We Are Drafting Policy for a Technology That Has Already Moved On
The withdrawn draft understood large language models. We now live in the agentic era, and quantum computing is next.

Sign up for my Substack daily AI newsletter here.
See my AI Training course portfolio for corporate Business Leaders here.
Follow me on LinkedIn: https://www.linkedin.com/in/johanosteyn/
Minister Solly Malatsi has promised a clean draft of South Africa’s National AI Policy by March. After the withdrawn version was found to contain fabricated academic references, that commitment is welcome, and removing the hallucinated citations will repair the credibility problem. It will not repair the deeper one. The document that was pulled had been conceived in the world of large language models, systems that generate text on request and then stop.
That world has already passed. We now deploy agents that act, hold credentials and make commitments in an organisation’s name, and behind them quantum computing sits close enough that serious institutions are already planning for it. A policy written for the previous generation, however carefully its footnotes are checked, will arrive to govern a technology that has moved on. I write as a participant in this policy process, which is precisely why the point needs making.
CONTEXT AND BACKGROUND
The failure itself is well documented. The eighty-six page draft was gazetted on 10 April 2026 and carried sixty-seven references, at least six of them fictitious. Malatsi withdrew it within weeks, the department conceding that the most plausible explanation was that AI-generated citations had been included without proper verification. Two officials were suspended. Home Affairs was meanwhile found to have more than one hundred fabricated references in its Revised White Paper on Citizenship, Immigration and Refugees, and suspended two officials of its own. The problem was never confined to one department.
What has drawn less attention is what the withdrawn document actually proposed. Its architecture was institutional and static: five new oversight bodies, among them a National AI Commission, an Ethics Board and a Safety Institute, together with an insurance fund modelled on the Road Accident Fund to compensate those harmed by AI.
INSIGHT AND ANALYSIS
That is a reasonable design for a technology that produces outputs a human then reviews. It is the wrong design for a technology that acts on its own authority. Picture an agent inside a municipality that reads an application, checks it against three databases, approves a permit, notifies the applicant and updates the register, without a person ever touching the file. Nothing was generated for review. Something was done. An insurance fund can compensate a citizen harmed by that decision. It cannot tell you which of thousands of automated actions caused the harm, which system granted the agent its authority, or who inside the administration is answerable for it. The governance question moves from adjudication after the event to authorisation before it, and the withdrawn draft was not built to ask it.
Behind the agents, quantum is coming for the foundations. Much of the cryptography protecting South African banking, revenue and identity systems rests on mathematical assumptions that quantum computing will eventually overturn.
I have previously written about this, arguing that quantum is the next meal for an already ravenous AI industry, and that African leaders should position themselves as participants rather than passive consumers. A national AI policy silent on that horizon is not merely incomplete. It is planning around a threat model with a known expiry date.
IMPLICATIONS
None of this argues for delay. South Africa has already spent more than two years on this document while the World Bank counts eighty-nine countries with published national AI strategies. We are late, and lateness carries a cost. The argument is for writing the right document quickly rather than the old document carefully.
Three choices would make the difference. Policy should be drafted against capabilities rather than named technologies, so that a rule about autonomous action holds whether the actor is a language model, an agent, or something not yet built. It should assume systems that act, which puts authorisation, identity, logging and revocation at the centre of the document rather than in an annexe. And it should carry a scheduled revision cycle, because any framework that takes three years to write and ten to amend will be obsolete before it is enforced.
CLOSING TAKEAWAY
The fabricated citations were a humiliation and they deserved the response they received. They were also a distraction. The greater risk is that we now spend another year producing an immaculate version of a document whose assumptions expired while it was being drafted. South Africa has no room left to waste. The technology has already moved from systems that generate to systems that act, and it will move again. Our task is not to deliver a clean policy for the world of two years ago. It is to deliver a usable one for the world now arriving, built so that it can be changed when that world changes again.
Author Bio: Johan Steyn is a prominent AI thought leader, speaker, and author with a deep understanding of artificial intelligence’s impact on business and society. He is passionate about ethical AI development and its role in shaping a better future. Find out more about Johan’s work at https://www.aiforbusiness.net




Comments