NexBDM Blog
AI Regulation in South Africa: what actually governs your business while the policy is being rewritten
By NexBDM Team · 2026-08-20
Key takeaways
- South Africa has no AI Act, and the draft national policy was withdrawn because its own reference list cited sources that do not exist. That is not a free pass. POPIA, the ECT Act and the Cybercrimes Act already govern most of what you do with AI.
South Africa has no AI Act, and the draft national policy was withdrawn because its own reference list cited sources that do not exist. That is not a free pass. POPIA, the ECT Act and the Cybercrimes Act already govern most of what you do with AI.
There is no AI Act in South Africa. AI regulation in South Africa currently runs through laws that already existed before the technology arrived, chiefly POPIA, the Electronic Communications and Transactions Act and the Cybercrimes Act. The dedicated national policy meant to sit above them was withdrawn in 2026 and is being rewritten.
The national AI policy was withdrawn, and the reason matters more than the delay
On 10 April 2026 the Department of Communications and Digital Technologies published the Draft South Africa National Artificial Intelligence Policy for public comment, as Government Notice 3880 in Government Gazette 54477.
Sixteen days later the Minister of Communications and Digital Technologies, Solly Malatsi, announced that it was being withdrawn. The reference list contained sources that do not exist. According to DLA Piper's analysis of the withdrawal, at least 10% of the references to academic sources in the document's reference list were fictitious.
The Minister's own explanation, reported by SAnews on 26 April 2026, was direct:
The most plausible explanation is that AI-generated citations were included without proper verification.
And then the sentence that every business owner using AI should read twice:
This should not have happened. In fact, this unacceptable lapse proves why vigilant human oversight over the use of artificial intelligence is critical.
The withdrawal became formal in a Government Gazette dated 12 June 2026, which stated that the draft policy is withdrawn in its entirety effective from the date of publication. The department has said it is targeting the 2026/2027 financial year to finalise a replacement, with a Cabinet submission planned for November 2026 and a fresh publication for public comment targeted for January 2027.
What this means for you: the vacuum is not a free pass
It is tempting to read "the policy was withdrawn" as "nothing applies yet". That is the wrong conclusion, and it is an expensive one.
A national AI policy is a framework document. It sets direction, coordinates departments and signals where future legislation goes. It is not the source of your current obligations. Those already exist, they are already in force, and they already cover most of what a small business actually does with AI.
POPIA already regulates automated decisions
Section 71 of the Protection of Personal Information Act is the provision most South African businesses do not know they are already subject to. It prohibits a person being subjected to a decision that has legal consequences for them, or affects them substantially, where that decision is based solely on the automated processing of their personal information intended to build a profile of them. The Act specifically names profiling of work performance, creditworthiness, reliability, location, health, preferences and conduct.
There are exceptions, and they are the practical part. The decision is permitted where it is connected to the conclusion or execution of a contract and either the person's request has been met, or appropriate measures protect their legitimate interests. Where you rely on that second route, section 71(3) requires you to give the person an opportunity to make representations about the decision, and to supply sufficient information about the underlying logic of the processing for those representations to be meaningful.
Read that last requirement against a typical AI screening tool. If you cannot explain why it produced the answer it produced, you cannot satisfy section 71(3). That is a live obligation today, not a future one, and it sits in the same Act as the rest of your POPIA compliance obligations.
The rest of the existing stack
The withdrawn policy was intended to give effect to laws that are already on the books. In the absence of dedicated AI legislation, the instruments doing the regulating are the ordinary ones:
- POPIA, for anything that touches personal information, including training data, prompts containing customer detail, and automated decisions.
- The Electronic Communications and Transactions Act, which has governed automated transactions and data messages since 2002 and already sits behind the rules on electronic signatures.
- The Cybercrimes Act, for unlawful access and interception.
- PAIA, for access to records, including records an automated system produced.
- Intellectual property legislation, for what you generate and what you feed in.
- Ordinary labour, consumer and contract law, which does not stop applying because a machine did the work. An unfair outcome is unfair regardless of what produced it.
None of this is exotic. It is the compliance base every business already has, applied to a new tool. If you have worked through the general compliance checklist, you are further along on AI regulation in South Africa than you think.
The lesson the government just paid for in public
Strip away the politics and the withdrawn policy is a very ordinary failure, of the kind happening quietly inside businesses every week.
Someone used an AI tool to produce a document. The output was fluent, correctly formatted and confident. Nobody checked whether the things it cited were real. It went out under an official name, and the error was found by an outside party rather than by anyone in the process that produced it.
Note what did not fail. The tool did what these tools do. The drafting did not collapse into nonsense. The failure was structural: there was no step in the workflow whose job was to verify the claims before publication, so a plausible document went out unverified.
This is the same pattern behind most disappointing AI projects, which we have written about in why AI projects fail. The technology performs. The process around it was never designed.
What actually changes in the work
Compliance advice that stops at "be careful" is not worth reading. Here is what a small business can put in place this month, without a lawyer and without waiting for the policy.
- Name the outputs that need verification before they leave the building. Not everything does. A draft internal email does not. Anything with a figure, a citation, a legal claim, a date or a customer name in it does. Write that list down once and it becomes a rule instead of a judgement call made under time pressure.
- Make the verification step a field, not a habit. Every claim that survives to a client document carries its source next to it. If a source cannot be produced, the claim is removed rather than softened. This is the single control that would have caught the policy failure.
- Log which decisions are automated. Section 71 only bites where a decision is made solely by automated processing and affects someone substantially. You cannot answer that question about your own business unless someone has written down which decisions your tools actually make on their own.
- Keep the explanation with the decision. If a tool scores, ranks or screens people, capture what it used and why, at the time. Reconstructing that months later, in response to a complaint, is how a manageable obligation becomes a crisis.
- Put your AI rules in one document that staff have actually read. An internal policy is not a legal shield, but it is the difference between an isolated mistake and a pattern. We publish a South African AI policy template as a starting point.
The automation angle here is not ironic, it is the point. Verification is exactly the kind of work that decays when it depends on someone remembering. It survives when it is a required field, a checklist item that blocks the send, or a step in a workflow that will not advance without it. That is a systems problem, and systems problems are solvable. We build these controls into the operating systems we set up in NexOne, so the check happens because the process demands it rather than because a person was diligent that day.
Frequently Asked Questions
Is there an AI law in South Africa right now?
No. There is no dedicated AI statute. AI use is regulated through existing law, principally POPIA, the Electronic Communications and Transactions Act, the Cybercrimes Act, PAIA, intellectual property legislation and ordinary labour and consumer law.
Why was the draft National AI Policy withdrawn?
Its reference list cited sources that do not exist. The Minister said the most plausible explanation was AI-generated citations included without verification. It was withdrawn in its entirety by a Government Gazette dated 12 June 2026.
When will South Africa have an AI policy?
The Department of Communications and Digital Technologies has said it is targeting the 2026/2027 financial year, with a Cabinet submission planned for November 2026 and republication for public comment targeted for January 2027. A policy is also not a law.
Does POPIA apply to AI tools?
Yes, wherever personal information is involved. Section 71 specifically restricts decisions with legal or substantial effects that are based solely on automated processing used to profile someone, and requires you to explain the underlying logic on request.
What should a small business do before the new policy arrives?
Treat the existing law as the requirement, because it is. Write down which outputs must be verified, which decisions your tools make unaided, and where the explanation for each decision is stored. Those three records cover most of the exposure.
Where to start
If you are already using AI in the business and are not sure which of those obligations you have quietly taken on, that is a mapping exercise rather than a legal one. It starts with an honest inventory of what your tools currently decide without a person in the loop. A Business Autopsy does exactly that mapping across your operation, and you can book a discovery call to see whether it fits.