Story audio is generated using AI
Artificial intelligence is no longer a futuristic concept confined to research laboratories and technology companies. It is already shaping decisions about who receives credit, who qualifies for employment, which students gain access to educational opportunities, how public services are delivered and, increasingly, how democratic discourse is conducted. The question confronting policymakers across the world is therefore not whether AI should be governed, but how.
The answer to that question remains unsettled. Despite the growing influence of AI on economies, societies and governments, the global landscape of AI governance remains fragmented. Only a small number of countries currently have dedicated AI legislation in force. Most rely on voluntary guidelines, executive directives or sector-specific regulations that are often inadequate to address the complexity and pace of technological change.
The EU has emerged as the global pioneer through its AI Act, establishing the world’s first legally binding, risk-based framework for artificial intelligence. South Korea has followed with its AI Basic Act, while countries such as China, Brazil, Canada, Kenya and Namibia continue to develop their own approaches.
These developments offer valuable lessons. Yet they also reveal a profound weakness shared by virtually every AI governance framework currently in existence: they regulate the system; they do not regulate the reasoning. This distinction may appear technical, but it goes to the heart of democratic accountability in the digital age.
A profound weakness shared by every AI governance framework is ... they regulate the system; they do not regulate the reasoning
Most current laws focus on the quality of data used by AI systems, the processes organisations must follow when deploying AI, and the transparency requirements attached to outputs. These are important safeguards. However, they do not adequately address a fundamental question: how did the system arrive at a particular conclusion?
When an AI system recommends that a person be denied a loan, rejected for employment, flagged by law enforcement or excluded from a social benefit programme, citizens are entitled to know more than the fact that an algorithm was involved. They are entitled to understand the basis upon which that decision was made. This is not merely a technical issue. It is a constitutional imperative.
South Africa’s constitution guarantees equality, access to information and administrative action that is lawful, reasonable and procedurally fair. These rights cannot be suspended simply because a decision was made by a machine rather than a human being.
Yet across the world, even the most advanced AI laws do not require meaningful traceability of reasoning processes, reproducibility of decisions, independent auditing of inferential logic, or verification of the evidence upon which conclusions are based.
In effect, many AI systems operate as black boxes. Inputs are visible. Outputs are visible. What occurs between the two often remains beyond meaningful scrutiny. This is the governance gap of our time. It is also where South Africa has an opportunity to lead.
As parliament begins to consider the future of AI governance, we should avoid the temptation either to overregulate innovation or to abdicate responsibility in the hope that markets will regulate themselves. Our task is to build a framework that protects constitutional rights while enabling innovation, economic growth and technological advancement.
The first layer protects constitutional guarantees by prohibiting clearly unacceptable uses of AI. These include unlawful biometric mass surveillance, systems designed to manipulate vulnerable populations, discriminatory algorithms, electoral manipulation and certain forms of real-time facial recognition. These prohibitions are not anti-innovation; they are pro-democracy.
The second layer introduces risk-based regulation. Not all AI systems carry the same societal consequences. A spam filter should not be regulated in the same manner as an AI system making health-care recommendations or determining eligibility for public benefits. High-risk applications require stronger safeguards, certification and oversight, while low-risk innovation should be encouraged.
The third layer focuses on organisational accountability. Developers and deployers of high-risk AI systems must be required to implement governance structures, risk management processes, internal audits, human oversight mechanisms and data governance practices consistent with international standards.
The fourth layer strengthens transparency and human oversight. AI should support human decision-making, not replace it in contexts where people’s rights, opportunities and wellbeing are at stake. Citizens must know when they are interacting with AI systems, and meaningful human review must remain available.
The fifth layer is where South Africa can make a distinctive contribution to global governance. This layer addresses what we term “process governance” or “reasoning auditability”. In practical terms, this means requiring high-risk AI systems to demonstrate source traceability, input traceability, reproducibility, evidentiary grounding and independent auditability.
By placing transparency, accountability and reasoning auditability at the centre of our legislative framework, we can demonstrate that innovation and constitutional democracy are not competing objectives. They are mutually reinforcing foundations of a trustworthy digital future.
The challenge before us is significant. But so too is the opportunity. We should seize it.
- Diko is chair of the communications & digital technologies portfolio committee









Would you like to comment on this article?
Sign up (it's quick and free) or sign in now.
Please read our Comment Policy before commenting.