Search legal guides

Search MJ Kotze Inc legal guides and articles

EU AI Act

High-risk AI and the December 2027 deadline

If your AI helps decide who gets hired, who gets credit, what an insurance policy costs or who passes an exam — and any of that happens in Europe — this is the part of the Act that will cost you real money to comply with. You have roughly sixteen months.

Written by

Martin Kotze

Attorney, Conveyancer & Notary Public

Last reviewed:

Quick answer

First, the good news about the date

The stage everyone expected on 2 August 2026 did not arrive. The high-risk regime was pushed back by roughly sixteen months, six days before it was due to land.

The reason was practical rather than political. The technical standards that were supposed to tell companies how to meet the requirements had not been published, and the European Commission had missed its own deadline for guidance on classifying high-risk systems. Regulating without telling anyone how to comply was untenable, so the deadlines moved: 2 December 2027 for the stand-alone high-risk uses, 2 August 2028 for AI built into regulated products. Those dates are now fixed and no longer conditional on standards being ready.

For a South African company selling AI into Europe this is a genuine reprieve — and the right way to use it is as a preparation window. The work involved is organisational, not just documentary, and organisations move slowly.

What counts as high-risk

The Act lists the specific uses that qualify. Below are the four clusters that matter most to South African exporters — but they are examples, not the full list. The complete list also covers critical infrastructure, public assistance and healthcare benefits, emergency response, law enforcement, migration and border control, and the administration of justice and democratic processes.

Being on the list is also not always the end of the analysis, which is the part most summaries leave out. Under Article 6(3), a listed system is not high-risk if it poses no significant risk to health, safety or fundamental rights and does not materially influence the outcome of decision-making — provided it meets one of four narrow conditions: it performs a narrow procedural task; improves the result of a previously completed human activity; detects decision patterns or deviations without replacing or influencing the earlier human assessment without proper review; or performs a preparatory task. Profiling of natural persons is always high-risk, whatever else is true. If you rely on this exclusion you must document the assessment before placing the system on the market, and register it under Article 6(4).

Employment

Recruitment and selection tools, CV screening, candidate evaluation, promotion and termination decisions, task allocation and monitoring of workers.

South African angle: The biggest South African exposure. HR-tech vendors with European employer clients, and any BPO or shared-services operation whose AI touches hiring for European entities.

Essential services and credit

Creditworthiness assessment and credit scoring, and risk assessment and pricing for life and health insurance.

South African angle: South African fintechs selling scoring models to European lenders, and insurtechs supplying pricing engines to European insurers, are building squarely in this territory.

Education

Admissions decisions, assessment and marking, and exam proctoring.

South African angle: Edtech products sold into European institutions. Proctoring in particular attracts attention because it usually involves biometrics as well.

Biometrics

Remote biometric identification, biometric categorisation, and emotion recognition where it is not already prohibited outright.

South African angle: Note the overlap with the banned list — emotion recognition in workplaces and education is prohibited entirely, not merely high-risk.

If your system already exists, check this before anything else

Article 111(2) limits how far the high-risk regime reaches backwards. For high-risk systems placed on the market or put into service before 2 August 2026, the Regulation applies only if, from that date, they are subject to significant changes in their designs. Ordinary updates and maintenance are not that. The exception is systems intended to be used by public authorities: those must comply by 2 August 2030 regardless. This qualification sits behind every deadline on this page, and for an established product it can be the difference between a large programme and a watching brief.

A South African fintech selling scoring models to European lenders, an HR-tech vendor with European employer clients, or an insurtech supplying pricing engines to European insurers is building in exactly this territory. So is a BPO whose AI-assisted output feeds any of those decisions for a European client. Check whether the Act reaches you at all before working through this page.

If you build it: the provider stack

This is the substantial part of the Act, and it is worth seeing in one place so the scale is honest. Nine obligations, each of which is real work.

ObligationWhereWhat it means
Risk managementArticle 9A documented risk-management process running across the whole life of the system, identifying and reducing risks to health, safety and fundamental rights. Not a once-off assessment.
Data governanceArticle 10Training, validation and test data that is relevant, sufficiently representative, and examined for bias. You have to be able to show what went into the model.
Technical documentation and loggingArticles 11–12A prescribed documentation set kept current, and automatic event logging built into the system.
Instructions for deployersArticle 13Documentation that lets the businesses using your system understand it, supervise it and operate it correctly.
Human oversightArticle 14Designed so trained people can actually supervise, intervene and override. Oversight that exists on paper but cannot be exercised does not count.
Accuracy, robustness, cybersecurityArticle 15Appropriate levels, declared up front and maintained across the system’s life.
Quality management systemArticle 17An organisation-level QMS covering design, development, testing and post-market monitoring. This is the biggest lift for most companies.
Conformity assessment, CE marking, registrationArticles 43, 47–49Mostly a self-assessment against the requirements, then an EU declaration of conformity, a CE mark, and registration in the EU database before you may place the system on the market. Certain biometric systems need a third-party notified body.
EU authorised representativeArticle 22A third-country provider must appoint a representative established in the EU before making the system available. This is the practical anchor for enforcement against you.

The quality management system is the item most companies underestimate. It is not a document you write in a week — it is an organisation-level process covering design, development, testing and post-market monitoring, and it has to be genuinely operating before a conformity assessment means anything. If you expect to be in scope, that is the piece to start on first.

You will need someone in Europe

One requirement deserves separating out, because it is structural rather than procedural and it surprises South African founders.

A provider established outside the EU must appoint an authorised representative established inside it before making a high-risk system available. That representative verifies your documentation, keeps it available for authorities, and cooperates with them. Critically, the representative must resign and notify the regulator if it considers you are not complying — so this is not a mailbox arrangement.

Failing to appoint one is itself finable, and in practice it blocks market access. It is also the answer to the question South African boards keep asking about how Europe could ever enforce against them: the representative requirement gives regulators an address, and market-surveillance authorities can act on the product itself — ordering corrective action, restricting availability, or forcing withdrawal — without ever needing jurisdiction over your company.

If you only use it: deployer duties

Businesses that use a high-risk system rather than build it carry a lighter set of duties. These land on European subsidiaries of South African groups, and on the European customers of South African vendors — which is precisely why those customers push obligations back up the chain to you.

  • Use the system according to the provider’s instructions.
  • Assign human oversight to people who are trained and competent to exercise it.
  • Make sure the input data you control is relevant and sufficiently representative.
  • Monitor how the system operates in practice.
  • Keep the automatically generated logs for at least six months.
  • Inform workers before you use such a system in the workplace.
  • Inform the individuals affected by decisions the system contributes to.

Some deployers go further. Bodies governed by public law, private entities providing public services, and any deployer of credit-scoring or life and health insurance pricing AI must complete a fundamental-rights impact assessment before first use. Note that the last category turns on what the system does, not on what kind of business you are — so it reaches a lender or insurer only because of the AI they deploy. If your South African group has a European insurer or lender in it, that duty is coming for them directly.

The white-label trap

The Act polices the value chain, and this is where South African development houses need to be deliberate.

A distributor, importer, deployer or any other third party that puts its name or trademark on a high-risk system, substantially modifies one, or repurposes a general-purpose system into a high-risk use becomes the provider — and inherits the entire stack above.

The distinction matters commercially. You cannot contract out of being the provider if your conduct makes you one — but you can, and should, agree who performs the compliance work and who pays for it. Article 25(4) assumes exactly that: it requires the provider and a third party supplying tools, services or components to set out, by written agreement, the necessary information, capabilities, technical access and assistance.

In the ordinary white-label arrangement the European client becomes the provider, because they supply the system under their own name, and you are a supplier to them. Record that in the contract along with who hands over technical documentation and instructions for use, who notifies incidents, who controls substantial modifications, and who provides log access so the deployer can meet its own retention duty — understanding that those terms govern the relationship between you and your customer, not your status under the Act.

Sixteen months, in order

The sequencing matters, because the expensive items depend on the cheap ones being done first. There is no point building a quality management system before you know whether your product is even high-risk.

  1. Now – mid 2027Live now

    Classify and assess

    For each system in scope, fix your role — provider, deployer or neither — and classify it against the high-risk list. The European Commission published draft classification guidelines in May 2026, three months after its own deadline; use them, but treat them as draft until the final version lands. If your system is likely high-risk, run a gap assessment against the Article 9 to 15 requirements. Negotiate role allocation into your white-label and development contracts now, while there is still leverage.

  2. Mid 2027Ahead

    Build the machinery

    Stand up the quality management system, plan the conformity-assessment route, and line up an EU authorised representative. The QMS is the long pole — it is an organisational change, not a document.

  3. 2 Dec 2027Ahead

    Annex III high-risk obligations apply

    Full compliance for stand-alone high-risk systems — recruitment, credit, insurance, education, biometrics. Conformity assessment, CE marking, EU database registration, deployer procedures, and fundamental-rights impact assessments where the deployer category requires them.

  4. 2 Aug 2028Ahead

    AI embedded in regulated products

    AI built into products that are already regulated for safety. The route differs by product type: machinery, toys, lifts and medical devices sit in Annex I Section A; motor vehicles, aviation and rail sit in Section B, where the requirements are carried through the existing sectoral regimes rather than applied as the Act’s own stack. Check which list your product falls under before assuming the obligations.

Frequently asked

What counts as "high-risk" AI?

Two groups. The first is a list of stand-alone use cases where AI makes or contributes to decisions that seriously affect people. Four clusters matter to South African exporters: employment (recruitment, CV screening, candidate evaluation, promotion and termination, task allocation and worker monitoring); essential services including creditworthiness assessment and risk assessment and pricing for life and health insurance; education (admissions, assessment, proctoring); and biometrics. The second group is AI embedded in products that are already regulated for safety. The first group applies from 2 December 2027, the second from 2 August 2028. Two qualifications matter on the second group. The route differs by product type — machinery, toys, lifts and medical devices are in Annex I Section A, while motor vehicles, aviation and rail are in Section B, where the requirements come through the existing sectoral regimes rather than as the Act’s own compliance stack. And on the first group, Article 6(3) can take a listed system out of the high-risk category altogether where it does not materially influence decisions and meets one of four narrow-task conditions, though profiling is always high-risk.

Why did the deadline move?

The high-risk regime was originally due to apply from 2 August 2026. After sustained industry pressure, and because the supporting technical standards and guidance were not ready, the European Commission proposed a "Digital Omnibus on AI" in November 2025. The Parliament approved it on 16 June 2026, the Council on 29 June 2026, and the amending regulation was published in the Official Journal on 24 July 2026 and came into force on 27 July — six days before the old deadline. The new dates are fixed, and no longer tied to standards being available. Treat the extra time as a preparation window, not a reprieve.

We are a South African vendor. Do we really need someone in Europe?

If you provide a high-risk AI system or a general-purpose AI model into Europe, yes. A third-country provider must appoint an authorised representative established in the EU before making the system available. That representative verifies your documentation and cooperates with authorities, and must resign and notify the regulator if you are non-compliant. Failing to appoint one is itself finable and, practically, blocks market access. It is also the mechanism that makes enforcement against a South African company workable — it gives regulators an address in Europe.

We build AI that a European client sells under their brand. Who carries the burden?

Normally the European client becomes the provider, because they supply the system under their own name or trademark, and you are a supplier to them. Be precise about why: that follows from the facts, not from what the contract calls each party. Anyone who puts their name or trademark on a high-risk system, substantially modifies one, or repurposes a system into a high-risk use becomes the provider by operation of law and inherits the full obligation stack — and no clause can hand that status to the other side. What the contract should do is record who hands over documentation, who cooperates with regulators, who controls changes, who bears the cost and who indemnifies whom. That is real and worth negotiating; it just is not a way of choosing your regulatory role.

Full guide: AI Act clauses in EU customer contracts

What do our European customers have to do?

Deployers carry a lighter but real set of duties: use the system as instructed, assign trained human oversight, make sure the input data they control is relevant and representative, monitor operation, keep the automatic logs for at least six months, tell workers before using such a system in the workplace, and inform the individuals affected. Some deployers must go further — bodies governed by public law, private entities providing public services, and any deployer of credit-scoring or life and health insurance pricing AI must complete a fundamental-rights impact assessment before first use. Those duties are exactly why your European customers are pushing AI Act obligations up the chain to you.

Do we need a notified body to certify our system?

Usually not. For most Annex III high-risk systems the conformity assessment is an internal-control exercise — you assess your own system against the requirements, draw up an EU declaration of conformity, apply the CE mark, and register in the EU database before placing it on the market. Third-party assessment by a notified body is required for certain biometric systems. "Internal" does not mean informal, though: it rests on the quality management system and the technical documentation actually existing and being current.

How much of this work is useful outside Europe anyway?

More than you would expect, which changes the business case. Risk assessments, documented human oversight, logging, bias testing and data-lineage records are exactly what makes a POPIA section 71 position defensible when an automated decision is challenged. They serve King IV technology governance. And they line up with the risk-based expectations the SARB Prudential Authority and the FSCA signalled for AI in financial services. South Africa’s own draft AI policy borrowed the EU’s risk-based architecture before it was withdrawn, and the direction of travel has not changed. Building to this standard is not purely a European cost.

Full guide: AI governance under South African law

What does high-risk readiness work cost?

It depends heavily on how much of the machinery already exists. The starting point is the exposure assessment from R15,000 — inventory, European touchpoints, role classification and a first-pass high-risk classification. A gap assessment against the provider obligations, contract remediation for role allocation, and authorised-representative arrangements are quoted on scope once we know what the classification says. For most South African companies the honest first question is not "how do we comply" but "is this system actually high-risk" — and that answer is often no.

Before working through any of this, confirm the Act reaches you at all — three questions and nine South African scenarios. For the whole picture, see the overview of the EU AI Act for South African businesses.

Sources & authorities

  1. 1.AI Act, Annex III — high-risk use cases
  2. 2.AI Act, Article 6 — classification rules, including the Article 6(3) exclusion
  3. 3.AI Act, Article 111 — transitional provisions for existing systems
  4. 4.AI Act, Annex I — Section A and Section B product legislation
  5. 5.AI Act, Articles 9–15 — requirements for high-risk AI systems
  6. 6.AI Act, Article 22 — authorised representatives of third-country providers
  7. 7.AI Act, Article 25 — responsibilities along the AI value chain
  8. 8.AI Act, Articles 26–27 — deployer obligations and fundamental-rights impact assessment
  9. 9.European Commission — AI Omnibus enters into force (new high-risk dates)
  10. 10.Regulation (EU) 2026/1744 (Digital Omnibus on AI) — EUR-Lex
  11. 11.Protection of Personal Information Act 4 of 2013 (POPIA)

Every authority above was checked against its primary source in August 2026. This page is general information about South African law, not legal advice.

For the businesses we act for

The Keystone Workspace

The attorney-designed platform the businesses we act for use to run their contracts, e-signatures and company secretarial work in one place.

Why you can trust this: Martin Kotze has been an admitted Attorney of the High Court of South Africa, registered Conveyancer, and Notary Public since 2014, practising from Pretoria. The firm is regulated by the Legal Practice Council under firm registration 17444.

This guide is general information, not legal advice for your specific matter.