AI GOVERNANCE AFRICA:From Principles to Practice

- 00Days
- 00Hours
- 00Minutes
- 00Seconds
In-Person | Online
Course Overview
AI is already running inside South African organisations, in most cases procured rather than built. Boards and executive committees now answer for outputs they cannot explain, produced by models they do not own. The regulatory position has hardened around them. The EU AI Act reaches organisations trading into Europe through its extraterritorial provisions, POPIA governs the data sitting underneath every deployment, and the African Union Continental AI Strategy alongside South Africa’s own policy direction signals where domestic expectation is heading. Generative tools, and increasingly AI agents acting on the organisation’s behalf, have widened the distance between who deploys and who answers.
This programme is built for the people carrying that accountability, not primarily for the people building the systems. Over two days in Johannesburg, Dr Dirk Brand works through the legislation that applies, structured AI risk management under the NIST AI RMF and ISO/IEC 42001, accountability mapped across the full AI lifecycle, and an incident response protocol tested against the clock. The work stays applied throughout, from positioning a live use case against the EU AI Act risk tiers to drafting a 90-day governance roadmap for your own organisation with an owner named against every action.
Learning Objetives
By the close of day two, you will be able to:
* Distinguish AI, machine learning, generative AI and AI agents at the level oversight requires, and name the governance concern each raises
* Assess your organisation’s exposure under the EU AI Act, POPIA and the international instruments shaping African AI policy
* Apply the NIST AI RMF across its four functions within your existing enterprise risk process, supported by ISO/IEC 42001
* Set AI risk appetite and escalation thresholds proportionate to the harm at stake
* Construct an organisational AI policy covering scope, roles, approval routes and acceptable use
* Structure board and executive committee oversight of AI, including generative tools and agents acting on the organisation’s behalf
* Map accountability across the full AI lifecycle, from problem definition and data sourcing through monitoring and decommissioning
* Design an AI incident response protocol with named decision rights, notification duties and post-incident review