By Lehlohonolo Lehana.
Concerns are growing over the credibility of South Africa’s draft National AI Policy amid the reports that the policy cited sources that cannot be verified, raising questions about accuracy, accountability and the use of AI in government drafting.
The Department of Communications and Digital Technologies has published South Africa’s Draft National Artificial Intelligence Policy (Draft AI Policy) for public comment.
The Draft AI Policy was approved by Cabinet on 25 March 2026 and gazetted on 10 April 2026.
The draft proposes establishing seven new institutional bodies: a National AI Commission, an AI Ethics Board, an AI Regulatory Authority, an AI Ombudsperson Office, an AI Insurance Superfund, a National AI Safety Institute, and an Integrated AI-Powered Monitoring Centre.
Cliffe Dekker Hofmeyr (CDH) Commentary on South Africa’s National Draft Artificial Intelligence Policy:
CDH Contributors:
Tayyibah Suliman a Director in our Corporate & Commercial practice and is Head of the Technology & Communications sector.
Sadia Rizvi a Senior Associate in our Corporate & Commercial practice and the Technology & Communications sector. Sadia specialises in technology, media, and telecommunications law.
Izabella Gutlar-Balkovic an Associate in the Corporate & Commercial practice and the Technology & Communications sector.
Regulatory framework
The Draft AI Policy does not adequately explain how these structures will interact with existing regulators such as the Information Regulator, ICASA, or the financial sector regulators.
The precise mandates, independence, funding and accountability mechanisms for each body are also not clear. The lack of clarity creates a risk of duplication, and issues regarding oversight and jurisdiction.
The proposed AI Insurance Superfund is particularly underdeveloped. It does not address who funds the Superfund, what harm qualifies, how causation is assessed, or how claims interact with other intertwined legislation, such as POPIA.
Risk classification
Central to the Draft AI Policy is a risk based regulatory framework modelled on international frameworks, including the EU AI Act. Higher risk AI systems, particularly those deployed in sensitive sectors such as healthcare, financial services, law enforcement, and critical infrastructure, are expected to have stricter regulatory requirements.
However, the Draft AI Policy does not define what constitutes a high, medium, or low risk AI system. Until clear definitions are introduced, organisations face uncertainty when attempting to assess regulatory exposure, particularly for organisations that build or use generative AI, automated decision-making tools, and large language models.
Data governance and accountability
The Draft AI Policy seeks to align AI governance with POPIA, with specific reference to automated decision making under section 71. It promotes data protection by design as a baseline requirement and reinforces transparency as a core principle.
Key proposals include mandatory watermarking of training data for large language models, the development of cross border data flow protocols to protect data sovereignty, and a requirement for “sufficient explainability” for high-risk AI systems.
Whilst these principles will require sector specific guidance to ensure that they are pragmatic and can be applied in day-to-day business operations, this is a step towards oversight and formulating sector-specific regulation on AI.
Practical considerations
Regulatory frameworks for AI systems should strike a balance between oversight and flexibility to avoid stifling innovation. Fostering AI innovation in South Africa is critical to driving economic growth, creating jobs, and positioning the country as a competitive player in the global digital economy.
The public consultation process offers an opportunity for organisations to influence the shape of South Africa’s future AI regulatory framework. Organisations – particularly those in financial services, healthcare, technology, and digital media – should begin mapping their existing and planned use of AI and identifying where they may fall into higher risk categories. We encourage organisations to submit written comments, particularly where the AI use cases have already been implemented.
Amid the backlash Department of Communications and Digital Technologies minister Solly Malatsi said he has asked the Director General to investigate and take action against anyone found to be responsible for any wrongdoing.
Malatsi meanwhile has also said he will engage the Independent Communications Authority of South Africa (ICASA) to understand why it has made little progress on his May 2025 policy direction.
The minister’s policy direction instructed the regulator to align its rules with the full scope of the BEE ICT Sector Code.
Malatsi’s December policy direction requires Icasa to align its licensing rules with the broader B-BBEE framework by recognising equity equivalent investment programmes, or EEIPs, as an alternative route to compliance.
Multinationals that cannot or will not cede 30% of local equity to historically disadvantaged groups would instead invest an equivalent amount in skills development, enterprise support, local infrastructure or research.
The mechanism already exists in South African law and is already used by Microsoft, IBM, Amazon Web Services and a long list of other global technology firms. It is administered by the department of trade, industry & competition. It is not new, not radical and not tailored to a single company, whatever critics of the direction have falsely claimed.
