There will be no standalone South African AI Act. Instead, South Africa will have a sector-specific, risk-based approach to AI regulation. This approach aligns with international best practices followed by the UK and Australia, which seek to use existing laws for AI regulation.
The aim is to identify high-risk, high-impact use cases and apply proportionate governance measures, rather than regulating AI in the abstract. This approach seeks to avoid creating barriers to innovation for low-risk use cases.
There will be no South African AI Act, but existing laws will apply.
How will we regulate without a South African AI Act?
There is no need to reinvent the wheel, especially if it is still turning just fine. Sometimes a tune-up and some fortification are sufficient. Regulators must also have had that in mind, since existing laws will be strengthened to regulate AI. This includes POPIA, PAIA, the ECT Act, CPA, the EE Act, and the Cybercrimes Act. There will also be reliance on established international standards, such as the NIST AI Risk Management Framework, ISO standards, the OECD AI Principles, and the UNESCO Ethics recommendation.
For specific use cases within an industry, the National AI policy mandates that industry bodies create guidelines and standards. The focus will be on high-risk use cases, while it remains unclear how high-risk AI systems will be classified. However, we may see alignment with Article 6 of the EU AI Act risk or the OECD Framework for the Classification of AI systems.
Stringent rules will apply to high-risk AI systems.
Who will be responsible for enforcing guidelines and standards?
The South African National AI policy calls for a coherent institutional architecture to manage AI. There will be cross-regulator collaboration between newly formed AI structures (AI Office, AI Ombudsperson, and AI Ethics Board) and existing bodies. Authorities such as ICASA, the Competition Commission and the Information Regulator will be tasked with managing AI. The Information Regulator will likely serve as the primary point of contact in these collaborations, given the close relationship between AI and personal information. This approach promotes harmonisation to avoid fragmented initiatives in the absence of a South African AI Act.
What measures in support of innovation will South Africa have?
The South African National AI policy will provide domain-specific governance roadmaps to coordinate implementation guidance for sector authorities. This is important for establishing standards in the absence of a South African AI Act. But more importantly, there is a mandate to establish sandboxes and AI innovation hubs. The sandboxes and hubs have already been successful in the South African fintech sector. Sandboxes allow developers, deployers, and regulators to observe how AI solutions interact in a real-world environment and help stakeholders identify the safeguards required for that specific use case (sector) to ensure consistency.
Core governance aspects for businesses to consider
Without a South African AI Act, the South African National AI policy will serve as the basis for industry-specific guidelines. This means that organisations must incorporate AI governance mechanisms to promote the responsible and accountable deployment of AI systems.
- Accountability mechanisms: Organisations should establish the right team for their AI governance to ensure accountability and human oversight throughout the AI system lifecycle. This enables auditable records, such as AI registries, that support traceability and transparency in AI decision-making.
- Security, safety, and data protection: Robust mechanisms must be in place to ensure the security of AI systems and the protection of information. This encompasses implementing security-by-design and privacy-by-default principles to safeguard sensitive information throughout the development and deployment of AI solutions.
- Explainability and contestability: A central focus is placed on ensuring that AI-driven decisions are “sufficiently explainable”. It is difficult to technically measure what ‘sufficient’ will be. But the idea is that AI outputs must be explainable so that citizens can understand the rationale behind automated decisions and be afforded the right to contest AI decisions. This is to foster trust and fairness in AI adoption.
- AI model assessments: Before deploying high-risk AI systems, organisations must conduct several assessments. These include algorithmic audits, gender and human rights impact assessments, and data protection impact assessments. This helps organisations identify and mitigate potential harms before deployment of high-risk AI systems.
- Lifecycle-based governance: Governance measures apply across the entire lifecycle of AI systems. From design and development through deployment and ongoing operation. This comprehensive perspective helps to ensure that AI remains safe, accountable, and aligned with legal and ethical standards at every stage.
Organisations must start intergrating these principles into their AI governance structures
There will be no South African AI Act, but where are we now?
There will be no standalone South African AI Act. The National AI Policy is currently under review across all five government clusters. After receiving strong support from director-general groups, it is pending Cabinet and political leadership consideration. The policy outlines the intent to regulate AI through a risk-based approach, focusing on sector- and industry-specific frameworks. For example, AI standards tailored to financial institutions would be developed. This approach is similar to the Joint Standards on Cybersecurity and Cyber resilience that apply exclusively to the financial sector due to its elevated risk profile.
The upcoming South African National AI policy will provide some legal clarity and guidance for AI initiatives. However, organisations that develop or deploy AI solutions are expected to comply with existing regulations as they integrate AI into their operations.
Actions you can take
- Establish accountability mechanisms by appointing responsible teams and persons, whom we empower in our AI governance programme
- Strengthen internal readiness through policy alignment by joining our data protection, access to information or cybersecurity programmes.
- Identify the impact of your AI project across digital compliance obligations by asking us to conduct various assessments, such as an AI assessment, a data protection impact assessment, or a cybersecurity compliance assessment.
- Keep up with us and read our insights for more developments.