There is a category of failure so neatly self-describing that it barely needs a commentator, and South Africa’s first attempt at a national artificial intelligence policy landed squarely in it. The document meant to set the rules for how the country uses AI was pulled after it emerged that some of the academic sources it leaned on had been invented, most plausibly by an AI.
The Department of Communications and Digital Technologies published the Draft South Africa National Artificial Intelligence Policy for public comment on 10 April 2026. News24 then reported that several of the academic journals in its reference list were completely fictitious. On 26 April, according to the government’s own news service, Communications and Digital Technologies Minister Solly Malatsi announced that the draft was being withdrawn.
“The most plausible explanation is that AI-generated citations were included without proper verification,” Malatsi said. “This failure is not a mere technical issue but has compromised the integrity and credibility of the draft policy.” He added that “there will be consequence management for those responsible for drafting and quality assurance”.
The withdrawal was made formal in the Government Gazette on 12 June 2026, according to ITWeb, which reported that the policy was “withdrawn in its entirety effective from the date of publication” and put the number of hallucinated references at as many as six. The public comment window had been due to close two days before that. ITWeb also reported that two officials were placed on precautionary suspension while the department investigated. Those are the department’s own actions as reported, and the outcome of that investigation has not been made public.
What the withdrawn draft would have created
This matters considerably more than the embarrassment, because the draft was not a minor document. As reported by Engineering News, it proposed building a set of new institutions: a National AI Commission, an AI Ethics Board and an AI Regulatory Authority, alongside tax incentives intended to draw private-sector money into AI collaboration.
For a business owner, that is the difference between a policy paper and a line item. New regulators mean registration, reporting and someone to answer to. Tax incentives mean a possible offset for companies that qualify. Neither exists yet, and the shape of whatever replaces the withdrawn draft is not public.
There is a real tension in the record that deserves naming rather than smoothing over. Legal analysis published before the withdrawal, including by Baker McKenzie, described the government’s direction as deliberately avoiding a single AI regulator in favour of spreading oversight across the authorities that already supervise each sector. The withdrawn draft, on the reported description of it, proposed a dedicated AI Regulatory Authority. Which of those two approaches the revised version follows is one of the more consequential open questions for any regulated business, and it cannot be answered until the new draft is published.
When enforceable rules actually arrive
The department is working to a revised timeline. ITWeb reported a target of taking the new policy to Cabinet by November 2026, with publication for public comment in January 2027. Sector-level implementation would follow after that, which puts genuinely enforceable AI-specific obligations somewhere in 2027 and beyond.
Treat those dates as targets rather than commitments. The original timeline already slipped once, for reasons nobody had pencilled in, and a policy that has to clear Cabinet before it can even be published for comment has at least one more delay point built into it.
The rules that apply while the rulebook is missing
The most common misreading of a regulatory gap is that it amounts to a permission slip. It does not. A business using AI in South Africa today is already governed by the law that existed before anyone deployed a model.
The Protection of Personal Information Act does not care whether a human or a model processed someone’s personal information, only that it was processed lawfully and that the responsible party can account for it. Consumer protection law does not soften because a chatbot made the representation. Employment law does not change because a screening tool produced the shortlist. In each case the obligation sits with the organisation rather than with the tool, and an AI-specific policy would refine that position rather than invent it.
That is also the practical answer for an SME owner wondering what to do before January. The compliance work that will matter under any version of the policy is the work that already matters: knowing what personal data your systems touch, being able to explain how a decision affecting a customer or an employee was reached, and keeping a human accountable for anything that goes out under your name.
The lesson the department learned in public
Malatsi, in remarks reported by Engineering News, framed the incident as a demonstration of why vigilant human oversight of artificial intelligence is critical. That is the right lesson, and an uncomfortable one to have to learn at national scale, in a document about AI governance, on your own department’s letterhead.
The failure mode is not exotic. A model asked for supporting references will produce references, and they will look correct, because producing plausible text is the whole of the job. The control that catches it is not technical sophistication. It is somebody opening the citation and checking that the journal exists. Every business now feeding AI output into a proposal, a report or a client deliverable is running the same risk on a smaller stage, with the same fix available.
The policy will arrive eventually. The habit it failed to demonstrate is available immediately, and costs nothing beyond the time it takes to look.
This is the first of three frontier AI stories this site covered in the same week: OpenAI’s GPT-6 Astra, Google’s Gemini 3.8 Flash price rise and Anthropic’s US-only defender access all landed while this policy sat withdrawn. For the compliance obligations that already apply regardless of when a finished policy arrives, see our practical guide to AI tools for small business.


