ArtWiz
← Back to articles
FijiAIPolicyTech

Fiji Is Building Its AI Rules Backwards (On Purpose)

July 9, 2026·6 min read·Sahil Kumar

Disclaimer: This article summarises public government announcements and published strategy documents. It is not legal advice. Where a claim describes a policy rather than enacted legislation, this is noted explicitly — always confirm current legal status with official sources before making decisions based on this piece.


Most countries writing AI regulation are doing it reactively — scrambling to put guardrails on technology that already exists, is already deployed, and is already causing problems. Fiji is doing something different. It's building AI rules last, on purpose, as the deliberate final layer of a multi-year digital transformation plan.

Whether that's wise or dangerously slow depends on what happens in the years between now and 2027.

The Sequencing Logic

Fiji's National Digital Strategy 2025–2030 doesn't treat AI governance as a standalone urgent problem. It positions it as a capstone — the final regulatory layer that sits on top of more foundational infrastructure: cybersecurity frameworks, national identity systems, and data/cloud policy.

The government's own language is telling: AI governance should be built on "trusted foundations rather than fragile pilots." The argument is that regulating AI in isolation — before you've sorted out who owns what data, how identity is verified, and what your cybersecurity baseline looks like — produces rules that don't actually hold up in practice.

In March 2024, Deputy PM Manoa Kamikamica made this explicit: "We looking at it from a cybersecurity lens, so we are developing a cybersecurity strategy for Fiji and National Digital Strategy so AI governance will be part of it as well."

That sequencing has largely held. By early 2026, the Cabinet had formally endorsed the National Cybersecurity and Resilience Strategy 2026–2031. The AI framework is next — targeted for 2027.

What's Already Been Built

The foundations aren't nothing. At the Datec Fiji Tech Summit in October 2025, Minister Filimoni Vosarogo confirmed several pieces as complete or near-complete:

  • 5G rollout underway
  • Fiji's national CERT (Computer Emergency Response Team) established
  • A National Privacy and Personal Data Protection Policy described as finalised

That last one needs unpacking — more on it below.

Also in 2024, Fiji launched an AI Hub: a coordinating body for AI training, resources, and partnerships. It's not a regulatory body, but it signals the government is actively engaging with AI adoption rather than waiting for 2027 to think about it.

The Important Caveat: Policy Is Not Law

This is where things get genuinely complicated for businesses.

Minister Vosarogo described a National Privacy and Personal Data Protection Policy as finalised. A policy is a government position or plan. It is not the same as enacted legislation with enforcement mechanisms.

Fiji's actual privacy protections currently appear to sit largely in Clause 24 of the 2013 Constitution — a constitutional right to privacy — plus scattered sector-specific laws covering banking, revenue, medical records, legal communications, and cybercrime. There is no single, comprehensive data protection Act equivalent to the GDPR or Australia's Privacy Act.

Earlier expectations of a dedicated Privacy Bill being enacted by 2023 don't appear to have materialised. The distinction matters enormously for any business that needs to know: what rules actually apply to how I handle personal data right now?

The honest answer in 2026 is: it's unclear, and that ambiguity may need to be resolved alongside the 2027 AI framework rather than before it.

What the 2027 Framework Is Expected to Cover

Based on the National Digital Strategy and government statements, the National AI Framework is intended to address:

  • AI ethics — principles for responsible AI development and deployment
  • Data privacy in AI systems — how personal data used to train or run AI models should be treated
  • Liability for AI-driven decisions — who is responsible when an AI makes a harmful or incorrect decision
  • Standards for AI in public services — guardrails for government use of AI in areas like health, education, and justice

This points toward a risk-based, sector-specific approach rather than a single sweeping AI law — which mirrors what the EU, UK, and Singapore are doing, and is generally considered more practical than trying to regulate "AI" as a monolithic category.

The Real Tension

Here's the problem that doesn't go away just because the sequencing makes sense in theory.

AI is already reshaping Fiji's BPO sector — the outsourcing industry that employs thousands of Fijians is under direct pressure from automation, and that's happening now, not in 2027. The Google data centre at Natadola is being built now, bringing infrastructure that will dramatically increase the capacity for AI workloads in the region. AI tools are being adopted by Fijian businesses and government agencies now.

The gap between real-world AI adoption and formal regulatory clarity is where risk accumulates. Businesses making AI-related decisions in 2026 are doing so without a clear legal framework for liability, data use, or ethics. The sequencing logic is sound — but the gap between now and 2027 is not empty. It's full of decisions that will have already been made by the time the rules exist to govern them.

What This Means for Businesses in Fiji

If you're a Fijian business thinking about AI — whether that's deploying AI tools, building AI-powered products, or using AI for customer data — a few things are worth being clear-eyed about:

  1. There is no dedicated AI law in Fiji right now. The framework is coming, but it doesn't exist yet.
  2. Data privacy rules are fragmented. Don't assume a finalised "policy" means enforceable law. If you're handling personal data at scale, get proper legal advice on what actually applies.
  3. The 2027 framework will likely be risk-based. Build your AI practices around the principles it's expected to cover — ethics, accountability, and data governance — and you'll be well-positioned when formal rules arrive.
  4. Watch the AI Hub. It's the government's coordinating body for AI right now and is likely to be the first source of formal guidance ahead of the 2027 framework.

Fiji is building its AI rules deliberately and thoughtfully. That's actually a better approach than many countries have taken. But "thoughtful and deliberate" still means there's a gap — and operating in that gap requires businesses to make their own judgements about responsible AI use until the framework arrives.


I work with Fijian businesses on IT strategy and infrastructure, and I'm watching AI reshape what clients ask for in real time — well ahead of any formal regulation. If you're trying to figure out what this means for your business or how to build responsibly in the gap, get in touch.


Sources

  1. Fiji developing AI governance framework — FBC News
  2. Plans to protect AI users — Fiji Times
  3. Cybersecurity and AI drive Fiji's digital leap — FBC News
  4. Fiji National Digital Strategy 2025–2030: Driving Inclusive Digital Growth — Tech In Pacific
  5. A Snapshot: National Digital Strategy 2025–2030 — Fiji Government (digital.gov.fj)
  6. Beyond the Scope: Fiji's digital strategy — Fiji Times
  7. From Strategy to Action: Fiji Advances Inclusive Digital Transformation — UNESCO
  8. Fiji Digital Transformation: National Strategy Ready! — The RegTech
  9. Fiji — AI Policy Portal
  10. Fiji — AI World