Trustworthy AI: balancing innovation and the law in South Africa

post-title

Nathan-Ross Adams, founder and managing director of ITLawCo, urges CIOs and compliance officers to ensure that AI is responsibly managed.

AI is now learning at a speed that would make a Formula 1 car seem sluggish. Algorithms, those invisible wizards behind the curtain, are becoming part of our daily lives, often in ways we don’t even notice.

Like an overconfident teenager, AI is brilliant, but not always responsible. And that’s where we – the grown-ups in the room, the lawmakers, compliance officers, and chief information officers (CIOs) – come in to keep things in check.

AI can do incredible things: predicting disease outbreaks, preventing financial fraud, and even suggesting the perfect playlist for your morning coffee. But like any powerful tool, AI has its risks. Enter the idea of ‘trustworthy AI’ – a fusion of progress and caution, where data protection, fairness and transparency must sit alongside innovation.

Why we need trustworthy AI

Trustworthy AI isn’t just about stopping the robots from taking over (though that might be a future concern). It’s about making sure these systems operate in ways that are transparent, fair, and legal. As South Africa gears up for the Fourth Industrial Revolution, businesses and governments are excited by the possibilities AI presents – but they’re also keeping a close eye on the legal playbook.

Trustworthy AI boils down to two key ideas: trust and accountability. People need to trust that AI won’t misuse their data or make biased decisions. At the same time, businesses need to ensure their AI systems can be checked and explained. That’s where CIOs come in, balancing the promise of AI with the heavy responsibility of ensuring compliance and transparency.

AI and the law: POPIA and what it means

In South Africa, the Protection of Personal Information Act (POPIA) is the go-to law for how organisations handle personal data. CIOs, once focused on keeping systems running smoothly, now find themselves with a far weightier task: ensuring their AI systems don’t inadvertently trample over people’s rights. After all, AI feeds on data, and it’s alarmingly easy for it to overstep the boundaries laid out by POPIA.

POPIA’s core principle is simple: personal data must be processed lawfully and transparently. Sounds straightforward, right? Not quite. AI systems often operate in mysterious, black-box ways that even their creators struggle to explain. Yet under the law, organisations must show exactly how they’re using people’s data and why. No “the algorithm said so” excuses allowed.

A perfect example of this tension is the recent complaint by the Southern African Artificial Intelligence Association (SAAIA) against LinkedIn. SAAIA argued that LinkedIn’s AI was using people’s data to profile and target them, without clear consent – a potential violation of POPIA. The case is still under review, but it’s a sign of things to come. If LinkedIn, a global tech giant, is on the InfoRegSA radar, you can bet that other AI-powered platforms will follow suit.

The role of the CIO in navigating the AI legal landscape

So, where does that leave CIOs in South Africa? Well, your role has evolved dramatically. You’re no longer just the ones who keep the lights on in the IT department; you’re now the guardians of personal data, ensuring that their AI systems are playing by the rules.

POPIA places a heavy responsibility on those who control and process personal data. A CIO must ensure that any AI system they oversee not only works well but also complies with data protection laws. And this isn’t just a ‘slap on the wrist’ situation. Fines for non-compliance can reach up to R10 million, and in some cases, there’s even the risk of imprisonment – not to mention the reputational hit that can follow. No one wants to be the company that made headlines for AI gone rogue.

But here’s the delicious irony: while AI increases the risk of non-compliance, it can also be the solution. AI tools can monitor data use, flag suspicious activity and ensure companies stay within the legal limits. In other words, AI can help organisations avoid falling foul of AI.

Building trust and accountability in AI

At the heart of all this is trust. Customers need to trust that businesses will use their data responsibly. Regulators need to trust that companies will comply with the law. And businesses themselves need to trust that AI, used wisely, will drive growth without landing them in legal hot water.

To build that trust, companies must focus on explainability. No more hiding behind complex algorithms. If an AI system makes a decision, companies must be able to explain why and how that decision was made. It’s not enough to say, “the AI said so”. CIOs must ensure that AI systems are understandable, transparent, and, most importantly, accountable.

The rise of AI governance frameworks is a step in the right direction. By establishing clear rules for the ethical use of AI, businesses can align their operations with legal standards while reassuring regulators and customers alike that they are committed to doing things right.

A call to action for CIOs

CIOs in South Africa stand at a crossroads. On one hand, you have the opportunity to harness AI’s power to revolutionise your businesses. On the other hand, you must ensure that this innovation doesn’t run roughshod over people’s rights or legal requirements. It’s a delicate balance, but with the right mix of technological savvy, legal insight and ethical awareness, it’s one that can be managed.

In this new world, CIOs are no longer just managing technology. They’re managing trust. And that, more than any piece of hardware or software, is what will define your success. Trustworthy AI isn’t just a buzzword; it’s the future. And the future begins now.

Related articles

Open weights, open futures

Sasol’s IT digital and innovation enablement lead Bramley Maetsa and Microsoft’s senior account technology strategist Phumlani Nhlapo explore why the industry's Open-AI coalition changes the sovereignty debate.

Top