South Africa and AI Regulation

South Africa and AI regulation concept illustrating artificial intelligence, law and governance.

SOUTH AFRICA AND AI REGULATION: WHERE THINGS CURRENTLY STAND

In April 2026, the Department of Communications and Digital Technologies gazetted a Draft National AI Policy for public comment – the country’s first substantive attempt to articulate a governance position on AI. It’s worth noting upfront that the policy was subsequently withdrawn in June 2026 after fabricated academic citations were discovered in the text, with a revised draft only expected early in 2027. Despite the withdrawal, the document remains the clearest public signal of the direction South African AI governance is likely to take and comparing it against what other major jurisdictions have already built is a useful way to understand where the country’s approach currently sits and what choices remain open as the next draft is prepared.

A Different Starting Point

First, it’s important to understand that this document is not law. It’s a statement of the government’s thinking, put out for public input, and the document itself says that legislation is just one option on the table, not a certainty. This provides a vastly different starting point from the EU, where the AI Act is binding law with specific rules for “high-risk” uses, or China, which regulates AI through a set of binding rules on algorithms and generative AI. Even the UK, often seen as the light-touch comparator, builds its approach on top of decades of established sector regulators.

South Africa’s draft floats four possible directions: an ethics-first model, a flexible model, an economy-focused model and a global-alignment model. Compared to the EU, China, the UK, the US and international frameworks like the OECD AI Principles, South Africa is clearly the furthest from a settled position. This is not necessarily a flaw; it could simply reflect a country still consulting, not one that has fallen behind.

What works?

The policy openly acknowledges South Africa’s digital divide and the lingering effects of apartheid-era inequality, rather than assuming everyone starts from the same place. It also builds in Ubuntu as an ethical foundation and commits to AI working across all 12 official languages, neither of which has a real equivalent in Western AI frameworks.

What needs improvement?

A few aspects read more as open questions than settled answers, and they are the likely focal points for the next draft. Around a dozen oversight bodies are proposed, with overlapping responsibilities and no clear process for resolving disagreements between them, and no budget has been attached.

There is also a contradiction worth noting: one section pushes for data sovereignty and less reliance on foreign cloud providers, while another suggests leaning on those same providers to help manage energy demand. That tension sits awkwardly alongside South Africa’s existing energy and municipal service problems, which the policy’s big infrastructure ambitions (i.e., national data centres, giga-factories and universal 5G) do not yet account for.

Regarding enforcement, the current draft doesn’t include a penalty regime comparable to the EU’s fines. The one compensation mechanism proposed, an AI Insurance Superfund, is modelled on the Road Accident Fund (“RAF”), a structure whose operational history is worth factoring into any redesign, given RAF’s well-documented financial strain.

A Fairer Comparison

Rather than measuring South Africa against the EU or China, a more useful comparison might be countries like Brazil or India – middle-income democracies facing the same core challenge: wanting strong protections but needing the institutional and financial capacity to actually enforce them. South Africa’s experience with the Protection of Personal Information Act, which took seven years to fully come into effect, is a useful reminder of how long implementation can take. By the time South Africa’s AI regulations become binding law, other countries will likely already have years of enforcement experience behind them.

Bottom Line

The withdrawn policy is a serious first attempt that engages with global frameworks while staying grounded in South Africa’s own context. The gaps aren’t a failure of this draft so much as a to-do list for the next one. The real test isn’t whether South Africa stumbled on the first try, but rather what the next draft can achieve with the extra time. If anything, the withdrawal is a second chance, not a setback, and how South Africa uses it will say more about its AI ambitions than the first draft ever could.