South Africa’s AI policy is delayed. Companies are already making the decisions it will regulate

Phone a bank, insurer or medical aid and an AI system may already be involved before a human being speaks to you. It can identify why you’re calling, retrieve information about your account, summarise earlier interactions or decide where your query should go next. None of this feels particularly futuristic anymore, which is perhaps why most of us don’t stop to wonder who decided what that system should be allowed to know or do.

South Africa is still working out the national answer. Its first attempt at a dedicated AI policy was published for public comment in April 2026 and then withdrawn later that month after fictitious references were discovered in the document. Communications and Digital Technologies Minister Solly Malatsi said an internal investigation found that the most plausible explanation was that generative AI had been used to create citations that weren’t properly verified, after which the department withdrew the draft National AI Policy and began rebuilding it.

There was an obvious joke available. A policy intended to help govern AI had been tripped up by AI. It travelled because it was funny, but the failure itself was more mundane and more useful than the punchline: somebody used a tool capable of producing plausible nonsense and the process around that tool failed to catch it.

Put the same basic failure inside a customer-service operation and the stakes shift very quickly. An invented citation in a policy paper embarrasses a department and damages confidence in the process. A system that gets an insurance claim wrong, misinterprets a customer’s account or feeds inaccurate information to an employee can affect somebody’s money, healthcare or access to a service.

South Africa isn’t without legal protections while the policy is being rewritten. POPIA already places obligations on organisations processing personal information, including provisions dealing with automated decision-making, while banks, insurers, healthcare providers and other regulated businesses have sector-specific obligations of their own. What’s missing is an agreed national framework built specifically around AI.

That absence matters because deployment hasn’t waited for policy. South African organisations are already introducing generative AI into customer service, internal knowledge systems, software development and other workflows. The questions around where data goes and who remains responsible for it are already showing up in practice, and we have previously looked at this in the context of TrendAI and Anthropic’s attempt to address South Africa’s AI compliance problem.

The government has appointed a seven-member expert panel to review and rebuild the policy, with a revised version expected to go to Cabinet in November and public consultation targeted for January 2027. That timetable gives South Africa a chance to produce something more credible than the document that was withdrawn, but it also means companies are likely to spend most of 2026 deploying AI while the dedicated national framework governing it remains unfinished.

Bruce von Maltitz, CEO of South African contact-centre technology company 1Stream, argues that the delay shouldn’t become an excuse for postponing internal decisions. “Waiting is itself a choice,” he says, and that is probably the most useful way to think about the gap because businesses are already creating their own AI rules whether they describe them as governance or not.

Every decision about whether staff may paste company information into a chatbot is a governance decision. So is deciding whether an automated system can make a recommendation about a customer, whether someone must approve it, what gets logged and what happens when the AI produces something nobody expected. Sometimes those decisions are made formally. Sometimes they emerge from procurement contracts, IT permissions and whatever employees discover they can do with the software they’ve been given. Both approaches create rules, although only one makes them easy to inspect.

Von Maltitz is wary of responding to the current uncertainty by rushing legislation. The concern is understandable because AI is being used for things with radically different levels of consequence. Software summarising an internal meeting shouldn’t automatically be treated in the same way as a system contributing to a decision about somebody’s credit or healthcare simply because both use similar underlying technology.

The human-in-the-loop debate shows why broad rules can become awkward when they move from principle into practice. Human review is relatively easy to defend where an automated system can materially affect someone and there needs to be a route for correcting a mistake. Von Maltitz is less persuaded when the same principle is presented as a way of preserving employment.

“Human oversight is a real safeguard for the consumer, and I back it for that reason,” he says. As an employment policy by itself, however, he describes it as closer to “wishful thinking”.

There is an uncomfortable point inside that distinction. Requiring a person to approve the work of an automated system doesn’t necessarily protect that person’s job if the economics of the work have already changed. It may reduce the risk of a bad decision and make accountability clearer, both of which are worthwhile outcomes, but neither is the same as creating durable employment. Skills policy, retraining and the way companies redesign jobs around automation have to carry far more of that burden.

The same scepticism should be applied in the other direction. Businesses can’t argue that prescriptive AI regulation risks slowing adoption and then treat the absence of regulation as permission to do very little themselves.

There are already standards intended to put some structure around those choices. ISO/IEC 42001, published in 2023, sets requirements for establishing, maintaining and improving an artificial-intelligence management system inside an organisation. ISO describes it as the first international AI management-system standard.

The language of management standards is not especially exciting, but the underlying requirement is straightforward enough. An organisation should know where it is using AI, who is responsible for those systems, what risks it has identified and what happens when something goes wrong. The policies governing those decisions should exist somewhere more substantial than a conversation between an IT manager and whoever happened to buy the software.

1Stream has recently gone through ISO/IEC 42001 certification, which gives von Maltitz an obvious interest in arguing for more formal governance. That interest is worth stating because certification shouldn’t be confused with proof that an AI system is safe, accurate or incapable of causing harm. ISO/IEC 42001 is a management-system standard, not an approval stamp for individual AI models or outputs.

For von Maltitz, the useful part is that governance has to become concrete enough for somebody outside the organisation to examine. “We went looking for others in our field who had done the same on the continent, and are still looking,” he says. His argument is less about the badge than about what a business needs to be able to show when another company asks how its AI is being controlled.

That question becomes harder to avoid as AI gets closer to customers. A bank considering an AI supplier has to worry about more than whether a demo works. It has customers, compliance teams and regulators of its own. An insurer outsourcing part of its customer interaction inherits some of the risk attached to the systems handling those interactions. The closer AI gets to personal information or consequential decisions, the less useful a general promise to “use AI responsibly” becomes.

This is where the relationship between governance and adoption becomes more complicated than the usual argument that regulation either protects people or slows innovation. Formal governance can restrict what an organisation is willing to let an AI system do, but it can also make that organisation more comfortable using AI in places it would otherwise consider too risky.

A company may be perfectly happy to experiment with an AI meeting assistant while refusing to let the same vendor near customer identity information. The technology hasn’t suddenly become less capable. The consequences of getting it wrong have changed, and the organisation needs a better answer to the question of who is accountable when that happens.

Von Maltitz sees that as a commercial issue as much as an ethical one. In his view, governance can make more ambitious adoption possible because companies need something firmer than a supplier’s assurances before trusting an AI system with sensitive work. That doesn’t mean every organisation needs the same certification, nor does it make voluntary standards a substitute for public accountability. Companies shouldn’t get to decide entirely for themselves what rights customers have when AI contributes to important decisions.

South Africa still needs to settle questions about disclosure, accountability, recourse and where responsibility sits when automated systems fail. The withdrawn policy means those arguments will take longer than expected, and that delay may even produce a better document if the government uses the additional time properly.

What it won’t do is preserve the status quo while policymakers catch up. AI systems bought in 2026 will still be inside businesses when the next policy draft arrives. Workflows being redesigned now may be difficult to reverse later. Data permissions granted to new tools become normal remarkably quickly once employees get used to having them.

By the time South Africa formally decides how AI ought to be governed, a considerable amount of AI governance will already have happened inside companies. Some of it will have been deliberate, documented and open to scrutiny. Some of it will simply be the accumulated result of all the small decisions businesses made while waiting for government to finish the larger one.

Zeen Social Icons