Sovereign AI/South Africa
Production AI your regulator can't object to.
SA schemes, banks, and insurers are running AI on foreign infrastructure. Their data leaves the country every time a model runs. We design the architecture that keeps it here, and keeps it defensible.
Sovereign AI, built for SA regulation
POPIA-native products in development, one per regulated industry, plus the control plane that sits over them all. Design partners wanted.
Sentinel
Medical AidSovereign claims-document AI for medical schemes
View product →
Ledger
BankingSovereign AML and transaction-monitoring copilot
View product →
Adjudicator
InsuranceSovereign claims and underwriting explainability engine
View product →Custodian
All threeThe POPIA control plane for any AI workload
View product →The distinction most pilots miss
Residency keeps the bytes in SA. It does not put them beyond foreign law. Sovereignty is about who can compel access, not where the disk sits.
Three regulated industries
Medical Aid
Member health data is the most protected data there is. Every AI pilot touches it, not just at rest, but the second a model runs.
Banking
AML and credit AI answer to POPIA, FIC, and SARB at once. One architecture has to satisfy all three.
Insurance
Every automated decision has to be fair, and explainable to a regulator. That is architecture, not just a model.
Compliance is an architecture decision, not a policy document.
Most AI governance stops at a written policy. The real exposure is in the data flow, where personal data actually moves when a model runs. That is the layer we work at.
Map the data flow
Storage, embeddings, prompt history, inference. Personal data moves through all four. Most teams have mapped the first and missed the rest.
Find the regulatory boundary
Where does POPIA get triggered. SARB. SAM. This is the line your architecture has to defend.
Design the sovereign path
On-prem, Cassava AI Factory, or hybrid. We pick the one that holds, and document it so legal and the regulator can follow.
Your data has a jurisdiction. We keep it inside the line.
Every model call is a decision about who can reach your data, and under whose law. We design the architecture so the answer is always: South Africa.
Sovereign AI stopped being optional this year.
The question used to be whether sovereign AI was even possible in South Africa. That question is settled. Now it is a deployment decision, and a compliance one.
- Jul 2021
POPIA takes full effect
Cross-border transfer of personal information (Section 72) becomes enforceable. Most AI calls are cross-border transfers.
- 2023-24
Enterprises pilot AI on foreign infra
Schemes, banks, and insurers ship LLM pilots on default cloud endpoints. The compliance work rarely happens.
- Oct 2025
Cassava AI Factory goes live
Sovereign GPU compute at scale, on SA soil, under SA law. The infrastructure excuse disappears.
- Now
The deployment decision
On-prem, sovereign cloud, or hybrid. The right answer is an architecture question, and that is the work.
For CIOs, CROs, and Heads of Data
"Where does our AI data actually live?" If the answer isn't clean, that's the conversation.
25 minutes. No pitch. A working session on your AI workloads and where the regulatory exposure sits.
Start the conversation