TECHila LAW

How Does the EU AI Act & its Omnibus Act apply to South African organisations?

While the EU Artificial Intelligence Act is not South African law, it may apply to South African organisations that place Ai systems on the EU market, or whose Ai systems produce outputs that are used in the EU.

By TECHila Law 14 August 2026 Reading time
Open article contents

Introduction

The European Union Artificial Intelligence Act is the world’s first comprehensive cross-sectoral legal framework for artificial intelligence. Despite being an EU regulation, the Act has an extraterritoria scope, as well as its own "Brussels Effect" that can impact Organisations in South Africa.

Although the AI Act is an EU regulation, its practical significance extends beyond Europe. Under Article 2, the Act also applies to organisations established outside the EU, including where an AI system or general-purpose AI model is placed on the EU market or where AI-generated output is used in the EU. South African organisations may therefore face direct legal obligations, contractual requirements or indirect market pressure, even when their systems are developed or operated in South Africa.

The central question for a South African organisation is whether its role, customers, products, data flows or AI outputs create a sufficient connection with the EU market.

The AI Act is not South African legislation. It does not automatically regulate AI activities that take place exclusively within South Africa and have no relevant EU connection.

South African organisations remain subject to South African law. The Protection of Personal Information Act 4 of 2013, or POPIA, remains particularly relevant where AI involves personal information, profiling, automated decision-making or cross-border data transfers.

South Africa’s withdrawn 2026 Draft National Artificial Intelligence Policy does not presently alter this position. The result is a dual compliance environment. A South African organisation may need to comply with POPIA and other domestic laws while also meeting the AI Act’s requirements where its activities fall within the EU’s territorial scope.

2. When the AI Act applies to a South African organisation

Article 2 applies the AI Act to several categories of activity involving organisations outside the EU.

A. Placing an AI system or model on the EU market

A South African provider may be covered if it places an AI system or general-purpose AI model on the EU market or puts it into service in the EU. This applies regardless of whether the provider is established in South Africa or the EU.

For example, a South African company developing a recruitment platform and selling it to EU employers may be subject to the Act if the system is classified as high risk.

B. Use of a South African AI system in the EU

The Act may also apply where an AI system is used in the EU, including where the system was developed or hosted outside Europe.

A South African company that provides an AI service to an EU bank, hospital, university or public authority may therefore fall within the Act depending on its role and the nature of the system.

C. AI output used in the EU

The AI Act has an important extraterritorial feature. It applies to providers and deployers established in a third country where the output produced by their AI system is used in the EU.

This may apply where a South African recruitment provider supplies AI-generated candidate rankings to an employer in the EU, where a South African financial-services company produces risk assessments used by an EU institution, or where a South African technology company provides an AI model whose outputs inform services delivered in the EU.

The decisive questions are where the AI system is located or hosted, where processing occurs, where the output is used, and what role the South African organisation performs in the EU-linked AI value chain.

A South African organisation may also face AI Act requirements indirectly where it supplies an AI component, dataset, model, software service or technical function to an EU provider or multinational group.

The legal classification of the South African entity will depend on its actual role. It may be a provider, deployer, downstream provider, importer, distributor or product manufacturer. The contractual consequences may nevertheless be significant even where the entity is not the primary regulated operator.

3. The risk-based structure of the Act

Article 6 proceeds on a hierarchical classification of AI risk. The table below provides an overview of the risk-based framework used by the Act.

Risk category General legal treatment Examples
Unacceptable risk Prohibited, subject to limited exceptions. Manipulative systems, social scoring and certain biometric practices.
High risk Permitted, but subject to extensive controls. Employment, education, essential services, biometrics and critical infrastructure.
Transparency risk Permitted, but subject to disclosure and labelling duties. Chatbots, deepfakes and certain generative AI systems.
Minimal or no risk Generally no new AI Act duties. Spam filters, many recommendation tools and AI-enabled games.

The vast majority of AI systems are expected to fall within the minimal or no-risk category. The most demanding obligations apply to high-risk systems and general-purpose AI models that may present systemic risk.

The classification exercise should be documented. A provider that determines that an Annex III system is not high risk should document that assessment and be ready to provide it to competent authorities when requested.

4. Prohibited AI practices

Article 5 prohibits AI practices considered incompatible with EU values and fundamental rights.

The main prohibited categories include:

  • AI systems that materially manipulate or deceive individuals in ways likely to cause significant harm;
  • systems that exploit vulnerabilities related to age, disability or socioeconomic circumstances;
  • social-scoring systems that result in unjustified or disproportionate adverse treatment;
  • certain predictive-crime systems based solely on profiling or personality characteristics;
  • untargeted scraping of facial images to create or expand facial-recognition databases;
  • emotion-recognition systems used in workplaces or educational institutions, subject to limited exceptions;
  • biometric categorisation used to infer sensitive characteristics such as race, political opinions, religious beliefs or sexual orientation; and
  • certain uses of real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes.

A South African organisation with EU exposure should screen its intended use case against Article 5 before developing, supplying or deploying the system. A prohibited system cannot be made lawful merely through contractual consent, improved documentation or a risk assessment.

EU AI Omnibus

The EU AI Omnibus introduced targeted simplifications to the AI Act while preserving safeguards for safety and fundamental rights.

The Omnibus introduced a prohibition relating to the generation of child-sexual-abuse material and non-consensual intimate or sexually explicit material involving identifiable persons. It also reduced administrative burdens for smaller organisations and addressed the use of special categories of personal data to detect and correct bias.

Article 4 requires providers and deployers of AI systems to take measures to support the development of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf.

Organisations must take into account technical knowledge, experience, education and training, the context in which the AI systems are used, and the persons or groups of persons on whom the AI systems are used.

5. The Brussels Effect

The AI Act’s influence in South Africa is not limited to direct legal application. It may also produce a “Brussels Effect” through market pressure and regulatory emulation.

Companies that sell to the EU may decide to apply EU AI Act controls across their global operations rather than maintain separate EU and non-EU systems. EU customers may require South African suppliers to provide risk assessments, documentation, audit rights, incident procedures, cybersecurity evidence and human-oversight controls consistent with the AI Act.

These obligations may apply contractually even where the South African supplier is not directly within the AI Act’s territorial scope. The Act’s standards may therefore become de facto global benchmarks.

South African policymakers may consider elements of the EU framework when developing local AI governance. This could support regulatory capacity, international interoperability and rights protection. It should not, however, be confused with automatic incorporation of EU law into South Africa.

6. The AI Act is not a human-rights instrument

Full compliance with the AI Act will not resolve every human-rights concern arising throughout the AI lifecycle. The Act was largely fitted into a product-safety framework, with limitations in its treatment of fundamental rights and human rights.

This is particularly important from a South African perspective, where AI governance must be considered alongside the constitutional rights to dignity, equality, privacy and just administrative action.

7. Incentive structures from a South African perspective

Compliance with the Act involves costs. These include regulatory complexity, specialist staffing, testing expenditure, documentation burdens and possible barriers for smaller firms.

A South African entity may nevertheless be incentivised to align with the AI Act where it is seeking access to EU-linked commercial value. AI Act readiness may assist South African businesses to:

  1. retain multinational customers;
  2. participate in international AI supply chains;
  3. demonstrate product trustworthiness;
  4. attract investors and strategic partners;
  5. reuse compliance documentation in other markets; and
  6. enter or remain in the EU market.

South African subsidiaries may also adopt group-wide AI Act controls because standardisation will likely be cheaper and easier than maintaining separate frameworks.

At the same time, EU-centric policy and governance frameworks may not reflect South Africa’s institutional capacity, development priorities, economic conditions or socio-political context.

8. Enforcement and penalties

Enforcement is divided between the European Commission’s AI Office, national competent authorities in the Member States and the European Data Protection Supervisor for AI systems used by EU institutions.

The maximum penalties include:

  • up to €35 million or 7% of worldwide annual turnover, whichever is higher, for prohibited AI practices;
  • up to €15 million or 3% of worldwide annual turnover, whichever is higher, for other obligations, including certain general-purpose AI breaches; and
  • up to €7.5 million or 1% of worldwide annual turnover, whichever is higher, for supplying incorrect, incomplete or misleading information.

The applicable penalty will depend on factors such as the nature, gravity and duration of the infringement.

9. The current implementation position

The AI Act is in active implementation and enforcement. Its provisions apply according to different dates, depending on the relevant obligation and risk category.

Organisations should track the commencement dates applicable to prohibited practices, AI literacy, governance, general-purpose AI models, transparency obligations and high-risk systems.

The implementation timetable creates a practical need for South African organisations with EU exposure to begin their assessments before a system is placed on the EU market or used to produce outputs for EU users.

Conclusion

The AI Act’s direct application to South African organisations will depend on the organisation’s role, the location of the market or use, and whether its AI output is used in the EU.

Its indirect effects are broader. South African organisations may encounter AI Act requirements through EU customers, multinational group policies, supply chains, investors, technical standards and procurement conditions. This is the Act’s wider “Brussels Effect”.

The soundest South African approach is targeted alignment. For EU-facing organisations, early compliance is a commercial and risk-management strategy. For organisations operating solely in South Africa, the immediate priority is not wholesale adoption of EU law, but a proportionate governance framework that integrates POPIA, sectoral regulations, cybersecurity, transparency and responsible human oversight.

As AI regulation continues to evolve, South African organisations will increasingly need to reconcile domestic obligations with the requirements of international markets.

TECHila Law assists organisations in interpreting evolving technology frameworks, assessing the implications for their operations and designing practical, proportionate responses that support responsible technology, lawful governance and certainty.

References

  1. Regulation (EU) 2024/1689, European Union Artificial Intelligence Act.
  2. Protection of Personal Information Act 4 of 2013.
  3. South African Government, withdrawal of the Draft National Artificial Intelligence Policy.
  4. European Union, Digital Omnibus on Artificial Intelligence.
  5. Marco Almada and Anca Radu, ‘The Brussels Side-Effect: How the AI Act Can Reduce the Global Reach of EU Policy’ (2024) 25 German Law Journal 646. https://doi.org/10.1017/glj.2023.108
Link copied