Sovereign AI/South Africa

Production AI your regulator can't object to.

SA schemes, banks, and insurers are running AI on foreign infrastructure. Their data leaves the country every time a model runs. We design the architecture that keeps it here, and keeps it defensible.

The distinction most pilots miss

Member data
Azure ZA-North
US-controlled provider

Residency keeps the bytes in SA. It does not put them beyond foreign law. Sovereignty is about who can compel access, not where the disk sits.

[ WHO ]

Three regulated industries

01 POPIA S26 · CMS

Medical Aid

Member health data is the most protected data there is. Every AI pilot touches it, not just at rest, but the second a model runs.

02 SARB Directive 3 · FIC

Banking

AML and credit AI answer to POPIA, FIC, and SARB at once. One architecture has to satisfy all three.

03 SAM · FSCA · TCF

Insurance

Every automated decision has to be fair, and explainable to a regulator. That is architecture, not just a model.

[ HOW ] The method

Compliance is an architecture decision, not a policy document.

Most AI governance stops at a written policy. The real exposure is in the data flow, where personal data actually moves when a model runs. That is the layer we work at.

01

Map the data flow

Storage, embeddings, prompt history, inference. Personal data moves through all four. Most teams have mapped the first and missed the rest.

02

Find the regulatory boundary

Where does POPIA get triggered. SARB. SAM. This is the line your architecture has to defend.

03

Design the sovereign path

On-prem, Cassava AI Factory, or hybrid. We pick the one that holds, and document it so legal and the regulator can follow.

[ SOVEREIGNTY ]

Your data has a jurisdiction. We keep it inside the line.

Every model call is a decision about who can reach your data, and under whose law. We design the architecture so the answer is always: South Africa.

Data node, in jurisdiction Sovereign core Cross-border attempt, blocked
[ WHY ] The shape of the problem
4 points personal data moves through an AI workload. Most teams have mapped one.
3 regulators a single banking AI answers to at once: POPIA, FIC, SARB.
§72 the POPIA section a default cloud AI call triggers, usually without anyone deciding to.
2025 Cassava AI Factory brought sovereign GPU compute to SA at scale. The excuse is gone.
[ CONTEXT ]

Sovereign AI stopped being optional this year.

The question used to be whether sovereign AI was even possible in South Africa. That question is settled. Now it is a deployment decision, and a compliance one.

  1. Jul 2021

    POPIA takes full effect

    Cross-border transfer of personal information (Section 72) becomes enforceable. Most AI calls are cross-border transfers.

  2. 2023-24

    Enterprises pilot AI on foreign infra

    Schemes, banks, and insurers ship LLM pilots on default cloud endpoints. The compliance work rarely happens.

  3. Oct 2025

    Cassava AI Factory goes live

    Sovereign GPU compute at scale, on SA soil, under SA law. The infrastructure excuse disappears.

  4. Now

    The deployment decision

    On-prem, sovereign cloud, or hybrid. The right answer is an architecture question, and that is the work.

For CIOs, CROs, and Heads of Data

"Where does our AI data actually live?" If the answer isn't clean, that's the conversation.

25 minutes. No pitch. A working session on your AI workloads and where the regulatory exposure sits.

Start the conversation