Lesotho as a Founding Member of WAICO: What Joining a New AI Treaty Body Actually Means in Law

On 16 July 2026, on the eve of the World Artificial Intelligence Conference in Shanghai, representatives of 29 states signed the Agreement on the Establishment of the World Artificial Intelligence Cooperation Organization (“WAICO”). The Minister of Foreign Affairs and International Relations, Honourable Limpho Tau, signed on behalf of the Government of Lesotho, placing the Kingdom among the organisation’s founding members. The Minister of Information, Communications, Science, Technology and Innovation, Honourable Nthati Moorosi, attended the accompanying High-Level Meeting on Global AI Governance. The United Nations Secretary-General was present at the signing ceremony.

WAICO is to be an independent intergovernmental organisation headquartered in Shanghai, established to promote international cooperation and global governance in artificial intelligence in a manner that is beneficial, safe and equitable, guided by the purposes and principles of the United Nations Charter.

The coverage has been, understandably, celebratory. Our purpose here is narrower and more practical: to identify what changes in law as a result, what does not change, and what directors, public bodies and businesses operating in Lesotho and across the Lesotho South Africa corridor, should be doing about it now.

1. Signature is not ratification, and ratification is not domestic law

The first point is the one most frequently lost in reporting on international agreements.

Lesotho, like South Africa and other Roman-Dutch and common law jurisdictions in the region, follows the dualist tradition. This has three consequences that matter here:

(a) Signature generally authenticates the text; it does not bind the State. Unless the instrument provides otherwise, signature signifies the State’s participation in the establishment of the organisation and its intention to proceed. Legal obligation at the international level ordinarily follows a further act of ratification, acceptance or accession, in accordance with the entry-into-force clause of the constitutive agreement itself. That clause, typically requiring a stated number of deposited instruments of ratification, will determine when WAICO comes into legal existence and when Lesotho is bound.

(b) A binding treaty still creates no rights or duties for private parties in Lesotho. An international agreement to which Lesotho is party does not, without more, form part of the law of Lesotho. It must be incorporated by domestic legislation. Until that happens, no Mosotho company, data controller or director acquires an obligation, and no individual acquires an enforceable right, by reason of the WAICO Agreement alone.

(c) Parliament’s role is not merely formal. Membership of an intergovernmental organisation typically carries financial obligations (assessed contributions), and usually a headquarters or privileges-and-immunities dimension. Where obligations of that character are assumed, the appropriate parliamentary process, and, where immunities are to be conferred domestically, enabling legislation, is not optional. This is the space in which the substantive legal consequences of membership will eventually be located, and it is worth watching.

The practical takeaway: as at the date of this article, Lesotho’s founding membership of WAICO is a significant act of foreign and technology policy. It is not yet a change in the law that governs anyone’s business.

2. What an organisation of this kind actually produces and why it still reaches you

Bodies of this type rarely legislate. They produce standards, model frameworks, technical specifications, capacity-building programmes and interoperability requirements. None of that is binding law in Lesotho.

But standards migrate. The mechanisms by which soft international instruments acquire hard domestic effect are well known to commercial practitioners:

  • Procurement. Government tenders begin to require compliance with a named framework. The standard becomes a condition of contracting with the State.
  • Licensing. Sector regulators, the Lesotho Communications Authority, the Central Bank of Lesotho for regulated financial institutions, adopt standards as licence conditions or supervisory expectations.
  • Contract. Counterparties, funders and development finance institutions incorporate the standard by reference into supply and services agreements.
  • The standard of care. In delict and in the assessment of directors’ duties, a widely adopted governance framework becomes evidence of what a reasonable operator would have done. Non-adherence becomes a fact that has to be explained.

That last mechanism is the one businesses tend not to anticipate. An AI governance standard need never be enacted to become the yardstick against which an organisation’s conduct is measured after something goes wrong.

3. The domestic gap: policy is ahead of legislation

Lesotho’s international positioning has moved faster than its statute book. The Government has approved a National Artificial Intelligence Policy, together with a Data Management Policy and a Broadband Infrastructure Sharing Policy. These are policy instruments. They articulate direction; they do not, in themselves, confer regulatory powers or create enforceable obligations.

Meanwhile, the operative legal framework has known gaps:

  • The Data Protection Act, 2011 (Act No. 5 of 2012) is on the statute book and establishes a Data Protection Commission, principles for lawful processing, security obligations, restrictions on transfers of personal information out of Lesotho, and breach notification duties. Public reporting has repeatedly noted, however, that the Commission has not been operationalised. An unenforced statute is not an inapplicable one — the obligations bind, and they can be litigated in the ordinary courts but the absence of a regulator has left many controllers under-prepared.
  • Cybercrime and cybersecurity legislation has been through successive iterations since 2021, most recently as the Computer Crime and Cyber Security Bill, 2024, and has attracted sustained constitutional criticism, particularly regarding interception and content provisions. Its current enactment status should be confirmed before any advice is given in reliance on it.
  • The Communications Act, 2012 and the Lesotho Communications Authority’s rules govern the communications layer on which AI services are delivered, including subscriber data obligations.
  • The Penal Code Act, 2010 contains a narrow provision on unlawful access to a computer or electronic storage device, a thin basis for a modern digital economy.
  • The Companies Act, 2011 supplies the directors’ duty framework against which AI deployment decisions will ultimately be judged.

There is, in short, no AI statute in Lesotho, and no AI regulator. That is the position from which membership of WAICO begins, and it is the gap that the capacity-building and rule-making elements of membership are presumably intended to help close.

4. Two governance orders, one compliance function

For businesses operating only within Lesotho, this is a medium-term planning issue. For businesses operating across borders, which describes most of our commercial client base, it is a present one.

An increasingly divergent international landscape is emerging. The European Union’s AI Act imposes obligations with extraterritorial reach, applying to providers placing AI systems on the Union market and, in defined circumstances, where the output of a system is used within the Union, irrespective of where the provider is established. Alongside it sit the G7 Hiroshima process, OECD principles, and the United Nations’ own emerging AI governance architecture. WAICO now adds an institutional forum whose founding membership is drawn substantially from the Global South and which does not include the United States or the European Union member states.

For a Lesotho or South African business, the practical question is not which framework is preferable. It is which frameworks apply to it simultaneously, and whether its governance documentation can satisfy more than one at once. In our experience the answer is usually yes, the common core of documented risk assessment, data governance, human oversight, transparency to affected persons, logging and incident response satisfies most of what any of these regimes demands, but only where the organisation has actually built that core rather than assuming it.

A South African dimension applies directly: the Protection of Personal Information Act 4 of 2013 (POPIA) governs processing by responsible parties in South Africa and imposes conditions on transborder transfers under section 72, while section 71 restricts decisions based solely on automated processing that result in legal consequences for a data subject. Where a group operates on both sides of the border, a Maseru operating company and a Bloemfontein or Johannesburg parent, or shared systems and shared personnel, intra-group data flows engage both POPIA and the Lesotho Data Protection Act, and the intra-group agreements are frequently silent on both.

5. Open source is a licence, not a licence-free zone

Much of the anticipated benefit of membership rests on access to open-source models and lower-cost deployment. This is real, and it is welcome. It is also a contracting exercise that is routinely mishandled.

Models distributed as “open” are distributed under licences. Those licences vary widely: some are genuinely permissive; others are community or research licences that restrict commercial use, impose acceptable-use policies, cap permitted user numbers, require attribution or the propagation of licence terms to downstream products, or reserve rights in outputs. A business that fine-tunes a restricted model on its customer data and embeds it in a commercial product may be in breach of the licence, unable to give the warranties its own customers demand, and holding an asset it cannot cleanly sell.

Related questions arise under Lesotho’s intellectual property regime as to the ownership and protectability of AI-generated output, and under contract as to who bears the risk of inaccurate output. These are answerable, but they must be answered before deployment, not after.

6. A board-level checklist

For directors of Lesotho companies, public bodies and cross-border groups, we suggest the following as a minimum:

  1. Know what you are running. Maintain an inventory of AI and automated decision-making tools in use, including those adopted informally by staff. Shadow deployment is the norm, not the exception.
  2. Map the data. Identify what personal information those tools process, where it is hosted, and whether it leaves Lesotho. Transborder transfer obligations under the Data Protection Act apply now.
  3. Fix the contracts. Vendor and cloud agreements should address data location, sub-processing, security standards, breach notification, service levels, indemnities and exit. Standard supplier terms rarely do.
  4. Read the model licence. Before any model is fine-tuned or embedded in a product, confirm commercial use is permitted and identify what the licence requires downstream.
  5. Keep a human in the loop for consequential decisions. Credit, employment, insurance and disciplinary decisions taken by, or materially on the recommendation of, an automated system attract legal risk in both Lesotho and South Africa.
  6. Document the decision. A short, dated AI use policy and a written risk assessment per material deployment is the cheapest available evidence that the board applied its mind.
  7. Consult employees where automation affects them. Restructuring driven by automation engages ordinary labour law obligations. Technology does not create an exception.

7. What we are watching

  • The text of the WAICO Agreement, its entry-into-force clause, and the terms of any financial obligations assumed by Lesotho.
  • Whether the Agreement is submitted to Parliament, and in what form.
  • Operationalisation of the Data Protection Commission, the single change that would most alter the compliance posture of Lesotho businesses.
  • The fate of the Computer Crime and Cyber Security Bill.
  • Whether the National AI Policy is followed by an AI Bill, and whether it draws on WAICO standards, the African Union Continental AI Strategy, the EU model, or a hybrid.
  • Any WAICO instruments Lesotho adopts, and the mechanism by which they are given domestic effect.

How we can assist

Mayet & Associates Inc. is a dual-jurisdiction commercial law firm with offices in Maseru and Bloemfontein, advising clients on both sides of the Lesotho–South Africa corridor. We advise on:

  • data protection compliance under the Lesotho Data Protection Act and POPIA, including transborder transfer arrangements and intra-group data agreements;
  • technology procurement, cloud and AI vendor contracting, and open-source model licensing;
  • AI governance frameworks, board policies and risk documentation for companies and public bodies;
  • regulatory engagement with the Lesotho Communications Authority and the Central Bank of Lesotho; and
  • the corporate governance and employment law consequences of automation.

This article is provided for general information only and does not constitute legal advice. It reflects the position as at July 2026 and is based on publicly available reporting of the signing of the WAICO Agreement; the text of the Agreement had not been published at the time of writing. Legislative status, particularly in relation to pending cybercrime legislation, should be verified before reliance. Readers should obtain advice on their specific circumstances before acting.