AI in the Legal Industry: What South African Practitioners Need to Know Right Now
A practical overview of where the law stands, where it is heading, and what it means for legal practice.
CreamLegal
- 14 August 2026
Artificial intelligence is no longer a future consideration for the legal profession in South Africa. It is here, it is being used, and it is beginning to shape how legal services are delivered, regulated, and evaluated. The question facing practitioners and firms is no longer whether to engage with AI, but how to do so competently, ethically, and in line with a rapidly evolving regulatory environment. This article sets out where South Africa’s AI governance currently stands following a turbulent few months in policy development, what tools are actively reshaping legal practice, and what practical steps every practitioner and legal business should be taking now.
1. The Regulatory Landscape: A Policy in Transition
South Africa’s attempt to build a unified AI governance framework has had a difficult year, and the story itself has become one of the most instructive examples of AI’s risks in professional and public-sector work.
The Draft AI Policy: What It Proposed
On 10 April 2026, the Department of Communications and Digital Technologies (DCDT) gazetted the Draft South Africa National Artificial Intelligence Policy (Notice 3880 of 2026, Government Gazette No. 54477). The document represented the culmination of a process that began with a National AI Summit in April 2024 and drew on 32 public submissions. Its stated vision was “AI for inclusive economic growth, job creation, cost reduction, and a developing Africa.”
For the legal industry specifically, the draft proposed:
- A risk-based classification framework, modelled on the EU AI Act, dividing AI systems into high-risk, medium-risk, and low-risk categories, with high-risk applications (such as AI in law enforcement, credit-scoring, and medical diagnosis) subject to mandatory conformity assessments and independent audits.
- New oversight institutions, including a National AI Commission, an AI Ethics Board, an AI Regulatory Authority, and an AI Ombudsperson, to coordinate governance and certify high-risk deployments.
- A requirement for algorithmic transparency and public-interest impact assessments, with clear accountability lines for developers, operators, and data controllers.
- Constitutional anchoring, ensuring all AI systems remain subject to the Bill of Rights, including the rights to equality (s. 9), privacy (s. 14), and human dignity (s. 10).
- A phased three-year implementation timeline running from 2025/26 through 2027/28, with Year 1 focused on establishing the Ethics Board and finalising high-risk regulations, and Year 3 targeting full policy realisation.
What Happened Next: The Hallucination Scandal
Within weeks of publication, the draft was withdrawn. News24 reported that a significant number of the document’s citations, at least six of sixty-seven bibliography entries, referred to academic articles that did not exist. Editors of respected journals confirmed that the credited authors had never published the work attributed to them. The diagnosis was swift and damaging: the policy had been drafted with the assistance of generative AI tools, and the citations had been hallucinated and fabricated references that sound plausible but have no basis in fact.
The draft AI policy was caught doing exactly what an AI policy is supposed to prevent: producing authoritative-sounding content without a reliable factual foundation. For the legal profession, a sector built on the integrity of citation and precedent, the lesson is not abstract. Minister Solly Malatsi withdrew the draft on 27 April 2026, describing the inclusion of unverified citations as a matter that had “compromised the integrity and credibility” of the entire document. Two officials were placed on precautionary suspension pending a formal investigation. Director-General Nonkqubela Jordan-Dyani called the incident “highly regrettable.”
Where Things Stand Now
The DCDT has confirmed a revised timeline to Parliament. A new draft will go to Cabinet for approval by November 2026 and will be released for public comment in January 2027, putting the final policy approximately nine months behind its original schedule. Minister Malatsi has committed to “much more rigorous oversight” in the revised process. In the interim, AI in South Africa remains governed by the patchwork of existing legislation that predates the draft: the Protection of Personal Information Act (POPIA), the Promotion of Access to Information Act (PAIA), the Cybercrimes Act, and the country’s intellectual property statutes. None of these were designed with AI specifically in mind, and the gaps are real.
2. AI in Legal Practice: What Is Already Happening
Regardless of where the policy framework lands, AI tools are already reshaping how legal work is done in South Africa. The question for practitioners is not whether this is real, because it is, but whether they are engaging with it deliberately or inadvertently.
Active Tools in the South African Market
LexisNexis Protégé™ Workflows
Launched in March 2026, Protégé™ Workflows represents South Africa’s most significant AI product rollout to date. The platform is designed to guide practitioners through complex legal tasks in a structured, repeatable way, grounding outputs in citable legal authority. It integrates research, drafting, and document review within a single environment.
Harvey AI (Major Firm Adoption)
Several of South Africa’s largest law firms, including Bowmans, ENS, Webber Wentzel, and Cliffe Dekker Hofmeyr, have begun adopting AI technologies including Harvey AI for research, drafting, and document analysis. The adoption is accelerating competition while simultaneously raising questions about the future of traditional hourly billing models.
Where AI Is Adding Genuine Value
Application | What it does in practice |
Legal research | Faster precedent searches across large case law databases, surfacing relevant authority that manual review might miss |
Contract drafting and review | Generating first drafts, identifying unusual or missing clauses, flagging risk exposure |
Document analysis | Reviewing large volumes of disclosure material, due diligence documents, or litigation bundles |
Predictive analytics | Estimating likely litigation outcomes based on historical case data |
Billing and admin automation | Reducing time spent on matter management, timekeeping, and reporting |
3. The Risks: What Every Practitioner Must Understand
Hallucinations and the Duty of Care
The hallucination problem is not confined to government policy documents. In 2025, the KwaZulu-Natal High Court dealt with the case of Mavundla v MEC: Department of Co-Operative Government and Traditional Affairs, in which heads of argument were filed citing nine authorities, of which only two could be verified. The remainder were AI-generated fabrications. A researcher tracking AI errors in legal proceedings has logged more than 900 US cases involving fictitious case citations, and at least four in South Africa before the Mavundla matter. The professional and reputational risk to any practitioner who submits AI-generated content without thorough verification is significant. The courts, clients, and professional insurers hold the practitioner responsible, not the software.
Confidentiality and Data Protection
- Uploading client documents or privileged information to public AI platforms creates potential POPIA compliance risks, depending on how the platform processes and stores data.
- Practitioners must understand the data handling terms of any AI tool they use before processing client information through it.
- The duty of confidentiality under the Legal Practice Act does not pause at the boundary of a technology tool.
Over-Reliance and Professional Accountability
The De Rebus journal has noted that, by 2026, the central professional question is no longer whether to use AI tools, but how to govern and supervise their use. The Legal Practice Council is expected to integrate AI competence into continuing professional development requirements in the near term. In the meantime, the baseline rule is unchanged: efficiency gains from AI do not reduce the practitioner’s responsibility for the accuracy and integrity of their work product. Every citation, case reference, statutory provision, and factual claim generated by an AI tool must be independently verified against a primary source before it is relied upon or submitted.
4. What Practitioners and Legal Businesses Should Do Now
Given the current state of the law, where AI tools are in active use but specific AI regulation remains pending, the following steps represent responsible, practical positioning for any legal practice or legal services business.
Immediate Steps
- Establish a clear internal policy on AI tool use before your staff uses them informally. This includes which tools are permitted, for which tasks, and what verification steps are required before any AI-generated output is used or shared.
- Audit your data handling practices. Identify which AI platforms you or your team are using and confirm how they process, store, and share the information submitted to them. Assess against your POPIA obligations.
- Build verification into your workflow. AI-generated research, citations, and drafts should be treated as a first draft only. Every reference must be confirmed against a primary, verifiable source.
- Train your team. Even basic AI literacy training materially reduces risk: understanding what hallucinations are, how to spot them, and what questions to ask of AI-generated content.
Positioning for the Policy Change Ahead
- Monitor the DCDT’s revised draft when it is published for comment in January 2027. The risk-based framework and institutional architecture from the original draft are likely to survive in substance; comments submitted during the consultation window can shape how the final rules are written.
- Understand the proposed high-risk categories. If your practice area involves automated decision-making that affects clients’ rights in credit, employment, healthcare, or public administration, you are likely to fall within the highest regulatory tier under any revised draft.
- Consider the billing model implications. As large firms use AI to execute standard tasks faster, the hourly billing model faces pressure. Smaller firms that adopt AI tools strategically can use them to compete at a level previously out of reach.
Conclusion
South Africa’s AI policy journey has been instructive in an unintended way: the government’s own drafting process demonstrated, at the highest level, what happens when AI-generated content is not rigorously verified. The legal profession, a sector whose entire authority rests on the reliability of its sources, cannot afford to repeat that lesson in practice. The tools are real, the benefits are real, and the risks are equally real. The practitioners and firms that will thrive are those who engage with AI deliberately: adopting it where it adds genuine value, governing it where it introduces risk, and maintaining the professional accountability that no tool can substitute. The revised national policy, when it arrives, will formalise much of what careful practitioners are already doing. The advantage goes to those who are ready.
This article is for general informational purposes only and does not constitute legal advice. For guidance specific to your circumstances, please consult our team directly.



