Welcome to the law in 2026! At the beginning of each year, we look ahead to help you prioritise your next steps. This is the law regarding digital, data and tech in 2026. We try to predict what will happen and what it will mean for you. Our expertise will guide you on where to spend your time and energy.

Many wise people have said ‘it is difficult to make predictions, especially about the future.’

We agree, but that doesn’t stop us from trying anyway. We try our best to get it right, and sometimes we don’t. Last year, the majority of our 2025 predictions were accurate. We aim to help you allocate your resources effectively to navigate the next 12 months. You can also attend our event on this topic or watch a recording of it.

The panel’s biggest legal concern for 2026 is organisations failing to govern AI.

Countries will regulate social media

Australia (through its Online Safety Act) has already banned social media for under-16s. In 2026, many other countries will follow their example and do the same. Society will try to protect children from the harms of social media.

Social media algorithms are a significant risk to everyone. They often drive people into echo chambers and radicalise them to a specific way of thinking. In 2026, people will become more divided and will move further to the left or the right. There will be few people left in the middle, and meeting in the middle will become unusual but even more important.

People will need to try to resist the algorythm.

Courts will admit more evidence that litigants find online and on social media, leading to embarrassment and the loss of claims. For example, think of a person claiming for loss of earnings due to a disability playing padel every second day.

Companies will step up efforts to manage the risks of social media.

Global regulation will be complex and hampered

Jurisdictions around the world will begin implementing and enforcing various digital regulations. But we will not be seeing a Brussels Effect as we did with the GDPR. Rather, the anti-regulatory pro-innovation (even the EU is trying to appear more innovation-friendly with the recent digital omnibus) stance of the US and the economically driven policies of smaller markets will lead to a converging approach to regulation. This may result in fragmented legal rules, requiring organisations to understand the specific regulatory structures in different markets.

There will be no Brussels Effect with digital regualtions specifically AI laws.

There are other regulatory trends that we can expect to see in digital regulations this year:

  1. Digital regulatory enforcement risk will increase, as regulators worldwide are already showing greater confidence in issuing fines for non-compliance, especially in data protection law.
  2. Simplification-driven regulatory changes will take place, with regulators focused on providing organisations with practical, plain-language tools to comply with digital regulations. This will give organisations legal certainty about what the law requires of them.
  3. Cybersecurity and privacy by design and default will give organisations a competitive advantage in scaling, especially as regulators hammer down on non-compliant organisations, big or small.

GRC disciplines will converge

In 2026, organisations that are serious about the future of the information economy will increasingly collapse traditional silos between privacy, access to information, cybersecurity, AI governance, and broader GRC functions.

The Information Officer role will continue to expand beyond legal compliance into oversight of cybersecurity controls, risk assessments, breach response, and AI-related accountability, while CISOs and technology leaders will be required to grapple directly with data protection, automated decision-making and AI governance risks.

As AI becomes embedded across business processes, many organisations will appoint dedicated AI officers (or expand existing roles) to carry explicit responsibility for AI governance.

Training employees will become a non-negotiable overhead

This convergence is happening against a backdrop of a clear skills shortage, with very few professionals able to operate confidently across law, technology, and risk. As a result, developing and retaining AI-literate cybersecurity and privacy professionals will become a strategic priority, and ongoing learning will shift from a discretionary cost to a non-negotiable operational overhead for organisations seeking to deploy AI responsibly and at scale.

Regulators will regulate AI

A survey of AI laws worldwide shows that several jurisdictions have already introduced AI rules or policies. For example, the South Korean Basic AI Law will come into force in January 2026. The Basic AI Law is similar to the EU’s, but focuses on high-risk AI and lacks the pre-market conformity assessments required under the EU AI Act, among other aspects. In regulating AI, regulators will take different approaches, but at a more sector-, industry-, or vertical-level rather than at the national level, as seen in the UK and the US. This may result in legal fragmentation across sectors, but it also means that organisations in less regulated sectors do not have to adhere to the same stringent standards as those in highly regulated sectors, such as financial institutions.

Regulators will regulate AI sector-, industry-, or vertical-level

The AI bubble will burst

Many knowledgeable people (from Sam Altman and Jeff Bezos to Jamie Dimon) have said we are in bubble territory. This will have a big impact on venture capital and private equity, but not on AI technology itself. As with the dot.com bubble, people continued to use the Internet, and it went from strength to strength over the years that followed. Despite the AI bubble bursting, the magnificent seven will become more magnificent.

The legal consequences of the bubble bursting will be significant. Think suppliers failing to deliver and breaching contracts.

Consider the consequences for your organisation if the bubble bursts, and try to put measures in place to mitigate the fallout.

AI will become integrated into key business software

Key business software will become even more AI-enabled. AI will be integrated into key business software and processes that are at the heart of businesses. In 2025, we saw many proof of concepts, trials, and tests. In 2026, AI will enable mission-critical systems, processes and software.

The likelihood and significance of AI related risks materialising will be greater.

You must maintain an inventory of the AI systems or models your organisation uses. You must assess risk and implement controls.

AI governance will become the number one governing body priority

Directors generally have a duty to take reasonable steps to become informed about AI before making a business decision. With a 88% increase in spending on AI adoption predicted for 2025, directors will begin taking steps to understand AI applications and their outcomes in their specific business context. This means that managers will also have to start answering questions about how AI is being governed, as AI governance will guide businesses.

AI governance is no longer a nice to have but is becoming a compliance expectation

AI-first companies will fail

Companies with no strategic vision for their business, and in the hope that throwing AI at every aspect of the business will lead to productivity and efficiency gains, will start to show their cracks and fall apart naturally.

Start with purpose, let AI follow.

These companies that will lose a lot of money by investing in AI tools that are not fit for purpose, deploy AI tools without the necessary safeguards, leading to business assets being compromised and lose trust by not upholding the basic AI governance principles. Companies should first understand their strategic business vision and identify aspects of that vision that can and should be AI-enabled to benefit from the gains AI tools offer.

AI risks will start to materialise more often

The last quarter of 2025 already showed how easily AI risks can materialise, with examples from the Deloitte Australia case, the Air Canada chatbot that gave customers false information, and the Relpit Agentic coding tool that wiped out entire databases and lied about it. As risks become reality, organisations without AI governance structures in place will face AI liability claims under existing regulatory obligations, such as consumer protection or product liability laws. Organisations must seek to take out cyber insurance and AI assurance to mitigate the fallout if these risks materialise.

AI literacy will become a key success factor

There is a clear skills shortage, with very few professionals able to operate confidently across law, technology, and risk. As a result, developing and retaining AI-literate cybersecurity and privacy professionals will become a strategic priority, and ongoing training will shift from a discretionary cost to a non-negotiable operational overhead for organisations seeking to deploy AI responsibly and at scale. AI education and training will become a key success factor for many organisations. Demand for AI skills will increase exponentially.

The recruitment and security of skilled staff will become a priority.

Shadow AI will become a threat to orgs that fail to govern AI

Many governing bodies are failing to recognise the need to govern and manage AI within their organisations. Their “excuse” is that the organisation is not using AI. When asked whether their employees are using generative AI to complete their tasks, responses are vague, but they generally concede that this is likely. The point is that not being able to account for the AI tools used in a business context (Shadow AI) creates unknown points of failure that the organisation is unaware of, and thus cannot mitigate or respond to quickly. This means that organisations must put in place practical governance structures, such as acceptable use of AI policies and AI registries, to exercise effective human oversight over the AI tools deployed and to meet global regulatory expectations for human-in-the-loop governance.

Without governance and training, employees may misuse AI and quite possibly do things that place the organisation at risk.

Some people will have humanoid robots in the home

Some of us have been hoping for this for many years, and 2026 will be the year it becomes a reality. China is currently the leader in this regard, and in 2026, we’ll see several impressive product launches. Robots like Neo will prove very popular despite some teething problems.

Governments will profile people

Data protection or privacy laws apply to both the private and the public sector. The public sector often forgets this. Parliaments often created data privacy laws to protect citizens from their own Governments. In 2026, many governments of countries around the world are going to forge ahead with digital ID projects. The benefits are significant. Faster access to services, efficiencies, cost savings, and elimination of corruption, to name a few. But the possibility of Governments using digital IDs to profile people and act against them will increase.

Big brother is watching

Some Governments will find it just too tempting and will invade our privacy and use our personal information as a weapon against us. In particular, authoritarian leaders will unlawfully process personal information to suppress their opponents and implement their policies. This is partly why data privacy became a human right after the Second World War and why it will become more important than ever. Data subjects in countries without strong privacy laws (like the US) will suffer the most. Data privacy is about freedom, and in 2026, freedom will be curtailed. “Let us live and strive for freedom”, as the South African national anthem concludes.

The cross-border transfer landscape will become more complex as regulatory priorities diverge

Countries have always taken different approaches to international data transfers, but in 2026, these differences will harden into meaningful divergence. Even within traditionally aligned regimes, we are seeing conflicting signals.

In the EU, the preliminary addition of Brazil to the adequacy list and the General Court’s recent confirmation of the EU–US Data Privacy Framework suggest a continued willingness to enable data flows, despite ongoing legal and political uncertainty.

At the same time, the UK is moving in a more flexible direction through the Data (Use and Access) Act, which replaces the test of ‘substantially similar laws’ with a risk-based test that asks whether protections in the third country are ‘not materially lower’ than UK standards. This lowers the compliance threshold for organisations and reflects a pragmatic regulatory priority.

Data transfer strategies must take into account different data localisation requirements across jurisdictions and which transfer mechanisims are most effective.

In contrast, the US is tightening controls through national security-driven measures such as the Data Security Program and the Bulk Transfer Rule, which restrict transfers of sensitive data to certain countries of concern.

The result is a fragmented global transfer landscape driven less by shared privacy principles and more by local economic, political, and security priorities. For organisations operating across borders, this means greater complexity and an increased need for ongoing monitoring, robust transfer impact assessments, and strong technical safeguards. In 2026, forward-looking transfer strategies will be essential to manage regulatory risk and maintain operational continuity.

Legal or compliance assessments will be simplified

Over the past year, organisations have been required to grapple with an expanding set of assessments, including data protection impact assessments, transfer impact assessments, personal information impact assessments, and AI impact assessments. A consistent challenge has emerged: these exercises are often complex, resource-intensive, and difficult to operationalise, requiring input across legal, technical, security, and governance teams.

In 2026, regulators and organisations will move toward a simpler, more practical assessment approach.

In South Africa, the Information Regulator confirmed in December that organisations should rely on international guidance in the absence of local frameworks, and international developments point clearly toward simplification.

In the UK, the Data (Use and Access) Act reframes DPIAs away from rigid, box-ticking exercises toward a more flexible, risk-based approach that supports innovation while still protecting data subjects’ rights. This direction is reinforced by the UK Information Commissioner’s Office, which has issued streamlined guidance and tools for transfer risk assessments to make cross-border risk analysis more accessible and proportionate.

If South Africa continues to align with international standards, 2026 is likely to see assessments become more focused, more usable, and better integrated into real-world decision-making rather than treated as standalone compliance hurdles.

Consumers will become increasingly savvy and demanding

Consumers will become increasingly savvy and demanding about the privacy of their personal information, particularly as cybercriminals use it to target attacks. This will lead consumers to demand greater protection and enforcement, as the daily losses they suffer from cybercrime make it a present ill. Consumers are also becoming aware of their data protection rights and responsibilities, meaning organisations will be under greater scrutiny from consumers about how, where, and when they process personal data.

Moreover, lessons from the information regulator indicate that it seeks to make it easier for individual consumers to file complaints via its portal.

The SA Information Regulator will focus on NPOs, estate agents and foreign companies

In 2026, the Information Regulator’s enforcement priorities will increasingly centre on sectors and entities where non-compliance is widespread. Recent enforcement actions and public statements indicate that the Regulator will focus on non-profit organisations, as evidenced by multiple PAIA enforcement matters against community associations and trusts.

The Information Regulator has also indicated that estate agents and gated access communities are likely to face closer scrutiny due to their routine processing of large volumes of sensitive personal information.

At the same time, the Regulator has made it clear that foreign companies doing business in South Africa are firmly within its sights, particularly where they process South Africans’ personal information but resist compliance on jurisdictional grounds. Ongoing disputes with multinational digital platforms underscore the Regulator’s position that POPIA and PAIA apply extraterritorially where services are directed at South Africans.

Taken together, we predict that the Information Regulator will issue more notices and be stricter in enforcement, with a particular emphasis on NPOs, gated-access communities, and foreign organisations.

AI-enabled security threats will increase

AI-enabled social engineering attacks, including deep fakes, will increase. AI will be employed to automate the search for vulnerabilities in computer networks that would take humans a great deal of time to discover and exploit.

We have seen that AI is being used to make social engineering attacks more credible. This may be by using AI to better profile the victims of the attacks and allow more accurate representations of the person or organisation the attacker purports to be. Deepfakes, whether of voice or image, have already been used very successfully to perpetrate high-profile compromises. Specifically;

  1. AI will introduce novel risks that security teams are not ready to mitigate. Many of the risks that AI will pose are refinements of existing risks. But there will be novel risks we need to consider (Poisening and noise attacks). The advent of quantum computing, allied with AI, will break encryption algorithms. Given the extent to which encryption and hashing are used in information security, this should be a major concern for most businesses, regardless of size.
  2. CISOs will increasingly rely on AI-driven defences. AI can significantly assist in combating cyber risks, and AI-based cybersecurity tools are being developed rapidly.

Supply chain risks (attacking the weakest link) will intensify

Improved ability will affect supply chain risk, which often relies on the trust developed in establishing and maintaining the relationships on which it depends. This is not confined to humans but will be used by attackers to allow the acceptance of computer credentials used to verify that a computer in a supply chain is trusted, when, in fact, it is controlled by the attackers.

Ransomware attacks will increase. Bad actors are already using AI agents to automate the entire ransomware attack chain.

We expect BECs, already a significant scourge in our commercial landscape, to increase further as they become more credible.

In this case, third-party risk management will be important for mitigating supply chain risks.

Organisations will develop strong identity-based access controls

Bad actors will attack identity to gain access to information since identity and password-based authentication are still the default. As cyberattacks such as phishing aim to discover passwords or codes, we will see more sophisticated methods, such as passkey protection and stronger biometric authentication, developed to control access. These technical measures must be complemented by an organisation-wide access control policy.

By |2026-02-02T10:22:10+02:00January 25th, 2026|Categories: Access to Information, AI Governance, Cybersecurity Law, IT Law, Life@Law, POPI and Data Protection|Tags: , |

Share This Story, Choose Your Platform!