Why South African Associations Can’t Wait for an AI Act to Get AI Governance Right
Somewhere in your association right now, someone is probably using AI. Drafting a member newsletter. Summarising a board pack. Triaging a complaint. Answering a CPD query. It’s rarely announced and rarely malicious. It’s just someone trying to get through a Tuesday.
Chances are, no one has decided who owns that. No policy says what member data may go into a tool like ChatGPT. No one has mapped which decisions still need a human hand on them. If your board asked you tomorrow how AI is being used across the organisation, and what safeguards are in place, could you answer with confidence?
For most South African association leaders, the honest answer is no. Not because they’ve been careless, but because AI governance has quietly become urgent faster than most organisations have had time to notice.
The obligation already exists, with or without an AI Act
It’s tempting to treat AI governance as something to plan for once South Africa finalises its national AI legislation. That would be a mistake. Two frameworks already govern how your association must handle AI today.
POPIA Section 71 doesn’t ban automated decision-making, but it requires safeguards wherever AI-influenced decisions carry legal or similarly significant effects on a person: membership approvals, disciplinary triage, credential verification, CPD penalties. Those safeguards are notification, explanation, human review, and accountability that stays with your organisation, not the vendor whose tool you used.
King V adds the second layer. It requires the governing body to set strategic direction for technology use, oversee technology-related risk, and ensure AI is used ethically and responsibly. That accountability is explicitly non-delegable. It sits with the board, whether or not the board has ever discussed AI.
Neither of these frameworks is emerging or aspirational. Both apply now, regardless of what any future AI Act eventually says.
What happens without governance: a case in point
If you want proof that this isn’t a theoretical risk, look no further than the government department tasked with writing South Africa’s own AI policy.
In April 2026, the Department of Communications and Digital Technologies gazetted South Africa’s Draft National AI Policy for public comment, having cleared Cabinet weeks earlier. Within sixteen days, the department was forced to withdraw it. Journalists checking the document’s references found that at least six of its 67 academic citations were fabricated: journals that don’t exist, or articles falsely attributed to journals that had never published them. The most credible explanation offered by the responsible minister was that a generative AI tool had been used to draft sections of the policy, and its output had gone unverified all the way through to gazetting. Officials were placed on suspension, and an independent panel was appointed to rebuild the draft, with no confirmed timeline.
The irony is instructive, but the lesson matters more than the irony. This wasn’t a failure of the technology. Generative AI did exactly what generative AI does: it produced fluent, confident, well-formatted text that was never true. The failure was that no one in the process owned the job of checking it before it carried the department’s name. That is a governance failure, not a technology one, and it is precisely the failure mode that a structured governance framework exists to prevent.
If a national department, with legal drafters and policy specialists at its disposal, can let ungoverned AI output reach an official gazette, no association should assume it is naturally immune.
What governance actually requires
Good AI governance isn’t a ban on AI tools, and it isn’t a technical project. It’s a small set of structural questions, answered clearly and in advance:
Who owns AI-related decisions, and can they defend those decisions to the board? What member data is allowed into which tools, and where are the boundaries? What is the organisation’s risk posture, and where does POPIA or King V require a human check? Do staff understand where the lines sit? And critically, is there a process step where AI output gets verified before it goes out the door?
That last question is exactly where the national AI policy came undone. It’s also usually the cheapest gap to close, once someone has actually mapped it.
Why the next few years matter
South Africa doesn’t yet have finalised AI legislation, and after the events of April 2026, it’s fair to expect that timeline to lengthen rather than shorten. That absence of legislative certainty is not a reason to wait. POPIA and King V already carry the weight of accountability, boards are starting to ask questions their executives can’t yet answer confidently, and the organisations that build governance maturity now will be the ones setting the standard the sector eventually regulates toward, rather than scrambling to catch up to it.
AIRA (AI Governance & Readiness for Associations) was built for exactly this moment: a structured, facilitated way for South African member-based organisations to understand where they stand, govern AI with confidence, and build a roadmap for responsible adoption, anchored in King V and POPIA rather than generic AI hype.
You don’t need a finished AI Act to start. You need a clear picture of where your organisation actually stands today.
Start with the free AIRA AI Readiness Checklist to get a directional view of your governance position in fifteen minutes: AIRA Checklist
Or book a free 30-minute conversation directly: meetings-eu1.hubspot.com/jerome-wiehe