Governance OF AI: AI Risk, Explained Simply
In the first article in this series, we drew a line between two conversations that often get collapsed into one: governance OF AI (overseeing how your company uses AI) and governance WITH AI (using AI to make the board's own work better). This article focuses on the first conversation, identifying some of the major areas of risk.
AI risk is a handful of distinct, ordinary risks that show up together whenever AI is involved. None require a technical background to understand, and none require the organisation to have a formal AI strategy before they become the board's problem. As established in the first article, if AI is already embedded in HR, finance, or customer-facing systems, these risks are already alive.
Here are the five worth knowing:
1. Bias
AI systems learn patterns from the data they are trained on. If that data reflects historical inequities, the system can reproduce or amplify them, often without anyone intending it to. A CV-screening tool trained on ten years of hiring data will learn whatever patterns were in that data, including ones the company would never endorse if stated outright. A lending or credit-risk model can end up systematically disadvantaging a group of applicants, even if it was not trained to discriminate against protected characteristics directly, but because other data points can act as proxies for those characteristics — a live concern under the Employment Equity Act and the National Credit Act.
2. Privacy
AI systems are hungry for data — the more data a model has, the better it tends to perform. That creates a pull toward collecting more data, retaining it longer, and feeding it into systems for purposes beyond what it was originally gathered for. A customer service chatbot that logs full conversation transcripts, or a marketing platform that builds detailed behavioural profiles, can quietly drift into territory that both the Information Regulator and customers care about, raising real questions under POPIA.
In addition to this, employees pasting sensitive company or customer data into a public chatbot to save time is now a routine, everyday privacy exposure, not a hypothetical one.
3. Regulatory Exposure
The regulatory picture for AI is moving quickly and unevenly, and an organisation doesn't necessarily have to operate in a heavily regulated industry to be exposed. The EU AI Act and various international frameworks are shaping global best practice, while locally, POPIA, sector-specific rules from regulators such as the FSCA and the SARB, and existing employment and consumer protection law are layering on top of one another. [MANUAL CHECK: South Africa does not yet have a dedicated AI-specific statute; the Department of Communications and Digital Technologies has published a National AI Policy Framework, and this section may need updating to reflect its current status and any subsequent legislative developments.] Employment law already governs how a company can use a hiring algorithm; consumer protection law already governs how a company can use a customer-facing chatbot. AI doesn't create these obligations, but it does make them easier to violate at scale, faster, and without anyone noticing until an outside party does.
4. Failure to Identify Inaccurate Information
This risk is less about the technology failing and more about people trusting it too much. Generative AI tools are fluent, confident, and frequently wrong in ways that are hard to catch. A team that leans on AI-generated summaries, forecasts, or drafts without verification can end up making decisions on foundations that look solid but aren't.
This risk grows quietly. It's a gradual erosion of the habit of double-checking, especially once a tool has been right often enough that people stop questioning it.
5. Reputational Risk
This is the category that ties the others together. A quiet internal AI issue becoming a public one. A biased hiring algorithm, a chatbot that gives a customer bad advice, or a mishandled data set can all become a headline once discovered. Reputational risk will occur when any of the first four go unmanaged long enough to surface externally.
What This Means for Oversight
Bias, privacy concerns, regulatory exposure, unreliability, and reputational fallout are risks boards already have some muscle memory of. Such oversight questions aren't fundamentally different from the ones boards already ask about other operational risks: Who owns this? How is it being monitored? What would we need to see to know if something had gone wrong? But AI changes their shape and speed.
As noted in article one, this is generally Risk or Audit Committee territory — and under King IV, boards are already expected to exercise this kind of oversight over technology and information governance — so it can be treated as an extension of existing risk oversight rather than a brand-new, freestanding category that needs its own separate infrastructure. At some point in the future we will delve into how boards are managing these AI risks.