AI Governance Institute
Directory

AI Regulation in South Africa

South Africa does not currently have AI-specific legislation in force. National AI policy has been under active development, but draft policy work has faced credibility setbacks — including a national AI policy process derailed after fabricated citations were discovered in supporting documentation, forcing a withdrawal and restart of that workstream. This underscores that the country's AI governance framework remains in an early, unsettled stage rather than an operative one.

In the absence of dedicated AI law, the Protection of Personal Information Act (POPIA) is the primary enforceable obligation touching AI systems that process personal data, including provisions relevant to automated decision-making. Consumer protection law and existing sector regulators (in financial services and telecommunications, for example) provide additional avenues for addressing AI-related harms using pre-existing authority, consistent with the approach many jurisdictions take before dedicated AI legislation is enacted.

For organizations operating in South Africa, the near-term compliance posture should prioritize POPIA compliance for any AI system handling personal data, since that is the concrete enforceable baseline today. National AI policy is worth monitoring for its next iteration, but the credibility setback from the fabricated-citation episode makes the timeline for a mature, enacted framework harder to predict than in peer jurisdictions currently drafting AI-specific law.

Key themes

  • 1.No AI-specific law in force — national policy still in development
  • 2.National AI policy process withdrawn after fabricated-citation issue, restart pending
  • 3.POPIA as the operative baseline for AI systems processing personal data
  • 4.Existing consumer protection and sector regulators as interim enforcement avenues

Regulatory frameworks and guidance(0)

No policies found for this jurisdiction.