Governing AI before the regulation arrives

Seven new institutions, and nobody to check a footnote

South Africa's draft National AI Policy proposed an AI Safety Institute, an Ethics Board and an AI Regulatory Authority. It was withdrawn sixteen days after gazetting because its own citations were fabricated. The failure was not the AI.

On 10 April this year, South Africa published its draft National AI Policy in the Government Gazette.1 On 26 April, the Minister withdrew it.2

Sixteen days.

The reason is the part worth sitting with. News24 checked the document’s reference list and found citations to work that does not exist — attributed to real journals, credited to real academics who had never written on the subject. At least six of the 67 academic references were fabricated. Editors at the South African Journal of Philosophy, AI & Society, and the Journal of Ethics and Social Philosophy each independently confirmed that articles attributed to their publications had never appeared in them.3

Minister Solly Malatsi’s explanation was direct: AI-generated sources had been included “without proper verification”, a failure that compromised the document’s “integrity and credibility”.2

I want to be careful about what the lesson here actually is, because the obvious reading is the wrong one.

The obvious reading is wrong

The easy conclusion is that AI was used where it shouldn’t have been. I don’t think that holds. Drafting policy with AI assistance is reasonable, and pretending otherwise is a position nobody is going to hold for long.

Something else failed.

Look at what the draft proposed to build: a National AI Commission. An AI Ethics Board. An AI Regulatory Authority. An AI Ombudsperson. A National AI Safety Institute. An AI Insurance Superfund. An Integrated AI-Powered Monitoring Centre.1

Seven institutions to govern the country’s use of AI.

Not one verification step covering its own.

That is the whole thing. The document was not undone by using AI. It was undone by using AI without the single control it was proposing for everybody else.

Why every layer missed it

This is the detail that should worry anyone deploying AI in a serious organisation.

That draft went through departmental drafting. It went through internal quality assurance. It was approved by Cabinet — twice, on 25 March and 1 April.3 It was cleared for gazetting. Then it was published nationally for public comment.

Every one of those stages is a review gate. Every one of them passed it.

Fabricated citations are not obviously wrong. They are plausible. A journal that exists, an author who exists, a title in the right register on the right subject, formatted correctly. Nothing in a reviewer’s peripheral vision flags it. You only catch it by going and looking for the paper — and no reviewer in that chain believed that was their job, because before generative AI it very rarely needed to be.

That is the shape of the risk, and it is not specific to policy documents. AI does not usually fail by producing something visibly wrong. It fails by producing something confidently plausible, in exactly the format you expected, that nobody has a reason to check.

A wrong figure in a board paper looks like a right figure. A hallucinated clause reference looks like a clause reference. A reconciliation that is out by one transaction looks like a reconciliation.

If your review process is a human glancing over output that looks correct, you do not have a review process. You have a signature.

What the missing control actually is

Two things, and neither is complicated.

Verification has to be somebody’s named job, on the specific thing that can be fabricated. Not “review the draft” — that is what happened here, repeatedly. Someone owns “every citation in this document has been opened and confirmed to exist.” That is a checkable task with a binary outcome, and it takes an afternoon.

And the check belongs where the failure mode is, not where it is convenient. Arithmetic goes in code, where it is exact. Facts get looked up against a source. Judgement goes to the model. Sign-off stays with a person who is accountable and has actually been given the time to do it.

The reason this piece of news matters more than most is that the failure happened at the far end of the seniority scale, inside a government department, on a document about AI governance, with a Cabinet-level review chain. If it can survive all of that, it can survive whatever your organisation currently has.

Credit where it is due

Malatsi’s handling deserves better than the pile-on it received. Khusela Diko, who chairs Parliament’s communications committee, called for withdrawal on credibility grounds.3 It was withdrawn the following day. He described it plainly, committed to consequence management for those responsible for drafting and quality assurance, and said something I would put on a wall:2

“This unacceptable lapse proves why vigilant human oversight over the use of artificial intelligence is critical.”

That is a better sentence about AI governance than most of what is in the policies that survived.

The revised policy is still pending.4 When it arrives it will be read more carefully than any AI policy on the continent, which is not the worst outcome available.

But the useful question is not what South Africa does next. It is whether the AI output moving through your own organisation this week has anybody named against verifying it — and whether that person has been given the time, or just the signature block.


References

A note on sourcing, since this article is about sourcing. The fabrications were identified by News24*; I have cited the reporting of that investigation rather than the investigation itself, because that is what I was able to open and read. Counts vary between sources — six of 67 is the conservative figure and the one used above. Status current as at 24 August 2026.*

Footnotes

  1. Draft National Artificial Intelligence Policy, Government Gazette Notice 3880 of 2026, published 10 April 2026, comment period to 10 June 2026. 2

  2. “Minister announces withdrawal of draft AI Policy”, SAnews (South African Government News Agency), 26 April 2026. https://www.sanews.gov.za/south-africa/minister-announces-withdrawal-draft-ai-policy 2 3

  3. “South Africa pulls AI policy after hallucinated citations expose drafting scandal”, CNBC Africa, April 2026, reporting the News24 investigation and the journal editors’ confirmations. https://www.cnbcafrica.com/2026/south-africa-pulls-ai-policy-after-hallucinated-citations-expose-drafting-scandal 2 3

  4. “The withdrawal of South Africa’s draft artificial intelligence policy: an opportunity?”, DLA Piper, May 2026. Notes that “at least 10% of the references to academic sources in the document’s reference list were fictitious” — a higher figure than the six-of-67 count reported elsewhere. https://www.dlapiper.com/en/insights/publications/2026/05/withdrawal-of-south-africa-draft-ai-policy