In a short piece for the Sowetan, journalist Lars Gumedé points out that a recent cybersecurity incident has laid bare the absence of a coherent artificial intelligence (AI) regulatory framework in South Africa. The article does not name the companies directly involved, but it notes that both large firms and small and medium enterprises (SMEs) were affected, underscoring that the problem is not limited to any single sector.
The term artificial intelligence refers to computer systems that can perform tasks normally requiring human judgement, such as image recognition or language translation. Cybersecurity, on the other hand, is the practice of protecting computers, networks and data from unauthorised access or damage. When AI tools are deployed without clear rules, they can become vulnerable entry points for hackers, a risk that the recent breach has made painfully clear.
According to Gumedé, the incident revealed that South Africa currently relies on a patchwork of existing laws, notably the Protection of Personal Information Act (POPIA), to govern data security, while there is no dedicated legislation that addresses the unique challenges posed by AI. This regulatory gap means that businesses, especially SMEs with limited resources, may struggle to implement the safeguards required to protect AI-driven systems.
Why the gap matters for SMEs
For a small business owner, the cost of a cyber-attack can be devastating. Lost data, downtime and reputational damage can quickly erode profit margins. When AI is part of the technology stack, the stakes rise because AI models often rely on large data sets that, if compromised, can expose sensitive customer information. Without clear guidance on how to secure AI applications, SMEs may either over-invest in expensive solutions that do not address the core risk, or under-invest and leave themselves exposed.
The article cites the Department of Communications and Digital Technologies as the body responsible for drafting AI policy, but it notes that progress has been slow. A draft national AI strategy was discussed in 2023, yet no final legislation has been published. This delay leaves companies to interpret existing regulations on a case-by-case basis, a process that can be both time-consuming and legally uncertain.
Industry observers have warned that the lack of a clear AI framework could hinder South Africa’s ambition to become a regional hub for tech innovation. If foreign investors see regulatory uncertainty, they may look elsewhere for more predictable environments. For local entrepreneurs, the message is clear: they need to stay ahead of the curve by adopting best practices in cybersecurity, even in the absence of specific AI rules.
Best practice advice includes conducting regular vulnerability assessments, encrypting data used by AI models, and training staff to recognise phishing attempts, the most common entry point for cyber-criminals. While these steps do not replace formal regulation, they can reduce the immediate risk highlighted by the recent breach.
Gumedé’s piece ends with a call for policymakers to accelerate the development of AI-specific legislation. Until then, the burden of protection falls on individual businesses, many of which may lack the expertise or budget to implement robust safeguards.
South Africa does not yet have a dedicated law governing artificial intelligence, relying instead on the Protection of Personal Information Act for the data-privacy dimension of an incident like this, while government’s own AI policy framework remains at a comparatively early, non-binding stage. That puts the country behind jurisdictions such as the European Union, whose AI Act imposes binding obligations on how higher-risk AI systems are developed and deployed. government’s own published AI policy framework documents outline the direction of travel, though implementation timelines remain unclear. For related coverage, see this site’s Tech and Telco coverage.



