Search legal guides

Search MJ Kotze Inc legal guides and articles

EU AI Act

Telling people they are dealing with AI

These are the EU AI Act rules most likely to touch an ordinary South African business — and they have been in force since 2 August 2026. Four duties, in plain English, with the wording to put on your site.

Written by

Martin Kotze

Attorney, Conveyancer & Notary Public

Last reviewed:

Quick answer

Why this is the part that will actually affect you

Most coverage of the EU AI Act focuses on the heavy “high-risk” regime — recruitment algorithms, credit scoring, insurance pricing. That regime is real, but it is a December 2027 problem and it only affects businesses building those specific things.

The transparency rules are different. They took effect on 2 August 2026, on the same day the enforcement machinery switched on. They apply to something very ordinary: a chatbot on your website, an AI voice agent on your phone line, a feature that drafts text or generates images for your users. If you have European customers, this is the part of the Act you are most likely to be breaching right now without knowing it.

The good news is that compliance is mostly cheap. Three of the four duties are satisfied by saying something clearly. Only the machine-readable marking duty needs engineering work.

The four duties

1

If you build it

Tell people they are talking to a machine

Any AI system meant to interact directly with people must be designed so that the person knows they are dealing with AI. The exception is where it is obvious anyway — nobody needs a disclaimer on a system that plainly announces itself.

For a customer-facing chatbot this is usually one line at the start of the conversation and a persistent label on the widget. Do not bury it in the terms of use. The test is whether a reasonable person would know, not whether the information exists somewhere on your site.

2

If you build it

Mark AI-generated content so machines can detect it

If your system generates synthetic audio, images, video or text, the output must be marked in a machine-readable format and detectable as artificially generated or manipulated. This is not a visible watermark for humans — it is metadata or an equivalent signal that other software can read.

This is an engineering task, not a legal one, and it needs to reach your product backlog. Systems already on the market before 2 August 2026 have until 2 December 2026 to comply — that is the deadline most businesses with existing generative features are actually working to. There is a real carve-out worth checking against your product: the duty does not apply where the AI performs an assistive function for standard editing, or does not substantially alter the input or its meaning. A spelling-and-grammar helper is not caught; a feature that drafts the paragraph for you is.

3

If you use it

Label deepfakes

If you use an AI system to generate or manipulate image, audio or video content that is a deepfake, you must disclose that the content has been artificially generated or manipulated.

The disclosure has to be made at first exposure — not in a caption three scrolls down or in a credits page. If your marketing team uses AI-generated presenters, synthetic voice-overs or manipulated footage in campaigns that reach Europe, this is your duty as the user of the tool.

4

If you use it

Disclose emotion recognition, biometrics, and AI-written public-interest text

Three further disclosures sit with the business using the system. Tell people when an emotion-recognition or biometric-categorisation system is operating on them. And label AI-generated text published to inform the public on matters of public interest — unless a human has reviewed it and someone holds editorial responsibility for it.

The editorial-responsibility carve-out is the practical route for most businesses publishing AI-assisted content: have a named human review it and own it. Note that emotion recognition in the workplace is banned outright in most cases, so if that duty is live for you, check the prohibition first.

The duty is yours, not your AI vendor’s

This is the point businesses most often get wrong, and it is worth being blunt about.

You build a customer-support chatbot on top of a model from OpenAI, Anthropic, Google or a hyperscaler platform. It feels natural to assume that the model vendor — the huge, sophisticated, obviously-regulated company — carries the compliance burden. They do carry obligations, but for the model. For the chatbot you built and put in front of your customers under your own brand, you are the provider. The disclosure duty is yours and you cannot outsource it upstream.

The hyperscalers say so themselves, quite openly. Microsoft casts itself as the upstream provider of AI tools, services and components, and its enterprise customers as the downstream regulated actors it has to support. Google Cloud signed the general-purpose AI code of practice as a model provider and tells customers they are the providers or deployers of whatever they build. AWS states that customers remain responsible for assessing how their use of AWS services falls under the Act. The model layer is theirs. The system layer is yours.

What good looks like

Five situations a South African business is likely to be in, and what to actually do about each.

A customer-support chatbot on your website, used by European customers

Disclosure that it is AI

Open the conversation with a clear line — "You are chatting with an AI assistant. Ask for a person at any time." Keep a persistent label on the widget. Make the handover to a human easy and obvious.

An AI voice agent handling inbound calls

Disclosure that it is AI

Say it in the first few seconds, in the language of the call, before collecting any information. A synthetic voice that sounds human makes this more important, not less.

Your product generates draft text, images or summaries for users

Machine-readable marking

Embed the marking in the output pipeline — metadata on generated files, provenance signals on generated media. If the feature existed before 2 August 2026, your deadline is 2 December 2026.

Marketing uses an AI-generated presenter or synthetic voice-over

Deepfake label

Disclose at first exposure — visible on the asset itself, not only in the campaign description. Build it into the creative brief so it is not a compliance fix afterwards.

You publish AI-drafted articles or newsletters on matters of public interest

Label, unless a human owns it

Either label the text as AI-generated, or put a named human reviewer and editorial owner behind it. Most businesses should choose the second — it is better practice regardless of the Act.

The December 2026 catch-up deadline

One date is easy to miss and matters to anyone who shipped an AI feature before August 2026.

Providers of generative systems that were already on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking obligation. If your product has been generating text, images or audio for European users since before August, that December date — not the August one — is your real engineering deadline. It is worth putting on the roadmap now, because output-marking touches the generation pipeline rather than the user interface, and that is rarely a one-sprint change.

Frequently asked

Do we have to tell people our chatbot is a bot?

If the chatbot is used by people in the EU, or its output is used there, then yes. Providers must design systems that interact directly with people so that those people know they are dealing with AI, unless that is obvious from the context. In practice: say it at the start of the conversation, keep a visible label on the widget, and do not rely on it being mentioned in your terms of use. This has applied since 2 August 2026.

Our chatbot runs on OpenAI or Claude. Is disclosure their job?

No, and this is the single most misunderstood point. The marking duty for generated content sits with the provider of the generative system — but if you build a customer-facing chatbot on a hyperscaler’s or model vendor’s technology, you are the provider of that chatbot system for these purposes. You cannot outsource the disclosure duty to the model vendor. They carry obligations for the model; you carry them for the product you built on it.

What does "machine-readable marking" actually mean?

It means the output carries a signal that other software can detect — metadata, provenance credentials, watermarking of the kind that survives ordinary handling. It is not the same as a visible "generated by AI" caption for humans, though you may want both. This is an engineering task rather than a drafting one, so it belongs in the product backlog, not the legal file. The European Commission published final guidelines on 20 July 2026 alongside a code of practice on marking and labelling that signatories can use to show compliance.

When is the deadline?

The transparency duties took effect on 2 August 2026, which is also the date the enforcement machinery switched on. There is one carve-out worth knowing: providers of generative systems that were already on the market before 2 August 2026 have until 2 December 2026 to comply with the marking obligation. If you shipped an AI writing or image feature before August 2026, that December date is your real deadline.

What is the fine for getting this wrong?

Breaches of the transparency duties sit in the operator-obligations tier: up to €15 million or 3% of total worldwide annual turnover, whichever is higher. Smaller businesses get the gentler reading, where the cap is the lower of the two figures. This is the tier most ordinary businesses would land in — the top tier is reserved for the banned practices.

Full guide: AI uses banned outright

We only have South African customers. Does any of this apply?

Not as a matter of law. The transparency duties bite where you supply an AI system into Europe or where your AI output is used there. A purely domestic South African business is outside them. Two caveats though. Your AI vendors’ terms may impose similar requirements contractually. And POPIA has its own transparency and automated-decision provisions — section 71 restricts decisions with legal consequences based solely on automated processing, which is a different rule but points in the same direction.

Full guide: does the EU AI Act apply to my business?

Is telling people it is AI bad for conversion?

It is a fair commercial question and the honest answer is that it depends on execution. A grudging disclaimer reads as a warning. A confident one — "You are chatting with our AI assistant, which can pull up your account instantly. Ask for a person any time." — reads as a feature, and it sets expectations that reduce frustration when the bot reaches its limits. Since the disclosure is compulsory for European users anyway, the useful work is in the wording, not in whether to do it.

Can you review our AI-facing product for this?

Yes. A prohibited-practice and transparency screen runs from R9,500: we work through your customer-facing AI surfaces, identify which of the four duties apply to which system, draft the disclosure wording, and give you a written record of the assessment. Where the product is also being sold into Europe, the broader exposure assessment from R15,000 is usually the better starting point.

The other rules already in force are the banned AI practices. For everything else, see the overview of the EU AI Act for South African businesses.

Sources & authorities

  1. 1.AI Act, Article 50 — transparency obligations
  2. 2.AI Act, Article 99 — penalties
  3. 3.European Commission — guidelines on the transparency of AI-generated content (20 July 2026)
  4. 4.European Commission — AI Omnibus enters into force
  5. 5.European Commission — enforcement framework of the AI Act
  6. 6.Regulation (EU) 2024/1689 (the AI Act) — full text, EUR-Lex
  7. 7.Microsoft — innovating in line with the European Union’s AI Act (15 January 2025)
  8. 8.Google Cloud — commitment to EU AI Act support
  9. 9.AWS — building trust in AI: the AWS approach to the EU AI Act
  10. 10.Protection of Personal Information Act 4 of 2013 (POPIA)

Every authority above was checked against its primary source in August 2026. This page is general information about South African law, not legal advice.

For the businesses we act for

The Keystone Workspace

The attorney-designed platform the businesses we act for use to run their contracts, e-signatures and company secretarial work in one place.

Why you can trust this: Martin Kotze has been an admitted Attorney of the High Court of South Africa, registered Conveyancer, and Notary Public since 2014, practising from Pretoria. The firm is regulated by the Legal Practice Council under firm registration 17444.

This guide is general information, not legal advice for your specific matter.