4 September 2026

Artificial Intelligence Is Becoming Public Policy: Why Businesses Should WatchGovernment as Closely as Technology

Artificial Intelligence Is No Longer Just a Technology Issue
Artificial intelligence (“AI”) has rapidly evolved beyond being a purely technological development.
Across Africa and globally, governments are increasingly treating AI as a matter of economic policy,
public administration, national competitiveness, rights protection, and regulatory governance. For
businesses, this means that understanding the trajectory of AI policy is becoming just as important
as understanding the technology itself.


Recent developments underscore this shift. The African Union has adopted its Continental Artificial
Intelligence Strategy, signalling a continent-wide commitment to responsible and inclusive AI
development through national strategies and risk-based governance frameworks. At the
international level, Lesotho participated in the inaugural United Nations Global Dialogue on Artificial
Intelligence Governance held in Geneva on 6–7 July 2026. During the Dialogue, Lesotho
expressed support for capacity-building, digital infrastructure, human oversight, and sector-led, risk-
based approaches to AI governance.


These developments are significant. They demonstrate that AI is increasingly viewed not merely as
an innovation issue, but as a governance issue requiring coordinated public policy responses.
Lesotho’s Emerging AI Policy Framework
Lesotho’s participation in international AI governance discussions reflects an emerging national
policy direction.


In its official statement to the United Nations Global Dialogue, Lesotho referred to an “Artificial
Intelligence Policy of 2025.” However, the policy document and implementation plan that are
publicly available through Government channels remain expressly marked as a “Second Draft.”
While this strongly evidences an ongoing policy initiative, no publicly available source reviewed for
this article confirms that a final version has been formally adopted, gazetted, or otherwise given
legal effect.


Accordingly, the prudent legal position is to regard Lesotho as having an emerging AI policy
framework rather than binding AI-specific legislation.
This distinction is important. Although policy documents often signal the direction of future
regulation, they should not be conflated with legislation that creates enforceable legal obligations.


Existing Law Already Applies
The absence of a dedicated AI statute should not be mistaken for the absence of legal obligations.
Businesses deploying AI systems remain subject to existing legal frameworks, depending on the
nature of the technology and its use.


In Lesotho, the Data Protection Act, 2011 regulates the processing of personal information. In
South Africa, the Protection of Personal Information Act 4 of 2013 (“POPIA”) governs the
processing of personal information by both public and private bodies and includes provisions
addressing certain forms of automated decision-making.
Beyond data protection legislation, AI deployment may engage a wide range of existing legal

obligations, including contractual commitments, duties of confidentiality, employment law, consumer
protection legislation, intellectual property law, professional obligations, and sector-specific
regulatory requirements. In other words, AI-specific legislation is not a prerequisite for legal risk.
Why This Matters Across Industries


The legal implications of AI extend well beyond technology companies.
Across international markets, organisations are increasingly using or piloting AI in financial services
for fraud detection and customer support, in mining and manufacturing for predictive maintenance
and operational optimisation, and in professional services for legal research, drafting, and
document review. These examples reflect broader international industry practice and are not
presented as verified evidence of AI adoption by businesses in Lesotho.


Regardless of sector, AI raises common governance questions. Organisations should consider who
remains accountable for decisions supported by AI, what information may safely be entered into
external AI systems, whether human review should remain mandatory before AI-assisted outputs
affect clients, employees or members of the public, and how the organisation will assess accuracy,
identify bias, preserve confidentiality and legal privilege, and document significant decisions. These
questions arise irrespective of whether comprehensive AI legislation has been enacted.


The Emerging Global Regulatory Direction
Although there is currently no single international model for AI regulation, a clear trend has
emerged.


Leading international frameworks increasingly adopt a risk-based approach under which regulatory
obligations are proportionate to the risks posed by particular AI systems. Systems capable of
materially affecting legal rights, safety, or significant commercial decisions are generally subject to
stronger governance requirements than lower-risk applications.


This philosophy is reflected, albeit with differing legal force and territorial application, in the African
Union’s Continental Artificial Intelligence Strategy, the European Union’s AI Act, and the United
States National Institute of Standards and Technology (“NIST”) AI Risk Management Framework.
While these instruments differ in scope and legal effect, they consistently emphasise principles
such as accountability, transparency, governance, and effective risk management.


Governance Responsibilities Are Already Evolving
These developments do not mean that boards of companies in Lesotho or South Africa are already
subject to a new statutory duty expressly labelled “AI governance.”


They do, however, indicate that AI increasingly engages existing governance, risk management,
and compliance responsibilities. Boards and senior management should understand where material
AI systems are being used within the organisation, what data those systems receive, which
business decisions they influence, who remains accountable for their outputs, and what
governance and oversight mechanisms exist. From a governance perspective, the central issue is
accountability rather than automation.


For many organisations, however, the immediate governance risk is not the implementation of
sophisticated AI systems but unmanaged use of publicly available tools by employees for drafting,
research, analysis or customer communications. Businesses may have no formal AI programme
while AI is already being used across the organisation. Effective governance therefore begins with

visibility. Organisations should identify the AI tools currently in use, understand the data being
processed and the decisions being influenced, and implement controls that are proportionate to the
associated legal and commercial risks.


Contractual Obligations May Arrive Before Legislation
For businesses operating across Lesotho and South Africa, AI-related obligations may arise long
before domestic AI legislation is enacted.


Multinational clients, technology vendors, financial institutions, and other regulated counterparties
are increasingly incorporating AI governance provisions into commercial agreements. These may
include contractual requirements relating to data handling, confidentiality, cybersecurity, intellectual
property, human oversight, audit rights, incident reporting, and subcontracting. These obligations
arise through contract rather than public regulation and may become commercially significant
irrespective of the pace of legislative reform.


Practical Steps Businesses Can Take Now
An effective AI governance framework need not be overly complex. For many organisations,
sensible first steps include identifying AI tools already in use, approving authorised AI platforms,
prohibiting the use of confidential or personal information in unapproved systems, allocating
internal responsibility for AI oversight, requiring human review of significant AI-assisted outputs,
conducting appropriate vendor due diligence, maintaining suitable records, and providing staff
training. The level of governance should remain proportionate to the legal, regulatory, operational,
and commercial risks presented by each use case.


Looking Ahead
Waiting for comprehensive AI legislation is unlikely to be an effective governance strategy. The
direction of public policy is already becoming clear. Existing legal obligations continue to apply,
while commercial counterparties are increasingly imposing their own AI-related requirements
through contractual arrangements.


AI-specific legislation is not a prerequisite for legal or commercial exposure. AI-assisted processes
may still engage obligations relating to data protection, confidentiality, contract, professional
responsibility, employment, consumer protection, and sector-specific regulation. Businesses that
establish proportionate governance measures now will be better placed to satisfy client due
diligence, manage existing legal obligations, and adapt efficiently as AI regulation continues to
develop.


Artificial intelligence is changing not only how businesses operate, but also how responsible
organisations should be governed.
The information provided in this article does not, and is not intended to, constitute legal advice;
instead, all information, content, and materials available in this article are for general informational
purposes only.


For further information or preparatory advice, contact Webber Newdigate. LEX Africa’s member in
Lesotho: https://www.webbernew.com/.

The Central, 96 Rivonia Road, Sandton, 2196, Johannesburg, South Africa

LEX Africa

Resources

Explore Articles

Artificial Intelligence Is Becoming Public Policy: Why Businesses Should WatchGovernment as Closely as Technology
4 September 2026
Artificial Intelligence Is No Longer Just a Technology IssueArtificial intelligence (“AI”) has rapidly evolved beyond being a purely technologica...
Ghana
17 August 2026
In today’s digital world, personal data has become a valuable resource forbusinesses. One of the principal uses of personal data collected by businesses isdi...
Kenya
14 August 2026
SERIES 1: WHAT IS THE IDEA AND FUNCTION OF A BRAND? INTRODUCTION This is the first article in a three-part series titled, “How Should Businesses Create...
South Africa: Is cryptocurrency ‘capital’?                  Taking the Mangundhla judgment under the loop
7 August 2026
Introduction Two Gauteng Division judgements have reached diametrically oppositeconclusions on the question as to whether cryptocurrency constitutes“capital...
Tanzania
3 August 2026
Electronic payments mandatory for specified transactions List of covered transactions stipulated and wide Six-month transition period provided   On 30 June ...
Navigating Pan-African Legal Issues: Insights from the 2026 LEX Africa AGM in Ghana.
29 July 2026
LEX Africa successfully held its 2026 Annual General Meeting (AGM) in Accra, Ghana, 3-6 June 2026, in partnership with its Ghanaian member Bentsi-Enchill, Le...
Mozambique
18 June 2026
The Council of Ministers approved Decree No. 14/2026, of April 17, which creates the National Commission for Artificial Intelligence (“CNIA”), a body for con...
LEX Africa Expands Pan-African Footprint, Welcoming New Member in Somalia, Burkina Faso, and the Republic of Congo (Brazzaville)
31 March 2026
For any international business or investor, Africa presents a continent of immense opportunity. However, navigating its 54 diverse legal and regulatory lands...
LEX Africa supports African law students
30 March 2026
LEX Africa’s CSR Programme supports worthy organisations operating in Africa. Lex:lead is a group of international lawyers and friends which offers ...
Africa
29 January 2026
The Common Market for Eastern and Southern Africa (COMESA) has recently issued far-reaching new regulations expected to impact the way that business is being...