Different arguments are being had in South Africa about who’s on the hook when an AI agent will get it incorrect. While all of it’s value having, none of it issues in case you can’t inform anybody what your agent truly did.
That’s the half lacking from the legal responsibility dialog, and it’s the half that decides who wins it.
The drawback with the legal responsibility argument
Here’s the state of affairs each a kind of legal responsibility debates assumes: one thing goes incorrect, an agent takes an motion, and any individual has to ascertain who’s accountable – the deploying organisation, below part 25(c) of the Electronic Communications and Transactions Act, or a vendor whose phrases exclude autonomous behaviour.
Whichever method you argue it, finally somebody has to show what occurred. What knowledge the agent touched. What triggered the motion. Whose credentials it was working below. What it was authorised to do and whether or not it stayed inside that authorisation.
Most organisations can’t produce that, and the issue isn’t essentially the legislation. It’s the proof. The agent might merely not have left sufficient of a path to elucidate what occurred to an investigator, arbitrator or regulator.
Why the path doesn’t exist
According to the 2026 CISO AI Risk Report, 92% of safety leaders say they lack actual visibility into what their AI brokers are doing. Three in 4 have already discovered AI instruments operating in manufacturing no one signed off on. That’s not an edge case. It’s turning into a standard enterprise drawback.
Agents don’t behave just like the issues our logging was constructed to catch. They don’t set off MFA prompts. They don’t generate the session information a SIEM is aware of how you can parse. They can transfer shortly, utilizing the permissions they’ve been given, with out anybody watching each motion because it occurs.
So in the case of answering “what exactly happened here,” quite a lot of organisations are going to find the sincere reply is: we don’t totally know.
Why this bites twice as onerous in South Africa
Reported compromises to the Regulator have been up 60% within the second half of 2025 alone, and the eServices portal constructed to catch them isn’t thinking about “the agent did something, we’re not sure what.”
For regulated monetary companies companies, it’s worse. The FSCA’s Joint Standard places cybersecurity governance failures at board stage, and board-level accountability is troublesome to dismiss with a shrug.
Whether you’re defending the corporate or attempting to level the finger at a vendor, the case is barely pretty much as good because the proof behind it. Right now, most South African enterprises could be arguing from a place of “we think,” not “we know.”
What truly closes the hole
Not a much bigger authorized workforce. Not a better contract clause, though you need to have these too. The reply is understanding which brokers you could have, what they’ll entry and what they’ve carried out – and preserve sufficient proof to reconstruct it later.
That’s a listing drawback earlier than it’s a authorized drawback. Where are our brokers? What can they entry? And if one thing goes incorrect, can we present what they did? Most boards can’t yet answer the primary of these with any confidence.
I’ll be sincere: we’re not there but both. TrendAI included. Nobody on this business will get to assert it’s solved. But there’s an enormous distinction between not having all the pieces solved and never having the ability to discover out what occurred when one thing goes incorrect.
The legal responsibility query will get settled finally, case by case, in entrance of a choose or an arbitrator or a regulator. Whoever wins that argument would be the occasion that may present its work. Right now, in most South African boardrooms, no one can.