This article first appeared in Business Day.
South Africa's uncertainty over AI policy should not be misread as a delay in addressing risk. If anything, it exposes an uncomfortable truth: AI risk is already embedded in business operations, and most organisations are not governing it.
The market conversation remains dominated by what AI can do, how quickly it scales, and where it unlocks efficiency. Far less attention is paid to whether organisations have the governance structures to control it, or how costly it is to wait.
AI failures are rarely technical. They stem from failures of oversight, accountability, and decision-making. This is not a future risk to be managed later. It is a present one, already active across operations, customer engagement, finance, and executive decision systems.
The cost of inaction is escalating. According to Gartner, by 2030, fragmented AI regulation will extend to 75% of the world's economies, driving $1 billion in total compliance spend.
South Africa's Policy Gap: A False Comfort
Regulatory uncertainty should not breed complacency. Formal policy may be delayed or evolving, but global standards are tightening, multinationals are importing governance expectations, and customers are becoming more aware. Litigation and reputational consequences will not wait for formal policy.
In this environment, self-governance is the first line of defence.
The Exposure Hidden in Plain Sight
In many South African organisations, AI tools are already embedded in workflows, often informally and without central visibility. Data inputs are fragmented or unverified. Accountability for AI-driven decisions is unclear. Sensitive data leakage and flawed AI outputs are not adequately assessed. Boards are not receiving structured reporting on AI risk exposure.
The result is a widening gap between AI adoption and AI control.
The Missing Governance Layer
AI governance is not an IT function. It is a cross-functional control system that must sit at executive and board level.
A credible framework must address who is accountable for AI systems, what decisions AI may influence or make independently, which tools are approved for use and
which are prohibited, how sensitive data is protected, how models are validated and challenged, and when independent verification is required.
Without this, organisations are effectively deploying uncontrolled decision engines.
Data Integrity: The Hidden Risk Multiplier
AI risk is fundamentally a data problem before it is a model problem. Poor data integrity produces biased outputs, faulty decisions at scale, regulatory exposure, and a loss of auditability.
Most organisations overestimate the quality of their data environments. Boards should be asking: Is the data feeding AI systems accurate, complete, and current? Can outputs be traced back to their source? Can the organisation defend or reproduce the decisions AI made? Is sensitive client data protected from unintended leakage?
If the data is flawed, the intelligence is flawed but at a speed and scale that amplifies the damage significantly.
Ethical Risk: The Silent Reputation Threat
AI introduces a category of risk that is difficult to detect until it is too late: ethical failure at scale. This includes embedded bias in credit, hiring, or pricing decisions; lack of transparency in automated outcomes; misuse of customer data; and results that conflict with stated ESG or governance commitments.
In a market like South Africa, where inequality, fairness, and access are highly sensitive, unmanaged AI ethics can quickly become a public and political issue. Organisations must be able to reproduce, explain, and comfortably defend every consequential decision AI produces.
Board Accountability: The Critical Shift
AI risk is now a board-level responsibility. Boards cannot delegate AI oversight entirely to technology teams. The implications reach into financial reporting integrity, customer conduct risk, regulatory compliance, and strategic decision-making.
Practical priorities include integrating AI risk into enterprise risk frameworks, establishing oversight mandates within existing audit and risk committees, requiring regular reporting on AI deployment and incidents, and ensuring independent auditability of AI systems and outputs. It is also worth noting that the new King V Code, effective 1 January 2026, requires the assessment of emerging technology risks, making structured AI oversight increasingly relevant from a compliance and legal perspective.
The question is no longer whether a company uses AI. It is whether the board understands and governs it.
AI will not fail because the technology is flawed. It will fail where organisations deploy it without governance, without control, and without accountability. The companies that will lead are not those that adopt AI fastest but those that govern it best.