South Africa's Information Regulator Warns Against AI Privacy Gaps
The Information Regulator of South Africa is calling for stricter AI audits and a national policy to protect human dignity and data privacy.
The Information Regulator of South Africa is challenging the rapid integration of artificial intelligence, biometric technologies, and automated decision-making systems across the country. Chairperson Pansy Tlakula stated that the current technological landscape has evolved significantly since the enactment of the Protection of Personal Information Act (POPIA) and the Promotion of Access to Information Act (PAIA).
Regulators identified several critical failures in the current AI ecosystem, including a lack of a national AI policy and a widespread failure by organizations to implement privacy by default. Tshepo Boikanyo, the executive for POPIA, noted that AI models often contradict existing law by retaining personal information beyond its intended purpose.
Agency executives emphasized that data protection is a matter of human dignity rather than a technical ICT issue. Mukelani Dimba called for thorough audits of AI system development to ensure compliance, arguing that regulators are often only invited to engage with companies via sandboxes after systems have already scaled, which he described as being too late.