South Africa's AI rulebook is three generations behind where the technology is going
Notes from Tech Talk with Vodacom on why the redraft has to be built for a world of agentic AI, not the one we have just left.

Video interview: https://youtu.be/2xp8L13JARI
Follow me on LinkedIn: https://www.linkedin.com/in/johanosteyn/
We are trying to write a rulebook for artificial intelligence in South Africa, and we are doing it three generations behind where the technology is going. I sat with Koni Mudau this week on Tech Talk with Vodacom to work through what that means in practice, and the answer is not comfortable.
CONTEXT AND BACKGROUND
Our draft National AI Policy was gazetted in April and withdrawn later the same month after it emerged that several of its citations had been fabricated — references to journal articles that do not exist. An expert panel is now rebuilding it. I sit on the group advising government on this work, so I want to be careful here. The withdrawal was the right decision once the problems in it were found. Criticising from the sidelines helps nobody. But the incident is worth thinking about honestly, because the lesson is not that the department is uniquely careless. The lesson is that every institution using generative AI for serious work — governments, universities, banks, law firms, my own advisory practice — is exposed to the same failure mode, and most have not built the checks to catch it.
The specific charge against the draft matters. The problem was not false claims in the ordinary sense of a factual dispute. The problem was fabricated citations: authorities that do not exist, produced by a language model and passed through review without verification. This is a well-documented behaviour of the current generation of these tools. In my own daily use, I would estimate that around one in five citations they produce is wrong in some way. That is my working impression from sustained use, not a peer-reviewed figure, and I would not want it treated as one. But it is stable enough across my own work that I now assume every AI-generated reference is guilty until verified.
INSIGHT AND ANALYSIS
That is the immediate story. It is not the important one. The important one is what the policy is being written for. Generative AI — the chatbots most South Africans have met over the past two years — is the technology of the last three years. Agentic AI is the technology of the next three. An agent is a system given a goal, book me the cheapest return flight to Cape Town on Tuesday, reconcile these invoices against the ledger, draft and send the follow-up emails, and left to plan the steps, choose the tools and execute the actions itself. The change from a chatbot to an agent is the change from asking for advice to handing over the keys. It moves the governance question from what the system says to what it does, and to whom liability attaches when it acts wrongly at speed and at scale.
Our current draft was not written with that world in mind. It proposes a set of new institutions, a National AI Commission, an Ethics Board, a regulatory authority, an ombudsperson, a safety institute, and a set of principles for responsible use. Those are sensible starting points for the world of large language models. They are not, on their own, an answer to a world in which an agent inside a bank misprices ten thousand policies overnight, or an agent inside a hospital reorders a patient’s medication because it has been told to optimise for cost.
Behind agents sits the quantum horizon. I told Koni I believe we are perhaps five years from quantum computing being commercially disruptive at scale. That is a contested view. Some serious people in the field would say ten, some would say fifteen, and they may be right and I may be wrong. What is not contested is that when it arrives, it breaks the mathematical assumptions underneath most of the encryption currently protecting our financial system, our health records and our national identity infrastructure. A policy that does not at least name that horizon is a policy that will need to be reopened before it has finished being written.
IMPLICATIONS
None of this is an argument against the current process. It is an argument for a different shape of one. Three things follow. The first is that South Africa cannot simply lift the EU AI Act or the American executive orders and translate them into local statute. Those instruments were written for economies with capital markets, research infrastructure and public administration that ours does not have, for a population profile that ours does not share. We are a country of more than sixty million people with an unemployment rate above thirty per cent and a public sector already struggling to deliver on the mandates it has. A rulebook that assumes European enforcement capacity will not survive first contact with the Auditor-General’s report.
The second is that the policy needs to be built to be revised. What we are drafting now should have an explicit review cadence written into it, twelve to eighteen months, not five years, and a mechanism for absorbing the agentic and quantum shifts as they become concrete rather than pretending they are already stable enough to legislate for. Policy that ages well in this field will be policy that expects to be edited.
The third is the point I keep returning to in my own work. In any process where a machine contributes to a decision, a human being has to remain a net contributor to that decision, and accountability has to sit with a named person who can explain and defend it. Delegating the work is legitimate. Delegating the answerability is not. That is the standard the withdrawn draft failed against. It is the standard the redraft has to be built to.
CLOSING TAKEAWAY
We are not going to catch up to the technology. Nobody is. The honest question is whether what we write next is designed for a world that has already moved on, or for the one arriving. That is the conversation the redraft has to have, and it is the one I hope the sector will help government have well.
Watch the full episode: https://now.vodacom.co.za/podcast/regulating-ai-in-south-africa/
Johan Steyn is a prominent AI thought leader, speaker, and author with a deep understanding of artificial intelligence’s impact on business and society. He is passionate about ethical AI development and its role in shaping a better future. Find out more about Johan’s work at https://www.aiforbusiness.net




Comments