users face their own fines — so a non-compliant supplier becomes commercially radioactive long before any fine is collected.
  4. 4Reputational and contractual consequences flow through vendor due diligence — which is the channel most South African businesses will actually feel.

Some perspective on where enforcement actually stands. The Commission’s AI Office only became entitled to exercise its investigation and enforcement powers over prohibited practices and general-purpose model providers on 2 August 2026 — days before this guide was written — and as at early August 2026 no fines had been publicly reported against any company, European or foreign. Many national regulators are still being stood up. None of that is a defence: it describes a machine that has just been switched on, not one that has been tried and found lenient. The first actions are widely expected to target visible breaches of the bans and the transparency duties, and the prohibitions themselves have been legally binding since February 2025 regardless of who was available to enforce them.

Even if you are out of scope, it still reaches you

For most South African businesses the AI Act will not arrive as a letter from a regulator. It will arrive as a clause in a contract.

Because European customers carry their own obligations and their own fines, they are pushing compliance up the supply chain to their suppliers — wherever those suppliers sit. The European Commission has published model contractual clauses for AI procurement, designed to be bolted onto supply contracts, and South African advisers are already telling local suppliers to expect them. Procurement questionnaires increasingly ask how you classify your AI under the Act and whether you hold ISO/IEC 42001 certification.

The same thing happens through your own vendors, in the other direction. The major AI and cloud providers have written AI Act norms into their global terms — you may not use their services for a banned practice, wherever you are. A South African company using those services for purely domestic business is not regulated by the Act, but it is contractually bound to AI-Act-shaped conduct, and breaking that is a breach of contract with its most important infrastructure supplier.

Read the detail on what is appearing in European customer contracts, and how the hyperscalers allocate responsibility between themselves and you.

What South African law says about AI right now

South Africa has no AI statute. A draft National AI Policy was published for public comment on 10 April 2026 and withdrawn later that month after fabricated citations were discovered in it. So AI here is governed through the law we already have — POPIA above all.

Two POPIA sections sit close to the themes of this guide. Section 71 restricts decisions that have legal consequences for a person and are based solely on automated processing meant to profile them — a narrower cousin of the AI Act’s insistence on human oversight. Section 72 governs sending personal information out of South Africa, which is where your cloud and model choices land.

The useful point for a South African board is that this all pulls in one direction. The governance artefacts the AI Act demands — risk assessments, human oversight, logging, transparency — are the same ones that make a POPIA section 71 position defensible, satisfy King IV technology governance, and meet the risk-based expectations the SARB Prudential Authority and the FSCA signalled for AI in financial services. Building to AI Act standards is not just a European exercise. More on AI governance under South African law.

What to do now

The right amount of effort varies enormously. A domestic retailer using European cloud regions needs only the first row. An HR-tech company selling into Germany needs all of them.

Right nowEvery business with any European connection — including ones confident they are out of scope

List every AI tool your business uses or sells. Next to each one, write down where its results end up. Then write down, in a paragraph, why you are in or out of scope and which facts that conclusion depends on. Screen the whole list against the banned uses and stop anything on that list that touches Europe.

Right nowBusinesses with EU users, EU clients receiving AI output, or generative AI features

Turn on the transparency basics: tell people when they are talking to a bot, mark AI-generated content, label deepfakes. Read your cloud and AI vendor terms — they now carry AI Act rules as contract terms. Prepare standard answers to the AI questionnaires European customers are sending.

By mid-2027Anyone selling AI into Europe, groups with EU subsidiaries, BPO providers with EU clients

For each system in scope, decide whether you are the provider or the deployer, and check it against the high-risk list. If it is likely high-risk, run a gap assessment, start building the quality management system and line up someone in Europe to act as your authorised representative. Fix role allocation in your white-label and development contracts.

By 2 December 2027Providers and deployers of high-risk AI

Full compliance: conformity assessment, CE marking, registration in the EU database, logging and human-oversight procedures, and — for public bodies, private providers of public services, and any deployer of credit-scoring or life and health insurance pricing AI — a fundamental-rights impact assessment before first use.

OngoingBoards, legal and compliance

Watch for European Commission guidance as it lands, the technical standards still being written, and South Africa’s own AI policy when it is re-issued. Re-check your scope every time your customer base, product or group structure changes.

The rest of this guide

Six companion guides go deeper on the questions this page raises.

Frequently asked

Does the EU AI Act apply to South African companies?

It can, even if you have no office, company or server in Europe. There are three ways in. First, if you place an AI system on the European market — for example licensing AI-enabled software to a German customer. Second, if a company in your group is established in the EU and uses AI. Third, and most commonly missed, if you sit in South Africa but the output your AI produces is used in Europe — a credit score sent to an EU lender, a shortlist sent to an EU employer, AI-assisted call scoring delivered to a French client. If none of those apply to you, the Act does not.

Full guide: does the EU AI Act apply to my business?

We host in AWS Ireland or Azure Frankfurt. Are we caught?

Not for that reason alone. The Act contains no trigger based on where computing happens, where data is stored, where a model is hosted or which cloud region serves your application. Its tests run on markets, establishments and where AI output is used. A South African company with only South African customers, hosting in Frankfurt, is not subject to the Act because of the hosting. That conclusion holds only as long as the facts do — the day a European customer signs, the analysis changes.

Full guide: EU data centres and the AI Act

What already applies, and what is still coming?

Three stages are live. The banned AI uses have applied since 2 February 2025. Rules for builders of general-purpose AI models have applied since 2 August 2025. On 2 August 2026 the transparency duties took effect and the enforcement machinery switched on — national regulators can now act. Still ahead: a new prohibition and a marking catch-up deadline on 2 December 2026, and the heavy "high-risk" regime on 2 December 2027 (or 2 August 2028 for AI built into regulated products). That high-risk date was pushed back from August 2026 by an amending regulation that came into force on 27 July 2026.

What are the penalties?

Three tiers, each capped at the higher of a fixed euro amount or a percentage of worldwide turnover. Using a banned AI practice: up to €35 million or 7% of worldwide annual turnover. Breaking the other operator duties, including the transparency rules: up to €15 million or 3%. Giving a regulator incorrect or misleading information: up to €7.5 million or 1%. Smaller companies get the gentler reading — the lower of the two figures rather than the higher.

How would Europe actually enforce this against a South African company?

Four ways, none of which need a European court to have jurisdiction over you personally. If you supply high-risk AI or general-purpose models you must appoint an authorised representative established in Europe, which gives regulators a local address — and failing to appoint one is itself finable. European market-surveillance authorities act on the product, not the person: they can order corrective action, restrict your system, or force it to be withdrawn. Your European customers carry their own liability, so a non-compliant supplier becomes commercially untouchable long before any fine is collected. And the whole thing flows down through contracts and vendor due diligence.

Does South Africa have its own AI law?

No. There is no AI-specific statute. A draft National AI Policy was published for comment on 10 April 2026 and then withdrawn later that month after fabricated citations were found in it. AI in South Africa is currently governed through existing law — POPIA above all, where section 71 restricts decisions made solely by automated processing and section 72 governs sending personal information out of the country. The SARB Prudential Authority and the FSCA have signalled risk-based supervisory expectations for AI in financial services.

Full guide: AI governance and regulation in South Africa

We are out of scope. Can we ignore all of this?

No, for two practical reasons. Your AI and cloud vendors have written AI Act rules into their standard terms, so using their services binds you contractually to AI-Act-shaped conduct even where the law does not. And European customers are pushing AI Act obligations down into supply contracts regardless of where you sit — role allocation, documentation, incident notification, audit rights and warranties. For most South African businesses the Act will arrive as a clause, not a letter.

Full guide: AI Act clauses in EU customer contracts

What does an EU AI Act exposure assessment cost?

From R15,000 for the exposure assessment: an inventory of your AI systems, a map of every European touchpoint, a written scope conclusion recording the facts it rests on, and a screen against the banned practices and the transparency duties. Reviewing an AI clause set in a European customer contract runs from R7,500. High-risk readiness work — gap assessment against the provider stack, role allocation in contracts, authorised-representative arrangements — is quoted on scope.

Sources & authorities

  1. 1.Regulation (EU) 2024/1689 (the AI Act) — full text, EUR-Lex
  2. 2.Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force 27 July 2026 — EUR-Lex
  3. 3.AI Act, Article 2 — scope
  4. 4.AI Act, Recital 22 — output used in the Union
  5. 5.AI Act, Article 5 — prohibited AI practices
  6. 6.AI Act, Article 50 — transparency obligations
  7. 7.AI Act, Article 99 — penalties
  8. 8.European Commission — AI Omnibus enters into force
  9. 9.European Commission — enforcement framework of the AI Act
  10. 10.Protection of Personal Information Act 4 of 2013 (POPIA)
  11. 11.SARB Prudential Authority & FSCA — AI in the South African financial sector (24 November 2025)

Every authority above was checked against its primary source in August 2026. This page is general information about South African law, not legal advice.

For the businesses we act for

The Keystone Workspace

The attorney-designed platform the businesses we act for use to run their contracts, e-signatures and company secretarial work in one place.

Why you can trust this: Martin Kotze has been an admitted Attorney of the High Court of South Africa, registered Conveyancer, and Notary Public since 2014, practising from Pretoria. The firm is regulated by the Legal Practice Council under firm registration 17444.

This guide is general information, not legal advice for your specific matter.