South Africa has no AI statute, and as of May 2026 it does not have a national AI policy either. The draft was withdrawn. What an operator actually faces is one binding instrument, the Protection of Personal Information Act, with a specific automated decision-making provision that is narrower than the GDPR equivalent and that grants no consent gateway. This guide sets out what section 71 actually says, what the Information Regulator can actually do, and what the financial regulators have and have not published.

Key takeaways

  • South Africa has no binding AI statute. The Department of Communications and Digital Technologies published a discussion document in October 2023 carrying an explicit not-for-publication disclaimer, and the Minister announced on 12 May 2026 that the draft National AI Policy had been withdrawn.
  • The reason for the withdrawal is directly on point for a publication about AI liability. The Minister stated that generative AI had been used irresponsibly during the drafting of the policy, that this adversely affected the document, and that withdrawal was the only way to reintroduce a credible policy. DCDT is now enforcing an internal responsible AI use policy and has appointed an independent expert review panel chaired by Professor Benjamin Rosman.
  • The binding provision is POPIA section 71, not section 26. Section 71(1) prohibits subjecting a data subject to a decision based solely on automated processing that has legal consequences or affects them to a substantial degree, where that processing is intended to provide a profile.
  • Section 71(2) has two exceptions, not three, and consent is not one of them. The gateways are a decision taken in connection with the conclusion or execution of a contract where the data subject's request has been met or appropriate measures protect their legitimate interests, and a decision governed by a law or code of conduct specifying appropriate measures.
  • Section 71(3) is the operative transparency right and the closest South African analogue to EU explainability: the appropriate measures must give the data subject an opportunity to make representations about the decision, and must require the responsible party to provide sufficient information about the underlying logic of the automated processing.
  • Neither SARB, the FSCA nor ICASA has issued binding AI rules. The FSCA and the Prudential Authority published a joint report on AI in the South African financial sector on 24 November 2025 which states that sector-wide ethical AI guidance is envisaged, meaning it has not been issued.

The regulatory landscape

South Africa's AI environment in 2026 has one binding layer and several layers that are frequently described as binding but are not. Distinguishing them is the whole compliance analysis.

The binding layer is data protection law under POPIA, which applies to any operator processing personal information about South African data subjects. Its automated decision-making provision, section 71, directly constrains AI deployments that make consequential decisions about individuals.

The policy layer is currently empty. DCDT published a fifty three page discussion document in October 2023, "South Africa's Artificial Intelligence (AI) Planning: Adoption of AI by Government", which states on its face that it is a draft for general discussion purposes and not for publication. In April 2024 the Minister described the draft National AI Policy as still requiring provincial input before finalisation. On 12 May 2026 the Minister announced its withdrawal. DCDT maintains a page titled "SA National AI Policy Framework" whose download listing is empty.

The sectoral layer is guidance and research rather than rules. The FSCA and the Prudential Authority have published a joint report. SARB and ICASA have published nothing AI-specific that could be located at their own domains.

Why the policy was withdrawn, and why it matters here

In his budget vote speech of 12 May 2026, the Minister of Communications and Digital Technologies said that the department could not discuss policy without addressing "the revelation that generative AI was used irresponsibly during the drafting of this policy", that this "adversely impacted the policy document", and that "withdrawing the policy was the only way to ensure that we reintroduce a credible policy for this critical area."

He announced an Independent Expert Review Panel chaired by Professor Benjamin Rosman, with Professor Vukosi Marivate, Professor Alison Gillwald, Ms Heather Irvine, Dr Tshepo Feela, Dr Jabu Mtsweni and Advocate Lufuno Tshikalange, to ensure that the policy reintroduced for public comment is based on the best available evidence. DCDT also stated that it is enforcing an internal responsible AI use policy and reviewing its policy development process.

For an operator, the practical consequence is that there is no South African AI policy to align to, and that anything describing an eight-principle national AI framework as current is describing a document that has been pulled. For a publication about AI liability, the episode is itself the most instructive South African development available: a government department published AI-generated material without adequate verification and had to withdraw it.

POPIA: the binding obligation for AI operators

POPIA entered into operation on 1 July 2021. The Information Regulator will not accept a complaint where the cause of action arose before that date. It holds a dual mandate under POPIA and the Promotion of Access to Information Act.

Scope and territorial reach

Section 3(1)(b) applies POPIA where the responsible party is domiciled in South Africa, or is not domiciled in South Africa but uses means in South Africa to process the information, other than merely to forward it through the Republic. For AI operators the reach is broad but it is a means-based test, not a targeting test. An AI system deployed outside South Africa that processes personal information about South African users using South African infrastructure is within scope.

Section 71: what it actually says

Section 71(1) provides that a data subject may not be subject to a decision which results in legal consequences for them, or which affects them to a substantial degree, which is based solely on the basis of the automated processing of personal information intended to provide a profile of that person, including performance at work, credit worthiness, reliability, location, health, personal preferences or conduct.

Section 71(2) sets two exceptions. The first is where the decision has been taken in connection with the conclusion or execution of a contract, and either the data subject's request in terms of the contract has been met, or appropriate measures have been taken to protect the data subject's legitimate interests. The second is where the decision is governed by a law or code of conduct in which appropriate measures are specified for protecting the legitimate interests of data subjects.

There is no consent exception. An earlier version of this guide stated three times that consent was a gateway under this provision. It is not, and an operator that built its South African AI compliance on consent would have been non-compliant. This is a real divergence from GDPR Article 22, which does permit explicit consent, and it is the kind of difference that a copy-and-adapt approach to a GDPR programme will miss.

Section 71(3) defines what the appropriate measures must do. They must provide an opportunity for a data subject to make representations about the decision, and they must require the responsible party to provide the data subject with sufficient information about the underlying logic of the automated processing. That second limb is South Africa's explainability obligation, and it is the closest domestic analogue to the EU explainability duties that operators tend to build programmes around.

The practical effect is that AI systems making consequential automated decisions about South African individuals, in credit assessment, hiring, benefit eligibility or pricing, must be routed through the contract gateway or a law or code of conduct, and in either case must carry representations and logic-disclosure measures. The operator must document which gateway applies.

Accountability, security and breach notification

Section 8 imposes the accountability obligation: the responsible party must ensure that all conditions for lawful processing are complied with when determining the purpose and means of the processing. For AI operators this means documenting the lawful basis for each processing activity and the safeguards applied.

Section 19 requires reasonable technical and organisational measures to prevent loss, damage or unauthorised access to personal information. For AI systems this reaches training data security, model access controls, audit logging, and procedures for detecting model manipulation or extraction.

Section 22 requires notification to the Information Regulator and to affected data subjects where a security compromise creates a risk of adverse effects. Unlike the GDPR, POPIA sets no numeric deadline; the Act says notification must be made as soon as reasonably possible.

Penalties, with the right section numbers

Section 107 is criminal. Conviction for contravening sections 100, 103(1), 104(2), 105(1) or 106(1), (3) or (4) carries a fine or imprisonment not exceeding ten years, or both; for sections 59, 101, 102, 103(2) or 104(1), a fine or imprisonment not exceeding twelve months, or both.

The ZAR 10 million figure is section 109(2)(c), which provides that an infringement notice must specify the amount of the administrative fine payable, which may not exceed R10 million. This matters structurally, not just as a citation correction. Section 109 attaches to an alleged offence under the Act, is delivered by infringement notice, and the recipient may elect to be tried in court. Breach of the processing conditions themselves is enforced by an enforcement notice under section 95; failing to comply with that notice is what becomes the offence. Describing R10 million as a general per-violation fine for breaching POPIA's conditions, as an earlier version of this guide did, overstates how the enforcement chain works.

What the Information Regulator has actually published on AI

Nothing. The Regulator's guidance notes cover direct marketing, processing of voters' information and countering misinformation during elections, processing special personal information, processing personal information of children, COVID-19, and political parties. There is no AI guidance note, no profiling guidance and no automated decision-making guidance.

Its published enforcement notices name the South African Police Service, Hardwick, the Department of Justice and Constitutional Development, the Department of Basic Education, FT Rams Consulting, Dis-Chem, WhatsApp, the Gauteng Department of Health, Sibanye-Stillwater and CJC. The one credit bureau matter, TransUnion, resulted in an enforcement notice rather than a fine. An earlier version of this guide described a ZAR 5 million administrative penalty against a credit bureau in 2023; no such penalty appears in the Regulator's published record and the claim has been removed.

An earlier version also cited the Regulator's 2023/24 Annual Report, as RP350/2024, for the proposition that operators using AI for profiling are expected to maintain processing impact assessments. The tabling reference is RP290/2024, and the full text of that report and of the 2024/25 report contains no reference to artificial intelligence, profiling or automated decision making. That claim has been removed.

The AI Institute of South Africa

The Artificial Intelligence Institute of South Africa, AIISA, was established in November 2022, following the recommendations of the Presidential Commission on the Fourth Industrial Revolution, whose report was adopted by Cabinet on 26 August 2021. It predates the 2023 discussion document and was not established under it. Its hubs sit at the University of Johannesburg, the Tshwane University of Technology, and the Defence Artificial Intelligence Research Unit at the Military Academy in Saldanha, launched in May 2024. An earlier version of this guide named it the South African AI Institute with the acronym SAAII and said it was established under the 2023 framework; all three elements were wrong.

Financial sector: a report, not a rule

An earlier version of this guide described a SARB Prudential Standard FSR01 on Technology Risk Management and an FSCA Guidance Note 2 of 2023 on the use of digital tools and artificial intelligence in financial advice. Neither exists. SARB's regulatory instruments page contains no FSR01, no technology risk management standard and no mention of artificial intelligence; the relevant instrument in that space is the draft Joint Standard on IT Governance and Risk Management of 23 May 2023. The FSCA's regulatory framework document store contains no document with artificial, guidance note, robo, digital or advice in its title, and the FSCA does not use the label Guidance Note. Both citations have been removed rather than reworded.

What does exist is the FSCA and Prudential Authority joint report "Artificial Intelligence in the South African Financial Sector", published 24 November 2025. It is survey-based: it records that 52 per cent of banking institutions and 50 per cent of payment providers actively use AI, and that more than half of bank respondents anticipated investing over R20 million in AI during 2024. It recommends explainability techniques such as SHAP and LIME, board-level oversight, disclosure where AI is used in consumer-impacting decisions, and coordination with the Information Regulator on POPIA alignment. Critically for an operator's compliance planning, it states that sector-wide guidance for ethical, fair and responsible AI is envisaged. Envisaged is not issued.

ICASA has published no AI-specific rules. A search of its own site for artificial intelligence returns no results.

Comparison with the EU AI Act and NIST AI RMF

Operators already compliant with the EU AI Act will find the South African gap smaller than the absence of an AI statute suggests, but differently shaped. South Africa imposes no risk classification, no conformity assessment and no registration. What it imposes is section 71, and a GDPR-derived programme will not satisfy it without adjustment, because the consent gateway a GDPR programme is likely to rely on does not exist in South African law. The section 71(3) logic-disclosure duty maps reasonably onto EU explainability documentation.

The NIST AI Risk Management Framework 1.0, published 26 January 2023, and the Generative AI Profile NIST AI 600-1, published 26 July 2024, remain useful as a governance scaffold. They are voluntary everywhere, and in South Africa they align to no published national principle set, because the national principle set was withdrawn.

For a comparison with other major non-EU jurisdictions covered in this series, see the India AI regulatory framework guide, the Australia voluntary AI safety standard guide, and the US, EU and UK comparison. For EU AI Act Article 26 deployer obligations, see the full Article 26 guide on agentliability.eu.

What operators should do

Five steps. First, conduct a POPIA scope assessment identifying which AI deployments process personal information about South African data subjects and on what lawful basis under section 11. Second, for each automated decision-making function, work out whether it is caught by section 71(1), and if so which of the two section 71(2) gateways applies; do not assume consent will serve. Third, build the section 71(3) measures in operable form: a real route for the data subject to make representations, and a means of providing sufficient information about the underlying logic. Fourth, apply section 19 security measures specifically to training data, model access and inference logs, and build a section 22 notification procedure that does not wait for a numeric deadline that POPIA does not set. Fifth, if you are a financial institution, read the FSCA and Prudential Authority joint report of 24 November 2025 for direction, while recognising that it is a report and that the ethical AI guidance it describes has not been issued.


Frequently asked questions

Does South Africa have a dedicated AI law in 2026?

No, and as of May 2026 it does not have a national AI policy either. The Department of Communications and Digital Technologies published a discussion document in October 2023 that carried an explicit not-for-publication disclaimer, and on 12 May 2026 the Minister announced that the draft National AI Policy had been withdrawn, stating that generative AI had been used irresponsibly during its drafting. An Independent Expert Review Panel chaired by Professor Benjamin Rosman is preparing a replacement for public comment. The binding framework is the Protection of Personal Information Act, enforced by the Information Regulator.

How does POPIA apply to AI agents deployed in South Africa?

POPIA applies under section 3(1)(b) where the responsible party is domiciled in South Africa, or is not domiciled there but uses means in South Africa to process the information. The provision that constrains AI decisions is section 71, not section 26. Section 71(1) prohibits subjecting a data subject to a decision with legal consequences, or affecting them to a substantial degree, based solely on automated processing intended to provide a profile. Section 11 requires lawful grounds for processing, section 19 requires reasonable technical and organisational security measures, and section 22 requires notification of a security compromise to the Regulator and affected data subjects as soon as reasonably possible, with no numeric deadline.

What are the exceptions to POPIA's automated decision-making rule?

Section 71(2) provides two, and consent is not one of them. The first is where the decision was taken in connection with the conclusion or execution of a contract and either the data subject's request in terms of the contract has been met, or appropriate measures have been taken to protect the data subject's legitimate interests. The second is where the decision is governed by a law or code of conduct in which appropriate measures are specified. Section 71(3) requires that those appropriate measures give the data subject an opportunity to make representations about the decision, and require the responsible party to provide sufficient information about the underlying logic of the automated processing. This is a real divergence from GDPR Article 22, which does permit explicit consent.

What penalties can the Information Regulator impose under POPIA?

Section 107 is criminal: conviction for contravening sections 100, 103(1), 104(2), 105(1) or 106(1), (3) or (4) carries a fine or imprisonment not exceeding ten years, or both; for sections 59, 101, 102, 103(2) or 104(1), a fine or imprisonment not exceeding twelve months, or both. The administrative fine of up to R10 million is section 109(2)(c), specified in an infringement notice for an alleged offence under the Act, and the recipient may elect to be tried in court. Breach of the processing conditions themselves is enforced by an enforcement notice under section 95; non-compliance with that notice is the offence. The Regulator has published no AI-specific guidance note.

Have South Africa's financial regulators issued AI rules?

No. The Financial Sector Conduct Authority and the Prudential Authority published a joint report, Artificial Intelligence in the South African Financial Sector, on 24 November 2025. It is survey-based and recommends explainability techniques, board-level oversight, disclosure where AI is used in consumer-impacting decisions, and coordination with the Information Regulator on POPIA alignment. It states that sector-wide guidance for ethical, fair and responsible AI is envisaged, which means it has not been issued. No SARB prudential standard on technology risk management or AI could be located at resbank.co.za, and ICASA has published nothing AI-specific.


References

  1. Department of Communications and Digital Technologies (South Africa). "South Africa's Artificial Intelligence (AI) Planning: Adoption of AI by Government", October 2023. Fifty three pages, marked as a draft for general discussion and not for publication. dcdt.gov.za.
  2. Minister of Communications and Digital Technologies, Budget Vote Speech, 12 May 2026, announcing the withdrawal of the draft National Artificial Intelligence Policy and the appointment of an Independent Expert Review Panel chaired by Professor Benjamin Rosman. dcdt.gov.za.
  3. Protection of Personal Information Act 4 of 2013 (POPIA), Government Gazette No. 37067 of 26 November 2013, in operation from 1 July 2021. Section 3(1)(b) (scope), section 8 (accountability), section 11 (lawful grounds), section 19 (security safeguards), section 22 (notification of security compromises), section 71 (automated decision making), section 95 (enforcement notice), section 107 (offences and penalties), section 109 (administrative fines). gov.za.
  4. Information Regulator (South Africa). Guidance notes, enforcement notices, and Annual Reports 2023/2024 (RP290/2024) and 2024/2025. No AI-specific guidance note has been issued, and neither annual report refers to artificial intelligence, profiling or automated decision making. inforegulator.org.za.
  5. Financial Sector Conduct Authority and Prudential Authority. "Artificial Intelligence in the South African Financial Sector", joint report, 24 November 2025. States that sector-wide guidance for ethical, fair and responsible AI is envisaged. fsca.co.za.
  6. Artificial Intelligence Institute of South Africa (AIISA), established November 2022 following the Presidential Commission on the Fourth Industrial Revolution report adopted by Cabinet on 26 August 2021. Hubs at the University of Johannesburg, the Tshwane University of Technology, and the Defence Artificial Intelligence Research Unit launched May 2024. dcdt.gov.za.
  7. NIST AI Risk Management Framework (AI RMF 1.0), NIST AI 100-1, 26 January 2023, and NIST AI 600-1 Generative AI Profile, 26 July 2024. Voluntary. nist.gov.
  8. Regulation (EU) 2024/1689 (EU AI Act), Article 26 (deployer obligations), for comparison.