South African AI Policy aims to promote responsible AI adoption through responsible AI governance. For organisations that develop, deploy, or use AI, this is the moment to act. The policy proposes sector-specific standards and guidelines for AI in South Africa. In the absence of a standalone AI Act, AI standards will operate within an integrated architecture of existing laws, existing regulators and authorities and new oversight bodies. There will be a sector-specific, risk-based approach that imposes strict regulations and “proportional controls” on high-risk applications while allowing flexibility in lower-risk sectors. Under this approach, principles-based governance measures would intervene when a high-risk threshold is met. The use cases that will constitute high risk will be left to sector authorities, in consultation with industry, to outline. Classification of high-risk AI may align with Article 6 of the EU AI Act or the OECD Framework for the Classification of AI Systems.
This means that AI will be regulated through a multi-level, multi-regulatory structure, which will require high-level coordination between the public and private sectors. Critics raise valid concerns that this multi-polar approach may fragment AI rules, stretch already-limited AI skills, or create regulatory barriers for AI startups. However, to achieve the policy’s innovative aims and promote responsible governance, the necessary governance structures must be put in place, especially to ensure accountability for seeing through the policy statements.
The time to prepare is now, not when the final policy lands.
Implementation timeline
The South Africa AI Policy is the result of many initiatives and documents, starting with the Presidential Commission on 4IR, which set the tone, the National AI Plan, and the National AI Framework, which has led to the draft. We are currently nearing the finalisation of the South African AI policy, with the draft out for comment 10 April 2026 and finalisation expected by the end of 2026.

The final phases are essential. For the policy to achieve its goals of boosting innovation and economic growth, the tiered regulatory approach it envisions must be carefully outlined so that everyone knows what they are responsible of doing. Moreover, the sector standards and guidelines should include a high level of industry engagement so that they are rooted in reality and context. A heavy-handed approach creates barriers to innovation, and too little regulation may result in harmful AI risks materialising.
You can start using AI lawfully in your organisation today. You don’t need to wait for the final policy or sector-specific regulations. Ask us how.
South African AI Policy
The South African AI Policy seeks to enable safe and secure adoption of AI technologies, while safeguarding rights and aligning with national values and
international norms. Specifically, the policy identifies a lack of dedicated legislative frameworks and institutional capacity tailored for AI-specific risks such as algorithmic bias, accountability in autonomous decision-making, and data protection in large-scale analytics systems.

Actions you can take
- Influence how sector-specific regulations are framed by monitoring the gazetting process and participating in the public comment period or joining our roundtable on the South African AI policy.
- Know how to appoint responsible teams and persons for AI accountability by joining our AI governance programme.
- Strengthen internal readiness through policy alignment by joining our data protection, access to information, or cybersecurity programmes.
- Conduct an AI assessment, data protection impact assessment, or cybersecurity compliance assessment by asking us to map your obligations now.
- Keep up with us and read our insights for more developments.
The six pillars of the South African AI Policy
The policy comprises six strategic pillars to support responsible and ethical AI development and deployment:
- Capacity and talent development by building the national AI skills base through education, training, and industry collaboration, supported by stronger digital infrastructure and connectivity.
- AI for economic transformation to drive growth through research, development, and innovation by supporting startups, SMEs, and local AI ecosystems.
- Responsible AI governance to establish safeguards for safety, security, privacy, and data protection, by setting expectations for professional responsibility in AI development and deployment.
- Ethical and inclusive AI to address fairness and bias, through ethical AI guidelines that promote AI that works equitably for everyone.
- Cultural preservation and international integration to protect South African languages, heritage, and human values in AI systems by positioning South Africa as a competitive global player.
- Human-centred deployment to keep humans in control of AI systems by requiring transparency, sufficient explainability of automated decisions, and responsible public sector implementation.
For AI governance, the most relevant pillars are responsible governance, ethical and inclusive AI, and human-centred deployment. For example, under Section 76 of the Companies Act, read with the King Code, directors already have a professional responsibility to govern AI responsibly and maintain AI literacy. Expect more obligations of this kind under sector standards.
South African AI regulatory approach
South Africa will not pass a standalone AI Act. Instead, the regulators will strengthen existing laws to address AI. Several legal obligations already apply. For instance, POPIA and AI already interact. POPIA governs how AI systems collect and process personal information, including automated decision-making, profiling, and cross-border data transfers. If your AI system handles personal data, POPIA now applies. POPIA also allows individuals to challenge automated decisions that significantly affect them.
Other applicable laws also apply. For example, the Cybercrimes Act covers AI used in security-sensitive environments. The Consumer Protection Act applies where AI drives customer-facing decisions. The Electronic Communications and Transactions Act governs automated digital processes.
Because most legislation was not designed with AI in mind, the South African AI Policy calls for strengthening existing regulations. Organisations should also align with international frameworks, including the NIST AI Risk Management Framework, ISO standards, the OECD AI Principles, and the UNESCO Ethics Recommendation. Adopting international norms enables scaling across markets and aligns your organisation with best practices where gaps exist in South African law.
When last did you do a compliance health – check?
Oversight authorities under the South African AI Policy
The South African AI Policy calls for a multi-institutional structure to manage AI. Newly formed bodies will collaborate with existing regulators to promote consistency, enabling coordination among authorities to avoid fragmentation. The duties of regulators and oversight authorities are to ensure fairness, transparency, and non-discrimination in AI applications, to promote algorithmic accountability, and to contribute to the development of technical standards. Organisations should view regulators as important stakeholders in their AI initiatives since their main aim is not to restrict or catch organisations out, but rather to provide guidance and offer regulatory sandboxes to support responsible AI innovation.
New bodies created by the South African AI Policy
The five new bodies created by the South African AI Policy will be harmonised through an AI regulatory forum; these bodies include:
- National AI commission (national AI office): This standalone office serves as the central “nerve-centre,” coordinating policy refinements, stakeholder engagement, and monitoring across government, industry, and civil society.
- AI ethics board: Tasked with enforcing ethical governance by focusing on considerations of bias, privacy, and fairness.
- AI regulatory authority: This entity is responsible for monitoring compliance, performing audits, issuing certifications, and conducting gender and human rights impact assessments.
- AI ombudsperson office: Established to provide a venue for redress, it allows individuals to challenge AI-driven decisions and seek compensation or corrections.
- National AI safety institute: This body works with international counterparts to advance the science of AI safety, developing guidelines and playbooks to mitigate technological risks.
Existing bodies involved in AI regulation
As for existing regulators, the Information Regulator will likely serve an important role, given the close relationship between AI and POPIA. Other bodies will also be part of this regulatory matrix, including;
- Independent Communications Authority of South Africa (ICASA), which will be responsible for AI in digital infrastructure and broadcasting, including telecommunications and postal services. Its expanded mandate includes overseeing the ethical use of AI in content recommendations and network management.
- The Competition Commission will be charged with ensuring digital market fairness by monitoring the AI landscape to prevent dominant interests from undermining competition.
- Financial Regulators (SARB and FSCA) will oversee AI in fintech and manage AI-related operational risks within the national financial system.
- South African Human Rights Commission (SAHRC) will monitor AI applications for compliance with human rights laws, address algorithmic biases, and advocate for transparent practices
Measures in support of innovation in the South African AI Policy
Once implemented, the policy will require sector bodies to engage with market stakeholders and civil society through a co-regulatory framework. A variety of government-led initiatives are being proposed to foster innovation, including regulatory sandboxes for piloting AI solutions. Sandboxes will play an important part in alleviating any regulatory barriers for AI start-ups looking to innovate in high-risk areas. Since the sandbox environment allows for real-world testing of AI products and services in a regulatory lax setting. There are also other measures proposed, such as direct funding through an AI Innovation Fund, economic incentives such as tax breaks and subsidies for AI initiatives and capacity building. If these measures can be successfully implemented, this approach may support responsible innovation by upholding the policy’s guiding principles while giving AI projects the resources and space needed to innovate.
A sandbox allows developers, deployers, and regulators to observe how AI solutions behave in real-world environments and identify the safeguards needed for each use case.
AI Liability and the AI insurance superfund
The Draft South Africa National AI Policy proposes an AI Insurance Superfund to address AI liability. This fund will be modelled directly on the Road Accident Fund, in which individuals or entities are compensated when accountability cannot be properly assigned. Just as motor vehicle liability is complex and multi-party, AI harm rarely traces cleanly to a single responsible actor. The chain runs through developers, deployers, data providers, and users. The Superfund acknowledges this reality upfront.
The fund is still at the concept stage. The policy is silent on how it will be capitalised, what categories of harm qualify, and how contributions will be structured. The RAF is funded through a fuel levy. The AI equivalent could be a levy on high-risk AI deployments, a mandatory contribution from organisations deploying AI in sensitive sectors, or a government appropriation. Your organisation needs to watch this closely, as it could become a direct, recurring cost of deploying AI.
Critically, the Superfund does not eliminate your liability. We are yet to see how it will play out, but your organisation still remains responsible for AI harms. The fund is not a shield. You still need documented accountability structures, internal governance mechanisms, and a review of your existing insurance cover to identify gaps that AI-specific liability products will need to fill.
AI governance under the South African AI policy
Without a standalone South African AI Act, the South African AI Policy will serve as the basis for industry-specific guidelines. Organisations must build AI governance mechanisms now.
- Accountability mechanisms. Establish the right team for AI governance to ensure accountability and human oversight throughout the AI lifecycle. This enables auditable records, such as AI registries, that support traceability and transparency in AI decision-making.
- Security, safety, and data protection. Apply security-by-design and privacy-by-default principles throughout the development and deployment of AI solutions. Given POPIA’s cross-border transfer provisions, ensure you know where your AI tools process data.
- Explainability and contestability. AI-driven decisions must be sufficiently explainable. Citizens have the right to understand and contest automated decisions that affect them.
- AI model assessments. Before deploying high-risk AI systems, conduct algorithmic, gender, and data protection impact assessments.
- Lifecycle-based governance. Apply governance measures across the entire AI lifecycle, from design and development through to deployment and ongoing operation.
