What was published and then withdrawn
The Draft National Artificial Intelligence Policy was published in Government Gazette No. 54477 on 10 April 2026. After fictitious references were identified, the Minister announced the withdrawal on 26 April 2026, Cabinet approved it on 5 June 2026, and Notice 3880 was withdrawn by gazette on 12 June 2026, which is the act that withdrew it. The withdrawn draft is public historical material, not current policy or law.
The withdrawn text described the following policy direction. It is not a reliable authority for current policy: the government withdrew it after fictitious references and undisclosed generative-AI use undermined its evidential basis.
- A sector-specific, multi-regulator governance model. Rather than creating a single dedicated AI regulator, AI governance will be embedded within existing supervisory frameworks — the FSCA for financial services, the Information Regulator for data protection, the Council for Medical Schemes for health, ICASA for telecommunications, the Department of Higher Education and Training for education, and so on. Pragmatic, but creates a patchwork that is harder to navigate for smaller businesses operating across sectors.
- Six core pillars organised around capacity and talent development, AI for inclusive growth and job creation, responsible governance, ethical and inclusive AI, cultural preservation and international integration, and human-centred deployment.
- A public comment process that did not continue after withdrawal.
- Final policy targeted for the 2026/2027 financial year.
- Sector-specific regulations and guidelines targeted for the 2027/2028 financial year.
Primary records: Government Gazette No. 54477, 10 April 2026 and Cabinet withdrawal confirmation, 5 June 2026. Any replacement policy requires a new official publication.
The South African legal baseline for AI today
South Africa does not have an AI Act yet, and the draft policy Cabinet approved is not itself an Act either — it is a policy that will later be translated into sector-specific regulations. But South African organisations deploying AI are already bound by a substantial body of existing law. None of these require waiting for the gazette.
- POPIA (Protection of Personal Information Act, 2013) — applies to any AI system that processes personal information. Section 71 specifically addresses automated decision-making and profiling: a data subject is entitled not to be subject to a decision based solely on automated processing unless specific exceptions apply. This obligation already binds South African organisations regardless of when the AI Policy is gazetted.
- Copyright Act, 1978 (and the unsigned Copyright Amendment Bill) — relevant to training-data provenance and to AI-generated outputs.
- Competition Act, 1998 — relevant to algorithmic pricing, market concentration in AI infrastructure, and data-driven anti-competitive conduct.
- Patents Act, 1978 — relevant to AI-generated inventions; the Thaler line of decisions has been tested in South African courts.
- King IV / King V Codes on Corporate Governance — non-statutory but widely adopted. King V was adopted by the Institute of Directors in South Africa (IoDSA) on 31 October 2025 and is in force for financial years commencing on or after January 2026. It consolidates King IV's 17 principles into 13 and introduces explicit AI governance principles alongside enhanced cyber risk provisions — governing bodies are now expected to oversee AI use and AI-related risk as a board-level matter under King V's "apply and explain" regime.
What South African organisations should do now
The April draft has been withdrawn. These steps are based on existing law and governance practice, not on treating the withdrawn consultation as binding:
- Inventory your AI systems. A list of what you have deployed, in which products, by which teams, with which third-party providers, and against which categories of personal data. POPIA already requires you to know this, and King V now makes it a board-level oversight obligation.
- Document your data flows. Where training data came from, what consent or contractual basis covers it, where inference data lives, and who has access.
- Document human oversight. For each high-stakes deployment (hiring, credit scoring, healthcare triage, content moderation), name the human function that reviews or can override the system. Human oversight is central to every modern AI governance regime and will be a focal point of the draft policy's "human-centred deployment" pillar.
- Map your existing obligations. POPIA Section 71 (automated decision-making), Competition Act, Copyright Act, and sector regulator guidance from the Information Regulator, the FSCA, the Council for Medical Schemes, ICASA and the Department of Higher Education and Training as applicable. Those are the regulators most likely to own AI rule-making in a sector-specific model.
- Monitor official DCDT and Government Gazette publications. A replacement policy or consultation should be treated as current only when an official record is published.
Where Regula fits
Regula is an open-source code-indicator and governance-questionnaire CLI built primarily around the EU AI Act. It can flag code associated with employment, biometrics, education, law enforcement, migration, critical infrastructure, credit, and medical uses for review. Those indicators do not determine how South African law applies, and the withdrawn draft policy is not a legal classification source.
For a South African team, the practically useful starting commands are:
# Install
pipx install git+https://github.com/kuzivaai/getregula.git@main
# Inventory what you have
regula discover . # AI systems present in the project
regula inventory # AI library / model references with GPAI annotations
# Risk indicators against the same categories the Framework names
regula check . # Scan for risk indicators
regula classify --input "..." # Classify a code snippet
regula check --explain path/to/file # Explain why something was classified
# Generate compliance evidence
regula gap # Articles 9–15-style gap assessment
regula oversight # Cross-file Article 14-style oversight detection
regula conform # Annex IV-style conformity evidence pack
regula register . # Annex VIII-shaped registration packet
# Health and reproducibility
regula self-test
regula doctor
The register command produces an Annex VIII-shaped local artifact even though South Africa does not have an EU-style central AI database. The fields it captures — provider identity, intended purpose, data inputs, system status, conformity references, fundamental rights impact assessment, data protection impact assessment — are the exact fields any sector-specific South African regulator will eventually ask for. Treat the artifact as a structured record-keeping baseline, not as a legal filing.
Regula is open source, written in Python with zero production dependencies, and the entire detection ruleset is in the repository. South African teams can fork it, add SA-specific patterns (POPIA Section 71 markers, FSCA conduct standards, CMS clinical AI requirements) and contribute them back.
Frequently asked questions
What did Cabinet approve on 2 April 2026?
The draft National Artificial Intelligence Policy was published in Government Gazette No. 54477 on 10 April 2026. After fictitious references were identified, the Minister announced the withdrawal on 26 April 2026, Cabinet approved it on 5 June 2026, and Notice 3880 was withdrawn by gazette on 12 June 2026, which is the act that withdrew it. It is not current policy or law.
Has South Africa's draft AI policy been gazetted?
It was gazetted on 10 April 2026 (No. 54477, Notice 3880). The Minister announced its withdrawal on 26 April 2026 after fabricated citations were found, Cabinet approved the withdrawal on 5 June 2026, and the notice was withdrawn by gazette on 12 June 2026. No replacement consultation date is treated here as authoritative until the responsible department publishes it.
Does South Africa have an AI Act?
No. The policy Cabinet approved is a policy, not an Act. Sector-specific regulations based on the policy are targeted for the 2027/2028 financial year. Until then, AI systems are governed by existing law: POPIA Section 71 (automated decision-making), the Copyright Act, the Competition Act, the Patents Act, and the King IV / King V Codes on Corporate Governance.
Will South Africa have a single AI regulator?
Reporting on the draft policy indicates government has chosen a sector-specific, multi-regulator model rather than creating a single dedicated AI regulator. AI governance will be embedded within existing supervisory frameworks — financial services (FSCA), data protection (Information Regulator), health (Council for Medical Schemes), telecoms (ICASA), education (DHET), and others. Pragmatic, but creates a patchwork for organisations operating across sectors. This claim will be verified against the gazetted text when it publishes.
When does the public comment window open and close?
The comment window opened with the 10 April 2026 gazette and closed on 10 June 2026 at 16h00. The Minister had already announced the withdrawal on 26 April 2026, so submissions made after that date were made against a draft the department had said it would withdraw, and the withdrawal notice was gazetted on 12 June 2026, two days after the window closed. Check the responsible department for any replacement consultation.
How does POPIA apply to AI systems?
POPIA Section 71 governs decisions based solely on automated processing of personal information, including profiling. A data subject is entitled not to be subject to such a decision unless specific exceptions apply — contract conclusion/execution, protective measures, or a law or code of conduct that safeguards their interests. Any AI system deployed in South Africa that processes personal data already falls under POPIA, regardless of whether the draft AI policy has been gazetted.
What does King V require for AI governance?
King V was adopted by the Institute of Directors in South Africa on 31 October 2025 and is in force for financial years commencing on or after January 2026. It consolidates King IV's 17 principles into 13 and introduces explicit AI governance principles alongside enhanced cyber risk provisions. Governing bodies are now expected to oversee AI use and AI-related risk as a board-level matter under King V's "apply and explain" regime.
What should South African organisations do now?
Inventory AI systems in production. Document data flows and lawful bases. Identify high-stakes deployments and the human function that reviews or can override them. Map existing POPIA, Competition Act, Copyright Act, and sector-regulator obligations. Monitor official DCDT and Gazette publications for any replacement policy.
What we are tracking and what we still need to verify
The official records establish publication and withdrawal. The department subsequently appointed a seven-member expert review panel to authenticate sources and advise the redraft; that process does not make the withdrawn text current. The following questions remain unresolved as of 26 August 2026 and must not be answered from the withdrawn text:
To verify if a replacement is officially published
- Exact number and naming of pillars. Current reporting says six; the gazetted text may show a different count or structure.
- The sector-specific multi-regulator model. Whether the final text confirms this approach or hedges it, and which specific regulators are named.
- Coordination mechanism across regulators. How DCDT proposes to prevent conflicting sector rules — this is the single most important practical question for businesses operating across industries.
- High-risk category definitions. Whether the draft policy carries an explicit Annex III-style list and how it compares to the EU AI Act's categories.
- Public sector obligations. The extent to which state use of AI (welfare, policing, border control) is treated differently from private sector deployment.
- Alignment with the AU Continental AI Strategy and SADC digital frameworks. Not addressable until the text is in the public domain.
This page will treat a replacement as current only after an official publication can be checked. To report a new primary record or a correction, open an issue.
Sources
- Post-Cabinet media briefing (2 April 2026) — Minister in the Presidency Khumbudzo Ntshavheni, Pretoria. Announcement of Cabinet approval of the draft National AI Policy for public comment. Confirmed via live broadcast coverage on Sowetan and Business Day.
- Michalsons — Nathan-Ross Adams (3 April 2026), "South Africa's draft national AI policy open for public comment." Source for the six-pillar structure, sector-specific multi-regulator model, 60-day comment window, 24 February 2026 parliamentary briefing, SEIAS clearance and DG cluster concurrence, and the 2026/2027 and 2027/2028 targets. To be verified against the gazetted text.
- Department of Communications and Digital Technologies — the lead department. Web: www.dcdt.gov.za. Tel: +27 12 427 8000.
- POPIA (Protection of Personal Information Act 4 of 2013) — Republic of South Africa. Section 71 governs automated decision-making and profiling.
- King V Code of Corporate Governance (October 2025) — Institute of Directors in South Africa. Adopted 31 October 2025, in force for financial years commencing on or after January 2026.
- October 2024 DCDT National AI Policy Framework — the precursor document published for public comment (closed 29 November 2024). Useful historical context; superseded in focus by the April 2026 draft policy.
If you spot an error on this page, open an issue on github.com/kuzivaai/getregula or email a correction. We would rather be told than be wrong.
Where does your own system stand?
The browser assessment is free, needs no account, and runs on your device. When the answer turns on something it cannot see, it says so and names the fact, rather than rounding the gap into a score. That makes it a starting point for review, not a legal determination.
Start the free assessment →