Does your board understand AI well enough to govern it, or only well enough to approve the budget?
AI Governance Is Becoming a Board Competence, Not an IT Competence
Somewhere in Africa this week, a board is approving a decision it does not fully understand.
A bank switches on an AI tool to catch fraud. An insurer uses one to support underwriting. A telecommunications company uses it to predict which customers are about to leave. A public agency introduces an assistant to help process citizen applications faster.
The chain of responsibility looks tidy. The board approved the investment. Management ran the implementation. The technology team maintains the system. Everyone can point to their part.
Then the system does something that matters. It declines a loan. It freezes a legitimate customer’s account. It ranks one job applicant above another. It sends a citizen’s application into a queue it will never come back from. And the tidy chain produces the one question it cannot answer cleanly:
When the machine affects a customer, an employee, a citizen or an investor, who is accountable for the decision?
I have spent years advising regulators, boards and executive teams across African markets on digital finance and technology governance. I sit on boards myself. And I can tell you that this question is arriving faster than the structures meant to answer it. Management may deploy AI. The board remains responsible for governing the decisions AI influences. That distinction is the entire argument, and most boards have not yet absorbed it.
This is not a plea for directors to learn to code. It is not about understanding how a model is trained. It is about the minimum institutional competence a board now needs to govern an organisation in which serious decisions are increasingly shaped by machines.
AI Did Not Arrive With a Strategy Document
Here is the assumption that will make boards late. It is the belief that AI governance begins when the board approves something called an “AI transformation,” with a budget line and a steering committee.
It does not work that way.
AI rarely comes through the front door. It arrives quietly, folded into decisions the institution already makes. Fraud monitoring. Credit scoring. Customer service. Underwriting. Claims. Recruitment. Transaction monitoring. Cyber defence. Document processing. Revenue forecasting. Public service delivery. A vendor upgrades a product and an AI component comes with it. A team adopts a tool because it is faster than the last one. None of this looks like a strategic AI decision on the day it happens.
So the governance problem can appear long before the board believes the organisation has made any AI decision at all. The board may never have approved an enterprise AI strategy. But it may already govern an enterprise in which dozens of decisions are shaped by AI.
Kenya shows that regulators have noticed. The Central Bank of Kenya ran a dedicated survey of AI use across its banking sector in 2025, examining institutions’ AI and data strategies, their actual AI activity, and how they manage AI risk, and it signalled that the findings would shape its regulatory guidance. Look at what that survey assumes. The regulator is no longer asking whether banks are experimenting with AI. It is asking how those experiments are governed.
The Rules Differ Across Africa. The Direction Does Not.
Let me be precise, because precision matters here. Africa does not have a harmonised AI regime. Our markets move at very different speeds, with very different institutional capacity. Pretending otherwise helps no one.
But a similar governance problem is surfacing across all of them, and several currents are beginning to run the same way: national AI policies, continental AI principles, technology risk regulation, cybersecurity rules, operational resilience expectations, data protection law, and sector supervision.
This is the part boards most often miss. AI governance will probably not arrive first through an “AI law.” It will arrive through obligations institutions already carry. Risk. Data. Cyber. Conduct. Outsourcing. Operational resilience. A board waiting for a dedicated national AI Act before it acts has misread the moment. Its existing duties may already reach most of the decisions AI is now influencing.
At the continental level, the African Union has already put responsible, development-focused AI on the table, endorsing a Continental Artificial Intelligence Strategy in 2024 that emphasises ethical use, governance and risk management. But continental principles have to be translated into the routines of individual institutions. Who approves an AI system. Who tests it. What reaches the board. Who answers when it causes harm.
South Africa shows where supervision is heading. Its Prudential Authority has written to the financial sector about preparing for frontier AI and AI-accelerated cyber risk, and the language is the tell. The focus is shifting from awareness to execution, operational resilience and demonstrable preparedness. This is no longer framed as something to be merely aware of. It is becoming a matter of evidence.
Ghana shows the perimeter tightening even where AI is not named directly. The Bank of Ghana’s 2026 Cyber and Information Security Directive is part of a wider move to treat technology and information risk as a governance matter rather than technical housekeeping. AI will increasingly sit inside that same accountability structure. Nigeria makes the same point from another angle. The Central Bank of Nigeria’s cybersecurity supervision already covers governance, third-party technology risk, incident response and operational resilience, much of the scaffolding AI governance will stand on.
The rules are not identical. The institutions are not at the same level of maturity. But the direction is getting hard to ignore. Accountability for technology is moving upward, toward executive management and the board.
The Gap Is Not AI Literacy. It Is AI Governance Competence.
There is a steady stream of articles telling boards they need AI training. Most of them describe the wrong thing. They describe literacy, and treat it as the destination.
AI literacy means directors broadly understand what AI is, what it can do, where the organisation uses it, and what opportunities it might open. That is useful. It lets a board follow the conversation.
But governing is not following. AI governance competence means the board can actually decide. Which uses are acceptable and which are not. Which decisions require a human being to stay accountable. What evidence of testing is enough. Which risks must be escalated. What gets reported, and how often. And when a deployment should be stopped.
Hold onto that distinction, because it is the one worth quoting. AI literacy lets a board take part in the conversation. AI governance competence lets it exercise judgement. One is comprehension. The other is authority.
None of this means putting a machine-learning engineer on every board. That is the tempting, shallow fix. The lone technologist, expected to absorb the whole problem so nobody else has to think about it. What a board actually needs is to hold, collectively, enough competence, enough access to independent assurance, and enough quality of information to challenge management with confidence. A board that can do that does not need to build the model. It needs to be able to interrogate the people who did.
A Framework Boards Can Actually Use: BOARD
Boards do not need another taxonomy of AI risk. They need a short set of questions they can ask reliably, in any meeting, about any system. Five hold up.
Boundaries. What is the system allowed to do? What may it recommend, and what may it decide automatically, with no human in the loop? Which decisions must stay with a named human being? This matters most where AI touches credit, insurance, employment, healthcare, identity or access to a public service. The decisions that change lives. Ask: which decisions has the institution decided that AI must never make alone?
Ownership. Not who runs the software. Not who supplied the model. Who owns the outcome. Who is accountable when an AI-assisted decision goes wrong. This is where the instinct to outsource meets its limit. You can buy the technology from a vendor. You cannot buy your way out of accountability for the decision. Ask: when an AI-assisted decision causes financial loss, unfair treatment or regulatory harm, which executive owns it?
Assurance. How does the board actually know the system works the way it was described? Assurance can take many forms. Independent model validation. Bias and fairness testing. Data-quality checks. Cyber testing. Performance monitoring. Human review. Incident reporting. External assurance where the stakes justify it. Management’s confidence is not evidence. Ask: what is the board receiving beyond management’s word that the system works?
Risk and redress. The risk list is familiar to any board: operational, cyber, conduct, discrimination and bias, privacy, reputational, concentration and third-party, legal and regulatory. Redress is the part most frameworks drop, and it is the part that matters most to the person on the other side of the decision. Ask: can a customer, employee or citizen challenge an AI-influenced decision, and can the institution explain it and correct it?
Disclosure and decisions. What must management disclose to the board, and how often? Useful reporting includes an inventory of material AI systems, high-risk use cases, performance failures, customer complaints, material model changes, third-party dependencies, and incidents and near misses. This is what separates governing from spectating. And it produces the question worth saving for last: does the board receive enough information to govern AI, or only enough to approve the budget?
The African Version of This Problem Is Not the European One
It would be easy to import the European and American AI debate wholesale. It would also be wrong, because our context raises questions those debates rarely touch.
Consider imported systems and local data. Many AI tools deployed by African institutions were built and trained elsewhere, on populations that look nothing like the customers they will now judge. The board should ask whether a system was tested against local customers and local conditions. Whether it performs differently across languages, regions, genders or income levels. Whether real data limitations are being hidden behind a confident-looking interface.
Consider third-party dependency. Most African institutions will buy AI, not build it. That multiplies the parties involved. Cloud providers. Model providers. Fintech partners. Consultants. Outsourced processors. And it raises a hard question about whether the institution can even get the information it would need to test what it bought. The principle is simple, and worth saying plainly. You can outsource the model. You cannot outsource the accountability.
Consider informality and exclusion. African data reflects an economy in which a huge share of activity has never been formally recorded. A customer with a thin financial history is not necessarily a risky customer. But a system that can only see what has been recorded may decide that they are. So the question is not only whether the algorithm is accurate. It is sharper than that. What assumptions about African consumers are being converted into automated decisions?
Consider regulatory capacity. Some markets will write specific AI rules quickly. Others will govern AI through existing technology, data, consumer-protection and sector law for years to come. But a board’s duty to exercise judgement does not begin only when a regulator issues an AI directive. Responsibility does not wait for regulatory maturity.
And for the many banking, insurance and telecommunications groups that operate across several African markets, there is one more complication. A single AI system may be deployed across a dozen countries in which data-protection rules, customer behaviour, language, regulatory expectations and routes to appeal all differ. That produces a genuinely pan-African board question. Can a model approved at group level be treated as safe in every African market where it runs? In most cases the honest answer is that group approval and local safety are not the same thing, and a board that assumes they are is exposed.
Africa’s Advantage Is Timing
There is an overreaching version of this argument. The one that claims the rest of the world only bolted on governance after adoption, and that Africa can simply leapfrog. Too neat to defend. Here is the version I will defend. Many African institutions are still early enough in enterprise-wide AI adoption to build governance before AI is deeply embedded and hard to unwind. That window is real. It is also closing.
Rwanda is worth watching as a matter of intent. Its national AI policy explicitly aims at responsible and inclusive AI, paired with a readiness and maturity framework meant to assess capability systematically rather than by assertion. The value is less in the specifics than in the posture. Deciding what good governance looks like before the technology is everywhere, not after.
And African institutions do not have to copy every international model to get this right. They can place AI inside governance structures they already run. Board risk governance. Conduct governance. Data governance. Technology governance. Outsourcing oversight. Operational resilience. Consumer redress. Africa does not need a perfect AI regulatory architecture before its institutions begin to govern AI well.
The Line That Matters
Implementation belongs to management. Assurance will pull in technology, risk, audit, legal and, where needed, outside specialists. But the decisions that define the institution, how much risk it will accept, which choices may be automated, and whether management is genuinely in control, reach the board. That is not a technical burden. It is a governance one, and it cannot be handed downward.
The board does not need to know how to build the model.
It does need to know what the model is allowed to decide, who stays accountable, and what happens when it is wrong.
So here is the question every board should be able to answer without flinching:
Does your board understand AI well enough to govern it, or only well enough to approve the budget?

