Phone your bank, medical aid provider or insurer, and there is a good chance the voice on the other end may not be human.

Bruce von Maltitz | image supplied
Increasingly, AI-powered systems are handling customer interactions, asking for ID numbers, accessing account details and retrieving information from previous conversations.
Millions of South Africans are already sharing personal information with AI systems, yet few stop to ask a simple question: who decided that these systems could be trusted with it?
For the moment, the honest answer is that nobody official did. South Africa currently has no law governing artificial intelligence. We were meant to have the beginnings of one by now.
South Africa's AI policy has been delayed
But the draft National AI Policy that was gazetted in April was withdrawn within weeks, after it emerged that the document meant to govern AI had itself been written with AI.
It would be easy to score points off that. I would rather draw a different lesson, because it is exactly what happens when a powerful tool is put to work, and nobody checks its output.
The same failure can occur in a contact centre, a loan department or a clinic, and it is the person on the other end who carries the cost. A seven-member expert panel is now rebuilding the policy. Its report is due in August, a revised draft reaches Cabinet in November, and public consultation is unlikely to reopen before January 2027.
So the rules most of us expected this year have slipped, comfortably, into next. That leaves a window of more than a year in which AI keeps answering calls, helping to approve applications and handling personal data with no official national framework behind it.
Regulation should not be rushed
Here my view may be less popular than you would expect from someone arguing for oversight. I do not believe the answer to this gap is to shove a thick stack of legislation into it.
Government has signalled that it will fold AI into the regulators we already have rather than build a single new one, and that instinct is sound. Heavy, hurried rules tend to freeze the very investment and experimentation a developing economy needs, and they seldom deliver what they promise.
Consider the popular notion that keeping a human “in the loop” will protect jobs. It isn’t likely to do so, at least as a principle by itself. Human oversight is a real safeguard for the consumer, and I back it for that reason.
As an employment-protecting or advancing policy, it is a bit more like wishful thinking. Jobs are protected by incentives, retraining and serious skills development, not by a clause requiring a person to hover near a screen.
Businesses cannot simply wait
If the law is a year away and shouldn’t be rushed, the question becomes what a credible operator does in the meantime. Waiting is itself a choice, and it isn’t the best one.
The alternative is to govern yourself against a standard that already exists and that the rest of the world recognises. One option is ISO/IEC 42001, introduced at the end of 2023 as the first international standard specifically focused on AI management systems.
It provides a structured framework for policies and controls covering how AI is designed, deployed, monitored and corrected when problems arise. It does not stand in for the law South Africa is still writing.
What it can do is give organisations a practical framework for demonstrating that their AI systems are being managed deliberately rather than being left to operate without clear accountability.
Trust matters in high-risk sectors
That matters because the sectors where AI has the most to offer in South Africa – banking, insurance, healthcare and public services – are precisely the ones where mistakes can have serious consequences.
These organisations are dealing with sensitive personal information and decisions that can directly affect people's finances, access to healthcare or interactions with government.
The question is therefore not simply whether an organisation is using AI. It is whether it can explain how that AI is being governed, what controls are in place, who is accountable when something goes wrong and how the system is monitored over time.
Certification against an international standard is one possible way of demonstrating that discipline, but organisations do not need to wait for legislation – or certification – before putting proper controls in place.
They can establish clear policies, conduct risk assessments, document how AI systems are being used and ensure that people remain accountable for consequential decisions.
The wait should be used to prepare
The national rulebook will arrive in 2027, and it should be all the better for the care now being taken over it. Organisations should not spend the intervening period standing still.
They can build the discipline themselves, so that when the rules do land, they are already operating within a culture of responsible AI use.
The voice that answers your next call should have earned the right to ask for your ID number. Increasingly, that will depend not only on what the technology can do, but on whether the organisation behind it can show how it is being governed.