Does the EU AI Act apply to companies in South Africa?
It can. The EU AI Act applies to providers and deployers anywhere in the world when an AI system's output is used in the EU, and to anyone placing AI on the EU market. A South African firm serving EU customers, running AI for an EU subsidiary or selling AI products into Europe is likely in scope. High-risk obligations now apply from 2 December 2027.
Who is in scope outside Europe
The Act reaches beyond the EU in the same way the GDPR does. It applies to providers who place AI systems on the EU market, and to providers and deployers located outside the EU where the output of the AI system is used in the EU. Importers, distributors and authorised representatives are covered too.
- A South African lender or insurer that scores EU residents.
- A software company that sells an AI product to European customers.
- A group whose South African shared-services centre runs AI for an EU subsidiary.
- A recruiter screening candidates for roles in the EU.
The dates, after the Digital Omnibus
- 2 February 2025: prohibited practices banned, and general provisions in force.
- 2 August 2025: rules for general-purpose AI models, governance and penalties.
- 2 December 2026: new bans on AI-generated non-consensual intimate imagery and child sexual abuse material, and the end of the shortened grace period for marking AI-generated content.
- 2 December 2027: obligations for stand-alone high-risk systems, such as credit scoring, recruitment and education (Annex III).
- 2 August 2028: obligations for high-risk AI embedded in regulated products such as medical devices (Annex I).
The Digital Omnibus, Regulation (EU) 2026/1744, moved the high-risk dates and entered into force on 27 July 2026. The underlying requirements did not change.
What to do first
- Map where your AI's output landsWhich systems produce decisions or content used by people in the EU.
- Classify each systemProhibited, high-risk, limited-risk (transparency duties) or minimal risk.
- Start the high-risk evidence earlyRisk management, data governance, logging, human oversight and documentation take longer to build than to describe.
- Reuse what POPIA already makes you doHuman oversight, explanation and a route to contest decisions overlap heavily with POPIA section 71.
Questions people also ask
When do EU AI Act high-risk rules apply?
From 2 December 2027 for stand-alone high-risk systems such as credit scoring and recruitment, and 2 August 2028 for AI in regulated products, following the Digital Omnibus.
Does a South African company need an EU representative?
Providers outside the EU placing high-risk systems on the EU market generally must appoint an authorised representative in the EU. Check your role and system under the Act.
Sources
- Regulation (EU) 2024/1689, the Artificial Intelligence Act
- Grant Thornton: the EU AI Act after the high-risk deadline moved
This guide explains the law and standards in general terms. It is not legal advice about your organisation. AI Integrity Certification is a certification body and does not consult on the systems it certifies.
Check your own organisation
AIC Aware is a free self-assessment against the AIC standard. It takes about ten minutes and shows where accountability for automated decisions is missing.