While African governments race to establish centralized AI oversight bodies, South Africa is bucking the trend with a radically different approach that distributes responsibility across existing regulatory agencies.
On April 2, 2026, the South African cabinet released a draft AI policy for public comment. The document, originally dated October 24, 2024, represents a sharp departure from the centralized models emerging across the continent.
"The AI policy aims to ensure that both the benefits and risks brought by AI are evenly distributed across society and generations," the South African Cabinet said in a statement.
No Super-Regulator in Sight
The Department of Communications and Digital Technologies (DCDT) is spearheading the policy, which is scheduled for full implementation in the 2027/2028 financial year. Notably, how dramatically this differs from regional trends.
Nigeria's proposed National Digital Economy and E-Governance Bill follows the EU AI Act playbook with prescriptive, risk-based oversight. High-risk AI systems in surveillance, finance, and public administration would require licensing, audits, and annual impact assessments under a centralized structure.
Kenya's 2026 AI bill takes similar centralized approach but adds political safeguards ahead of elections. The legislation targets synthetic media and AI-driven manipulation with criminal penalties for non-consensual deepfakes, while maintaining innovation flexibility through regulatory sandboxes.
Sector-Specific Expertise Takes the Lead
Instead of building new institutions, South Africa is empowering existing regulators within their domains of expertise. The Financial Sector Conduct Authority (FSCA) and the South African Reserve Bank will oversee financial AI systems. The South African Health Products Regulatory Authority (SAHPRA) gets responsibility for AI in medical diagnostics.
The Information Regulator retains its role as primary enforcer of data privacy under the Protection of Personal Information Act (POPIA). This distributed approach reflects a core philosophy: regulators closest to specific industries understand their unique risks best.
A mining regulator understands mining complexities. A financial regulator knows financial systems inside out. Why create overlapping bureaucracy when domain expertise already exists?
Four-Tier Risk Framework
South Africa's policy centers on risk-tiered regulation that treats AI systems differently based on their potential impact. The framework establishes four categories: unacceptable, high, limited, and minimal risk.
High-risk applications in hiring, lending, and healthcare face intensive scrutiny including audits, impact assessments, and mandatory human oversight requirements. Lower-risk applications operate under lighter regulatory touch.
This tiered approach concentrates regulatory resources where potential harm is greatest rather than applying blanket restrictions. It sends clear signals about acceptable AI use while preserving innovation space for beneficial applications.
Coordination Over Control
What strikes me about South Africa's approach is its emphasis on coordination rather than control. While other African nations build centralized AI oversight structures, South Africa is betting that distributed expertise with coordinated oversight delivers better outcomes.
The policy reflects practical governance thinking. Rather than creating new institutions that need years to develop sector-specific knowledge, South Africa leverages existing regulatory capacity while ensuring agencies work together.
As African nations grapple with AI governance challenges, South Africa's decentralized model offers an alternative path that prioritizes flexibility over centralized authority. Whether this approach proves more effective than centralized oversight remains to be seen, but it represents a distinctly different vision for AI governance on the continent.
