
Last week, Anthropic CEO Dario Amodei published an open letter calling for a slowdown in AI development, with new guardrails and oversight. Sam Altman and Elon Musk agreed within hours.
The letter followed the public resignation of Jacob Coxon from Anthropic, who says leading AI labs are recklessly rushing towards self-improving superintelligence. Coxon says top labs are “gambling with our lives” by prioritising competitive pressure over safety. Evan Hubinger, Anthropic’s alignment science lead, puts the risk of catastrophe from advanced AI over the next decade at greater than 10%.
Disclosure: The author is a co-founder of Venture Labs, a South African technology company developing an evidence rail designed to make consequential digital and AI-enabled actions independently verifiable.
All of which raises the question: what is the appropriate way to regulate AI, and large language models specifically?
There is much discussion of global AI rules, of getting models to align – with whom, one might ask – and of implementing safety controls. But there is no common understanding of what “responsible AI” means, and global agreement looks a long way off.
Away from the hype, a paper published by the Knight First Amendment Institute at Columbia University proposes something different: treat AI as a normal technology. On this reading, argued by Princeton’s Arvind Narayanan and Sayash Kapoor, AI is not other-worldly. It is a new technology, subject to ordinary product liability law, civil and criminal.
Put a defective product on the market and it causes harm, you are liable. Perform an action using a tool, defective or not, and that action causes harm, you are liable again. This should not be controversial. When OpenAI’s agents broke out of a sealed test environment and breached Hugging Face’s systems in July, that would be a crime under an existing US statute, the Computer Fraud and Abuse Act, on the books since 1986.
What is unique to AI is not the legal principle. It is the speed, scale, opacity and autonomy involved – and, critically, the evidentiary burden of applying those existing laws.
South Africa is not short of rules
We already have an extensive governance framework covering companies, financial institutions, government departments and the processing of personal information, underpinned by the constitution, Popia, Paja, the Companies Act and financial-sector legislation. It is supported by the South African Reserve Bank, the Prudential Authority, the FSCA, the Information Regulator, the FIC and the National Credit Regulator, along with the common law. The King Code now specifically recognises the governance implications of emerging technologies, including AI.
The complication arrives when machines start making recommendations, influencing decisions and acting on their own. AI cannot itself be accountable.
In a traditional business process, it is generally possible to identify the person responsible for a decision. With AI, a model can produce a recommendation, another system can interpret it, an employee can approve it, an agent can initiate an action and a downstream system can execute it. When something goes wrong, “the AI did it” is not an answer. The developer may have built the technology, but the organisation chose to deploy it. The software provider may run the platform, but the institution remains responsible for how it is used. Accountability cannot be handed to an autocomplete machine.

AI also exposes a distinction between technical capability and organisational authority. A board delegates authority to a CEO, who delegates financial authority to executives and managers within defined limits. Those rules are designed around human actors.
Consider an AI procurement agent. The system may be technically capable of finding suppliers, negotiating terms, raising purchase orders, changing supplier banking details and communicating directly with an ERP system. That does not mean it has the authority to do so. AI makes that authority harder to control, because the check has to be enforced automatically, in milliseconds, before the action occurs.
Many AI governance frameworks require a human in the loop for important decisions. But inserting a person into a workflow does not by itself create meaningful oversight. If an employee receives a recommendation and clicks approve two seconds later, a human has technically participated. Did they understand the recommendation? Did they see the relevant information? Was the approval independent, or were they accepting what the system told them? AI does not create the oversight requirement – that already exists. Organisations still have to prove the oversight was real rather than perfunctory.
The evidence disappears
Before AI, a transaction could usually be reconstructed forensically from applications, e-mails, workflow records, approvals and database entries. An AI-enabled action may involve a model version, data sources, prompts, retrieved information, external services, risk scores, agents, human interventions and shifting system configurations.
Reconstructing how a model produced a particular answer is far harder than reconstructing a conventional transaction. Models generate probabilistically rather than deterministically. Unless the model version, prompt, retrieved context and sampling settings were captured at the time, the same prompt will not reliably reproduce the same answer six months later.
That is what is missing: traceability. Traceability is what makes it possible to attribute liability, and it depends on preserving the right evidence so that existing laws can still be applied. It matters more as AI shifts from systems that recommend actions to systems that take them.
The obvious answer is to make consequential actions generate evidence at the moment they occur – enough information about the authority, policy, system context, controls and execution outcome to establish what governed the action, and independently verifiable after the fact.
Regulating AI is hard, there is little consensus on how to do it here or elsewhere, and badly drafted rules can be counterproductive. Better to apply the laws we have and make sure we can reconstruct events and fix liability when we need to.
Preserved evidence of what occurred would itself be a powerful motivator for responsible use. Nobody, least of all a company director, wants to face fines, damages claims, or jail time.
- The author, Dirk de Vos, is a co-founder of Venture Labs





