On 2 August 2026, the transparency obligations in Article 50 of the EU AI Act became applicable. They may not apply directly to most South African organisations. That is not really the point. What matters is the direction of travel.

Regulatory expectations are moving from broad commitments to responsible artificial intelligence towards specific, auditable evidence. Organisations are increasingly expected to show when people are interacting with AI, when content has been generated or manipulated, and how affected individuals are informed.

For boards and Audit and Risk Committees, this signals an important shift in the oversight lens. Asking whether the organisation has an AI policy remains relevant, but it is no longer enough.

What evidence shows that the organisation’s AI controls are working — and who has verified it?

Why the traditional lens needs to evolve

Traditional oversight has often relied on policies, frameworks, management attestations and periodic reporting. These remain important. The difficulty is that AI can change faster than the governance processes designed to oversee it.

AI capability may be embedded in customer platforms, human-resources systems, productivity tools and vendor applications. It may arrive through a software update rather than a formal procurement decision. The organisation may therefore be deploying AI without a complete view of where it is being used, how it is changing or what decisions it influences.

A policy can set the right intention while the organisation’s actual AI footprint continues to evolve outside the line of sight of those charged with oversight.

Transparency must become demonstrable

Transparency as a governance principle is valuable. Transparency as a demonstrable outcome is more demanding: the organisation can produce evidence that disclosures, controls and accountability mechanisms are operating in practice.

That evidence might include a current inventory of AI systems, records of AI capabilities embedded in vendor platforms, workflow-based disclosures to people interacting with AI, controls over synthetic content, testing results and independent assurance over the operation of those controls.

The governing body does not need to manage these mechanisms. It does need sufficient evidence to determine whether management has implemented them and whether assurance over their effectiveness is credible.

Three areas that deserve attention

1. AI interactions

Can the organisation identify where customers, employees, suppliers or members of the public interact with AI? Are disclosures built into those interactions, and has anyone independently verified that they appear consistently?

2. Synthetic content

How does the organisation govern AI-generated content it produces? Equally, what controls help it detect manipulated content entering payment, verification, recruitment or communication channels? An absence of reported incidents is not evidence of resilience when detection capability has not been tested.

3. Vendor-embedded AI

Does the organisation know when vendors add material AI capabilities to systems already in use? Do contracts require notification, clarify responsibilities and permit meaningful assurance? A register that is not updated and verified provides little protection against a rapidly changing technology estate.

A more useful board conversation

The oversight question is no longer confined to whether appropriate rules have been adopted. Boards and committees should ask whether management can demonstrate what AI is being used, what controls apply, what has changed and what independent assurance supports the conclusions reported to them.

This does not discard the traditional oversight lens. It strengthens it. Policy, risk appetite, accountability and assurance remain essential; the evolution lies in testing them against operational evidence.

Article 50 is therefore relevant beyond its direct legal reach. It illustrates a broader governance trajectory: responsible AI will increasingly be judged not by the quality of the organisation’s intentions, but by the evidence of what happens in practice.

Questions for boards and Audit and Risk Committees

  • Can management produce a current inventory of AI systems, including AI embedded in vendor tools?
  • What evidence demonstrates that people are informed when they interact with AI?
  • How are outbound AI-generated content and inbound synthetic-content risks controlled?
  • How does the organisation learn when vendors materially change their AI capabilities?
  • Is assurance based on management self-assessment, internal audit work or independent verification?