Erich Barlow · Zenodo (CERN European Organization for Nuclear Research) 2026 · 2026
DOI: 10.5281/zenodo.23114962
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Artificial intelligence (AI) has moved from pilot projects into credit decisions, claims handling, customer service, fraud detection, and the drafting of documents that boards themselves rely on. In South Africa, accountability for those uses rests with the governing body. This white paper addresses a gap between management-level AI governance and director-level oversight. It analyzes the duties of directors under sections 76 and 77 of the Companies Act 71 of 2008, the King IV principles on technology and information, risk, delegation, and assurance, and their successor provisions in the King V Code, which was released on 31 October 2025 and applies to financial years beginning on or after 1 January 2026. It then examines POPIA accountability, security safeguards, breach notification, and automated decision-making; the governing-body duties in Joint Standard 2 of 2024 on cybersecurity and cyber resilience, effective 1 June 2025; and lessons from the 2026 withdrawal of the Draft National AI Policy. ISO/IEC 38507, ISO/IEC 42001, the NIST AI Risk Management Framework, and the EU AI Act serve as reference points. The paper proposes the BOARD Framework for director-level AI oversight, with five pillars: Bound, Organize, Assure, Report, and Develop. It closes with a practical Board AI Toolkit: an oversight charter outline, a sample AI risk appetite statement, a themed question bank, a quarterly board AI report template, a director AI-literacy plan, and a maturity self-assessment.
No comments yet — start the discussion below.