The New Teller Is A Black Box


By Jabulani Chibaya


From a Spanish bank’s open-sourced code to Zimbabwe’s new national AI strategy, the rules for the machines that now decide who gets paid, insured and lent to are being written in real time — and Southern Africa has a rare chance to help write them.

Somewhere in London or Cape Town, a Zimbabwean nurse sends money home to Harare this weekend, the way millions of others do every month. Before it lands, it will pass through the hands of several decision-makers who have never met her, never met her mother, and have no hands at all. An algorithm will score the transfer for fraud.

Another will screen it against sanctions lists. A third may quietly decide the payment “looks unusual” and needs a human to look again on Monday.

Zimbabweans abroad sent home an estimated US$2.45 billion last year alone, according to the Reserve Bank, with South Africa and the United Kingdom supplying most of it; add the corridors running the other way, and across the region, and you start to see the real story hiding behind a phrase that sounds bloodless: AI governance.

It is easy to dismiss “AI governance” as a slide from a consulting deck, nodded through before lunch. That would be a mistake. Deloitte’s own governance research puts numbers behind the anxiety: more than half of organisations say they are moving “fast” on generative AI, three-quarters expect to overhaul their talent strategies within two years because of it, and nearly eight in ten plan to spend even more next year.

South Africa is telling the same story at home: banks that spent under a million rand on AI in 2024 are, on current plans, set to spend upwards of thirty million rand each in 2026, with the financial sector projected to add hundreds of billions of rand to GDP through AI by 2030.

Zimbabwe, not to be left behind, launched its own National AI Strategy in March, naming finance as one of the sectors it is built to transform. Adoption, in short, is not coming. It has arrived. The only open question is whether oversight arrives with it, or three years too late.

That question matters more in finance than almost anywhere else, because the product a bank, insurer or remittance company sells is not really money. It is trust, wrapped in money. Deloitte’s own research on AI risk lists the obvious suspects: hallucination and inaccuracy, bias and unethical use, breaches of intellectual property and confidentiality.

In a hospital, a hallucinating model is a scandal. In a bank, it is someone’s rent money, someone’s insurance claim, someone’s loan for school fees, decided wrongly by a system that cannot be cross-examined. Get AI governance right, and you get faster underwriting, sharper fraud detection and decisions people can actually query. Get it wrong once, publicly, and you can spend years re-earning the trust an algorithm burned in a second.

Two rulebooks, one landing date

Two frameworks are doing more than anything else to set the global tone here, and both are worth understanding in plain language rather than legal jargon. The European Union’s AI Act works like a graduated traffic law: the riskier the system, the stricter the rules. Credit scoring and insurance underwriting are explicitly named as “high-risk,” in the same category as systems that touch someone’s safety or livelihood.

This year Brussels pushed the compliance deadline for those high-risk systems from August 2026 out to December 2027, after admitting its own technical standards weren’t ready in time. Here is the sharp part many risk teams are missing: that delay does not touch the rules on general-purpose AI models or on labelling AI-generated content, which still land in August 2026 as originally planned. Anyone quietly telling their board “we have more time now” is reading only one of two clocks.

The second framework, ISO 42001, is not law at all — it is closer to the certificate of fitness your local garage issues before a kombi is allowed to carry passengers. Nobody is forced to get it. But increasingly, the banks, card networks and correspondent institutions that African fintechs depend on for cross-border rails are starting to ask for it, the same way international clients started asking for ISO 27001 certificates once cybersecurity got serious.

Neither South Africa nor Zimbabwe yet has a binding AI law of its own — South Africa’s national AI policy is still working through public consultation, and Zimbabwe’s brand-new strategy is deliberately built around sandboxes and principles rather than fines. That is not a loophole. It is a head start, for any institution willing to build the discipline before a regulator forces it to.

A bank opens its playbook

In June, Spain’s Banco Santander did something no major global bank had done before: it put its actual AI governance tools, not just a glossy ethics statement, into the public domain, free, under an open licence. The flagship release, built by its internal AI Lab, sets hard checkpoints on high-stakes AI decisions, tiered from light-touch review up to mechanical, non-negotiable gates a model cannot talk its way around.

Alongside it came tools for testing lending and screening models for bias, and a way to generate realistic but entirely synthetic fraud data, so smaller institutions can stress-test their fraud systems without ever touching a real customer’s information. Think of it as a stokvel treasurer publishing her exact ledger format so every stokvel in the neighbourhood can adopt the same trustworthy bookkeeping, instead of each one improvising and hoping. No African bank or fintech needs to build this kind of infrastructure alone from a blank page any more. The code is sitting on GitHub, waiting to be forked.

Know thy machine before you govern it

Deloitte’s governance framework, applied to AI, breaks a board’s job into six honest questions: governance of the governance itself, strategy, risk, performance, talent and culture. Underneath all six sits one unglamorous starting point most institutions skip: do you actually know what AI is running inside your own organisation?

Not the pilot project the innovation team is proud of — every model touching a lending decision, a claims payout, a sanctions screen, a remittance route. Most boards cannot answer that with a straight face. It is the equivalent of running a delivery fleet without a list of how many trucks you own, what they are carrying, or who is driving. You cannot govern what you have not first counted.

For the boardroom

The practical version of this, stripped of consultant-speak, is a short list any board or executive committee can run through this quarter. Who owns the “off switch” if a model starts wrongly declining legitimate remittances, or worse, waving fraudulent ones through? Is there a living inventory of every AI system touching money decisions, reviewed with the same seriousness as the loan book?

Does management have a genuine view of where AI is heading in the business over the next three years, or only where it sits today? And critically: is governance one named executive’s job, or is it “everyone’s responsibility,” which in practice usually means nobody’s? Boards that can answer these plainly are not slower. They are the ones still trusted with people’s money when something inevitably goes wrong somewhere in the industry.

For the founder’s desk

None of this is only a big-bank problem. Fintech founders often treat governance as something to bolt on once a regulator or a big investor asks for it. That is backwards, and expensive. Documenting which decisions your model makes, keeping a clean record of the data it trained on, and knowing which features are genuinely “high-stakes” versus merely convenient, costs very little with fifty users and a great deal with fifty thousand and a subpoena.

Zimbabwe’s new AI Innovation Fund and regulatory sandbox, and South Africa’s proposed equivalent, are both explicit bets that young companies who build this discipline in early will move faster later, not slower. A two-person lending app does not need a Basel-sized compliance department. It does need to know, honestly, which three or four decisions its model makes actually matter.

Guardrails, not roadblocks

There is a tempting but lazy story that governance and innovation are natural enemies, one slowing the other down. The opposite is closer to true. Brakes do not make a car slower; they are precisely what let a driver go fast with any confidence at all. A region where institutions have often had to fight hard to earn ordinary people’s trust has, in AI governance, a genuine chance to compete on something other than price or marketing: on being the fintech, the insurer, the remittance app that people actually believe.

That is not a small thing in economies built on informal trust networks, stokvels, mikando, and the simple promise that a relative’s money will arrive.

So picture that nurse in London, sending money home this weekend. The rules governing the invisible machinery around her transaction are being rewritten right now, in Brussels, in a bank’s repository in Madrid, and, encouragingly, in Pretoria and Harare too. The institutions that take this seriously before they are forced to will not just dodge fines further down the line.

They will be the ones still standing, still trusted, when the next wave of AI arrives, while the ones who treated governance as an afterthought are explaining themselves to a regulator, or worse, to a customer whose money didn’t arrive on time.


Jabulani Chibaya is the CEO and Founder of GourdAI, an AI strategy and data advisory firm based in Harare. Stay Connected On The DSE News Network

Leave a Reply

Your email address will not be published. Required fields are marked *