Thursday, 24 September 2026
ZAR/USDR16.440.54%. Rand weaker against the US dollar
ZAR/EURR18.680.17%. Rand weaker against the euro
ZAR/GBPR21.730.13%. Rand weaker against the pound
Regulatory & Policy

South Africa Holds Off on AI Financial Rules Until Global Watchdog Reports Back

South Africa Holds Off on AI Financial Rules Until Global Watchdog Reports Back

South Africa’s financial regulators are deliberately waiting for the world’s top standards body to finish its own homework before writing a single rule on artificial intelligence, according to Bloomberg reporting. The Financial Sector Conduct Authority’s commissioner said the country wants to stay aligned with the Financial Stability Board, the Basel-based body coordinating global financial regulation, which is due to publish its own AI principles next month as a formal G20 deliverable under this year’s US presidency of the forum.

“It’s good for us to be waiting for that because we want to be aligned,” the commissioner said, a line that doubles as a statement of strategy: rather than drafting South African-specific AI rules in isolation and risking a mismatch with whatever the FSB eventually recommends, the country’s regulators are holding off until there is a global reference point to build against.

That reference point will feed directly into a joint discussion paper the South African Reserve Bank, the Prudential Authority and the FSCA are preparing together, which is expected to include specific consideration of agentic AI, systems capable of taking autonomous action rather than simply generating a recommendation for a human to approve. The two authorities have already published one paper examining how South African financial institutions are adopting AI today, and the planned follow-up will set out how governance principles around that adoption should actually work in practice.

Principles, not rules, for now

The approach the regulators have signalled is principles-based rather than rules-based, a distinction that matters more than it might sound. A rules-based regime spells out specific, prescriptive requirements, this system must log its decisions this way, that model must be tested against this benchmark, which is easier to enforce but tends to age badly against a technology moving as quickly as generative and agentic AI currently is. A principles-based approach instead sets out the outcomes regulators want, fair treatment of customers, explainable decisions, robust risk controls, and leaves financial institutions more latitude in how they get there, at the cost of more subjective enforcement.

South Africa is not unique in reaching for that trade-off. Regulators in several major markets have made the same choice for the same reason: AI capability is evolving faster than any legislative or regulatory drafting cycle can realistically track, and a narrow rules-based framework risks becoming obsolete before it is even fully implemented. The FSB’s own work, coordinating input from securities regulators, central banks and prudential authorities across dozens of countries, is meant to produce a common baseline other jurisdictions can adapt rather than each writing an AI rulebook from scratch.

For South African banks, insurers and fintechs already deploying AI in lending, fraud detection and customer service, the practical effect of this wait-and-see approach is continuity rather than disruption: nothing currently in production needs to change because of a rule that has not yet been written. But it also means institutions building new AI-driven products over the next year are doing so without a clear regulatory target to design against, beyond the broad principles already flagged in the regulators’ first paper. That is a real cost for compliance teams trying to build systems today that will still pass muster once the eventual framework lands, even if it is one South Africa’s regulators have judged worth paying in exchange for not locking the country into rules the rest of the world may later abandon.

The timeline itself is worth tracking closely. With the FSB’s report due next month, South Africa’s own discussion paper is likely to follow within the next few reporting cycles, though the regulators have given no fixed date. Financial institutions operating in the country would do well to treat the FSB’s own publication, whenever it lands, as the real starting gun for South Africa’s AI compliance clock, rather than waiting for a local rulebook that is explicitly designed to follow it. This regulatory caution sits alongside a broader pattern of South African institutions treating AI adoption itself as outpacing the policy environment meant to govern it, a tension this site has covered before in the context of a cybersecurity breach that exposed gaps in the country’s wider AI policy framework.

There is also a harder-nosed reason for South Africa’s regulators to wait rather than move first. Writing a bespoke national AI framework ahead of the FSB’s own principles risks producing rules that conflict with whatever the global standard eventually settles on, forcing a costly rewrite just as local institutions finish adapting to the first version. South Africa’s banking sector is also unusually internationally exposed relative to its size, with several major banks operating subsidiaries or branches across the rest of the continent and beyond, which raises the stakes of drifting out of step with international norms: a bank managing AI governance across multiple jurisdictions has a strong commercial interest in those jurisdictions’ rules looking similar enough to administer from one compliance framework rather than a patchwork of local variations.

The FSCA and Prudential Authority’s own prior paper on AI adoption in the financial sector already flagged several areas likely to feature in the eventual framework: model explainability, where a customer or regulator needs to understand why an AI system made a particular lending or claims decision; third-party risk, since many South African institutions license AI models and tools from foreign vendors rather than building them in-house; and concentration risk, the possibility that if enough of the industry relies on the same handful of underlying AI models or cloud providers, a single outage or flaw could ripple across the sector at once. Agentic AI, the specific focus flagged for the coming joint discussion paper, adds a further wrinkle: a system that can independently execute a transaction or make a decision, rather than simply flagging one for a human to approve, blurs the line between a tool a bank uses and an entity a bank has effectively delegated authority to, a distinction current regulatory frameworks were never built to draw.