
What POPIA actually asks of an AI programme, and how to answer it.
A practical read on governing AI in a regulated South African enterprise.
South Africa does not have an AI Act, and it will not get one soon. The Draft National AI Policy was gazetted in April 2026 and then withdrawn within weeks, after it emerged that a portion of its academic citations were fabricated, the kind of error a careless AI tool produces and a human is supposed to catch. The irony is the lesson. Until a dedicated law arrives, and the timeline now stretches towards 2027 and beyond, the rules that already bind your AI programme are the ones in the Protection of Personal Information Act.
POPIA was written before the generative wave, but it applies the moment your system touches personal information. Here is what it actually asks.
Automated decisions need a human in the loop
Section 71 is the provision that speaks most directly to AI. It protects people from decisions made solely by automated processing that profile them and carry legal or similarly significant effects, think credit scoring, insurance pricing, or shortlisting a candidate. You are not barred from using AI for these. You are required to keep meaningful human oversight, or to fall inside a narrow set of exceptions, and to let the affected person make representations and understand how the decision was reached. If a model declines someone's loan, you must be able to explain why, in terms a person can contest.
You must be able to explain and document
That right to contest only works if the system is explainable. A model you cannot interrogate is a compliance problem, not just a technical one. POPIA's accountability and openness principles mean you need records of what the system does, what data feeds it, and where that data flows. A data protection impact assessment, run before a high-impact system goes live, is the practical way to show this. It is not yet strictly mandatory under POPIA, but it is fast becoming the expected standard, and the regulators are signalling as much.
Know where your data goes
Most AI tools run in the cloud, often outside the country. POPIA limits cross-border transfers of personal information to specific conditions, such as the person's consent or equivalent protection at the destination. If you do not know which region your AI assistant processes data in, you cannot answer the question POPIA asks. For a regulated enterprise, that single unknown can stall an entire deployment.
The regulators are already moving
This is not theoretical. In November 2025, the Financial Sector Conduct Authority and the Prudential Authority published the first comprehensive picture of AI in South African financial services, drawn from more than 2,100 institutions. Their message was direct. Where AI affects customers, disclose it. Where automated decisions are involved, be ready to prove compliance. And they confirmed they will coordinate with the Information Regulator to keep AI aligned with POPIA's fairness and privacy principles. Penalties under POPIA reach up to ten million rand, alongside reputational cost that is harder to price.
What a defensible programme looks like
None of this requires waiting for the AI Act. A programme that would satisfy POPIA today does a few things deliberately. It keeps a human accountable for every consequential decision. It can explain its systems in plain language. It assesses impact before deployment, not after. It knows where its data lives. And it treats privacy as a design choice, built in from the first prompt rather than bolted on before launch. Build that now, and whatever the final policy says, you will already be most of the way there.
Sources: Protection of Personal Information Act 4 of 2013 (s71, s72); DCDT National AI Policy Framework (Aug 2024) and Draft National AI Policy, Notice 3880 of 2026 (published 10 April 2026, withdrawn 26 April 2026); FSCA & Prudential Authority, Artificial Intelligence in the South African Financial Sector (Nov 2025).


