Nakhile Consulting
Responses
In your opinion, what outcomes would make the first Global Dialogue on AI Governance a success?
The Dialogue will succeed if it moves the international conversation from principles to instruments. Most existing AI governance work — UNESCO's ethics recommendation, the OECD principles, regional frameworks — remains at the level of values: AI should be fair, accountable, explainable. These are necessary but no longer sufficient. The frontier question is operational: by what producible instrument can a board, a regulator, or an auditor demonstrate that fairness, accountability and explainability are being delivered at the level of the individual decision an AI system enables? A successful first Dialogue would, in my view, deliver three outcomes. First, agreed working language for the interoperability of governance approaches — not uniformity, which is unrealistic and would extinguish jurisdictional diversity, but interoperability that lets a methodology developed in South Africa be cited credibly in Singapore and built upon in Brazil. Second, recognition that decision-centric governance is a necessary complement to model-centric governance — that the governance gap between the model layer (where SR 11-7 and ISO/IEC 23894 already operate) and the financial-statement layer (where audit standards already operate) is where AI risk actually crystallises, and that this gap requires its own governance language. Third, meaningful representation from emerging-market practitioners and applied risk professionals — auditors, chief risk officers, and accountants delivering governance inside institutions — as a distinct voice alongside Member States, civil society, academia and the technical community. A Dialogue dominated by aspirational principles would replicate work already done. A Dialogue focused on the operational, interoperable, applied layer would be the contribution this moment requires.
From your perspective, which of the following thematic areas identified by the General Assembly Resolution 79/325 for the AI Dialogue reflect your priorities for urgent action and active engagement?
- Safe, secure and trustworthy AI
- Interoperability of governance approaches
- Protection and promotion of human rights
- Transparency, accountability, and human oversight
Please briefly explain your selection.
3
These four priorities form a single architecture from a financial services governance practitioner's perspective. Safe, secure and trustworthy AI and Interoperability of governance approaches together define the supply side of governance - the methodologies, frameworks and standards by which AI is governed within and across jurisdictions. South Africa, where my practice operates, sits at the intersection of multiple instruments: the National Credit Act creates per-decision adverse-action obligations; the Policyholder Protection Rules require written reasons for individual claims declines; POPIA section 71 grants policyholders the right to object to automated decisions affecting their legal rights. None of these are coordinated with each other, and none are formally interoperable with international instruments like SR 11-7 or the NIST AI Risk Management Framework. The result is institutions that can be SR 11-7 compliant at the model layer and still in breach of PPR written-reasons obligations at the decision layer. Interoperability is not abstract; it is operational. Protection and promotion of human rights and Transparency, accountability, and human oversight together define the demand side - what individuals, regulators, and the public can legitimately expect of AI-enabled decisions. These two priorities are most credible when grounded in jurisdictions that have already operationalised individual-decision rights - POPIA section 71 in South Africa is one such instance, predating GDPR Article 22 in operational specificity in claims and credit decisioning. Transparency cannot be a principle; it must be producible at the level of an individual decision letter to an individual customer. The four priorities together describe the gap between principles and practice. Closing that gap is, in my view, the central work of the Dialogue.
In your opinion, are there any cross-cutting or emerging issues not captured by the listed themes above? If so, please explain.
5
Three issues warrant naming. First, decision-to-signal latency. AI-enabled decisions create financial and human consequences before the institution's monitoring infrastructure detects them. Most model risk monitoring runs on monthly or quarterly cycles; the financial impact of model drift accumulates faster than the cycle. The board sees the result in the financial statements; the cause in the model risk pack; the two are not joined. This temporal gap between decision and signal is governance-critical and yet absent from the seven listed themes. Second, the governance vacuum between the model and the financial statement. Traditional governance protects the model (model risk management) and the financial statement (audit). The decision system between them - where AI-driven judgement meets institutional consequence and customer harm - is operationally governed by no single function. In financial institutions this manifests as an unstaffed C-suite role between Chief Risk Officer (model risk), Chief Data Officer (data and infrastructure), and Chief Technology Officer (platform). The thematic clusters do not name this structural gap; they presuppose that some function owns the decision layer. Most institutions, in our experience, do not. Third, the emergence of agentic AI. When AI systems move from advising decisions to autonomously initiating transactions - agentic payment infrastructure, autonomous treasury operations, AI-orchestrated trade execution - the unit of governance shifts from the decision class to the agent itself. The fiduciary authority of an autonomous AI agent transacting on an institution's behalf is currently undefined in international, sectoral and most national frameworks. This is not a future issue; agentic systems are in production in payments today. The Dialogue should make space for this question explicitly rather than wait for it to arrive through enforcement actions.
How are the governance gaps and related developments/advances in the thematic areas you selected above affecting your country, region, or sector? Please highlight the most significant challenges.
South Africa, and Africa more broadly, is in an unusual position: AI adoption in financial services is rapid and operationally meaningful — automated credit decisioning at fintech lenders processes tens of thousands of applications monthly; major short-term insurers settle thousands of motor claims through automated engines per month — while the formal AI governance infrastructure is still consolidating. The most significant challenge is the gap between regulatory ambition and institutional capacity. South Africa has unusually advanced individual-decision protections on paper: POPIA section 71 grants automated-decision objection rights; the Policyholder Protection Rules require written reasons for claims declines; the NCR requires reasons-on-record for adverse credit action; the FSCA/SARB Joint Standards on AI in Financial Services come into force in July 2026. In practice, most institutions cannot demonstrate compliance at the individual-decision level because their governance has been calibrated to model-level oversight. The mismatch is not theoretical — it is a live regulatory exposure the moment a complainant tests it. The most significant opportunity is symmetric. South African institutions, supervisors and consultants are operationalising individual-decision-level governance ahead of jurisdictions that have only principles-level frameworks. Methodologies developed here speak directly to the frontier the Dialogue is convening. Africa is rarely positioned as a producer of AI governance instruments. It can be. The Continental Strategy on Artificial Intelligence adopted by the African Union in 2024 already names sovereign AI governance as a priority. The next step is for that ambition to become methodologies that can be cited, tested, and built upon by other jurisdictions facing similar institutional realities.
What role can the AI Dialogue play in advancing international cooperation on AI governance?
The most useful role the Dialogue can play is to convene the operational layer of governance, not just the principles layer. Principles-level cooperation — UNESCO's Recommendation on the Ethics of AI, the OECD AI Principles, the G7 Hiroshima Process, the Bletchley Declaration — has produced strong values consensus and weak operational outcomes. The next decade requires the inverse. Three specific cooperative roles would have outsized impact. First, methodology peer review. The Dialogue can host structured peer review of jurisdictional and institutional governance methodologies — frameworks like the FSCA/SARB Joint Standards in South Africa, the EU AI Act's high-risk classification, NIST AI RMF, ISO/IEC 42001 — to surface where they converge, diverge, and could be made interoperable without forcing uniformity. Second, instrument exchange. Member States and practitioners should be able to identify and adopt specific operational instruments — assessment templates, risk registers, board reporting frameworks, materiality scoring methodologies — developed in other jurisdictions, with appropriate sectoral adaptation. The Dialogue can be the forum where these instruments are catalogued and made discoverable. Third, applied case-study repositories. The Dialogue should support a growing public repository of anonymised case studies in AI governance — what worked, what did not, what regulators found, what audit committees challenged. This kind of institutional learning is currently locked inside private engagements and Big Four advisory deliverables. The Dialogue's distinctive contribution will not be another set of principles. It will be the infrastructure of practice: peer review, instrument exchange, shared case studies, methodology clinics. International cooperation on AI governance ultimately succeeds if institutions in different jurisdictions can adopt each other's working methods.
What are some of the existing initiatives, partnerships, or mechanisms that the AI Dialogue should build upon or connect with, and what added value could the AI Dialogue bring?
The Dialogue should not begin from a blank page. Substantive initiatives already exist that the Dialogue can connect, extend, and add value to. Standards-setting and methodology infrastructure. NIST AI Risk Management Framework (US); ISO/IEC 42001 (AI Management Systems) and ISO/IEC 23894 (AI Risk Management); the Federal Reserve's SR 11-7 model risk supervisory letter; the Bank of England's SS1/23 model risk management principles. These are the operational backbone of much current institutional practice. Regional and supranational frameworks. The European Union AI Act and its risk-tiering approach. The Council of Europe Framework Convention on AI. The African Union Continental Strategy on AI (2024). The ASEAN Guide on AI Governance and Ethics. Singapore's Model AI Governance Framework. These are the jurisdictional layers within which institutional practice operates. Sectoral instruments. The FSCA/SARB Joint Standards on AI in Financial Services (South Africa, effective July 2026). The European Insurance and Occupational Pensions Authority guidance on AI. The Basel Committee's principles on model risk. UK FCA guidance on AI in financial services. UN ecosystem. UNESCO's Recommendation on the Ethics of AI (2021). The UN Secretary-General's High-Level Advisory Body on AI. ITU AI for Good. The Global Digital Compact (2024). The Dialogue's added value is not to replicate any of these. It is to occupy the interoperability layer above them: the forum where principles meet methodologies, where Member States meet practitioners, where standards bodies meet sectoral regulators, where the EU AI Act's classification logic can be tested against ISO/IEC 42001, the FSCA/SARB Joint Standards, and POPIA in a single conversation. Connection, not duplication.
How can different stakeholders contribute to the AI Dialogue? Please share recommendations for the format and structure of the AI Dialogue.
The current categorisation — Member States, civil society, academia, technical community, private sector, international organisations — is appropriate but sub-optimal. Within "private sector" and "academia" specifically, two distinct communities are currently merged that should be separated. The applied practitioner community. Auditors, chief risk officers, internal audit functions, sectoral consultants — the people who actually operationalise governance inside institutions — are submitting under "private sector" and being heard alongside AI vendors and large platform companies whose interests and expertise are entirely different. This community has expertise the Dialogue cannot replicate from any other category, and currently has no distinct seat at the table. The implementing academic community. Distinct from AI ethics and policy academics, the implementing academic — typically embedded in business schools, law schools, engineering schools and accountancy faculties — is the community translating frameworks into curricula and translating practice into research. This community is currently underweighted relative to AI safety and AI ethics scholars whose contribution, while valuable, addresses a different question. Format recommendations. Three formats would draw out the practitioner voice specifically. Methodology clinics — half-day workshops where practitioners walk through actual governance instruments (templates, scoring frameworks, board reports) and receive structured peer review. Sector demonstration sessions — banking, insurance, health, public services in one room, comparing the same governance question across sectors. Cross-jurisdictional case panels — three jurisdictions presenting how they handled the same AI governance scenario, with structured comparison. These formats privilege application over advocacy and grounded comparison over abstract debate. They are the formats most likely to produce durable instruments.
Which voices, communities, or perspectives are currently underrepresented in global discussions on AI governance? How could they be included?
Five constituencies are currently underrepresented in international AI governance dialogue, in my observation. African practitioners and African institutional voices. African AI governance is largely discussed about rather than by African voices. The African Union Continental Strategy on AI (2024) has not been substantively cited in international AI governance dialogue. African academics, regulators and practitioners must be present as principal voices, not as case studies in others' submissions. Emerging-market sectoral regulators. South Africa's FSCA, Brazil's BCB, India's RBI, the Philippines' BSP, Kenya's CMA — sectoral regulators in emerging markets are operationalising AI governance ahead of many of their developed-market counterparts and are rarely heard in international conversations dominated by US, UK and EU regulators. Their experience is instructive. Women in technical AI governance roles globally. AI governance dialogue, while improving, remains dominated by male voices. Women practitioners in technical AI risk roles are present in industry but underrepresented in panels, advisory bodies, and submission processes. Active outreach is required, not passive openness. Frontline workers and customers affected by AI-enabled decisions. Customers who have experienced an automated claims decline, applicants who have received an algorithmic credit refusal, employees affected by AI-driven scheduling — these voices are routinely cited but rarely present. Civil society organisations representing them carry the message but cannot replace it. The internal audit and chartered accountancy community. Globally, the institutions that ultimately attest to financial governance — the audit firms, the professional bodies — are not formally represented in AI governance dialogues commensurate with the role they play in institutional accountability. Inclusion of these voices requires structured outreach, not invitations passively published.
What innovative engagement formats could most effectively foster meaningful and dynamic engagement during the AI Dialogue?
Five formats would foster more dynamic engagement than panel-based plenary structure alone. Living document submissions. Stakeholder submissions that evolve through public commentary across the consultation period. Currently submissions are static, one-shot documents. A living-document approach — submission opens, peers comment, author responds, submission tightens — would surface convergence and disagreement productively, and would create durable artefacts the Dialogue can reference. Methodology clinics. Structured, half-day sessions where a practitioner presents an actual governance instrument — a risk-scoring template, a board reporting framework, a model card requirement — and a multi-stakeholder panel works through it in real time. The output is improved methodology, not just shared opinions. Cross-jurisdictional case panels. The same governance scenario (a credit-scoring model produces materially adverse outcomes for a protected demographic; a vendor AI produces systematic settlement errors; an LLM hallucinates in customer-facing communications) presented from three jurisdictional perspectives. Structured comparison across regulators, practitioners and academics in one session. Anonymous case-study submissions. A formal channel for institutional submissions to the Dialogue with appropriate anonymisation of the institution. The applied learning currently locked inside Big Four advisory deliverables, regulatory enforcement files, and internal audit reports could populate a public learning record without exposing institutions to reputational consequences. Pre-Dialogue practitioner working groups. Six to eight working groups convening before the formal Dialogue, each focused on a specific instrument-level question (decision-classification methodologies, board reporting templates, vendor governance, agentic AI). Outputs feed the Dialogue as substantive material, not just advocacy positions. These formats privilege production over deliberation. The Dialogue's lasting impact will be measured by what institutions adopt, not by what was said.
Please share examples of policies, practices, platforms, or approaches that promote effective AI governance or offer concrete solutions to addressing its challenges.
1
Three jurisdictional examples and one methodology-level example illustrate effective AI governance practices. POPIA section 71 (South Africa). South Africa's data protection law grants individuals the right to object to automated decisions affecting their legal rights. The obligation attaches at the level of an individual decision, not the model. Institutions cannot satisfy section 71 with general AI policies; they must demonstrate per-decision objection mechanisms. POPIA s71 predates GDPR Article 22 in some operational specificity. Policyholder Protection Rules (FSCA, South Africa). The PPR requires insurers to provide written reasons for claims declines. Operationalised in an AI context, this means a per-decision explanation framework - not a general institutional disclosure. This is one of the clearest existing regulatory expressions of explainability obligations on AI-enabled decisions in financial services globally. The Decision Materiality Index (Nakhile Consulting, 2026). A producible methodology that scores AI-enabled decisions on seven dimensions (financial consequence, customer harm, regulatory obligation intensity, reversibility, explainability gap, systemic exposure, accountability). Designed to be interoperable with SR 11-7, NIST AI RMF, ISO/IEC 42001, and the FSCA/SARB Joint Standards. Applied in production engagements in banking and insurance. The methodology is documented in a public-classification whitepaper available on request and is offered as a contribution to the Dialogue's instrument-level cooperation work. Decision-centric methodologies are a necessary complement to model-centric standards.