Critical point

The King V Code of Good Governance ensures the responsibility for AI lies firmly with the board

Critical point

King V has moved artificial intelligence (AI) from the IT department into the boardroom. It’s one of the areas where the latest iteration of the King Codes of Good Governance will have a massive impact, as directors are now expected to embrace AI while at the same time safeguarding their company against the risks of it – without losing their own curiosity and ability for critical thinking.

SA’s corporates have started applying King V for their 2026 financial years since it came into effect on 1 January 2026. ‘It’s still too early to draw conclusions about its impact,’ says Parmi Natesan, CEO of the Institute of Directors South Africa (IoDSA), which is the custodian of the King reports. ‘Governance changes typically take time to become embedded in organisational practices and even longer before their effects become visible in governance outcomes.’

She says the first meaningful insights are likely to emerge during the 2026 reporting cycle when organisations publish their King V disclosures. One of the earliest impacts may not be a change in governance practices themselves, according to Natesan, but rather an improvement in the quality, consistency and comparability of governance reporting.

‘The King V Disclosure Framework establishes a minimum disclosure baseline for organisations claiming application of King V and is already encouraging more structured and transparent reporting,’ she says. ‘Early adopters have demonstrated different but equally valid approaches to applying the framework, illustrating how organisations can enhance transparency while still retaining flexibility in how they tell their governance story.’

Asked where she expects King V’s most significant impact on companies compared to its predecessor King IV, Natesan says there’s likely to be ‘greater accountability through more explicit board statements regarding governance outcomes and the effectiveness of governance arrangements.’ She also anticipates increased transparency around departures from recommended practices through the requirement for specific exception declarations and disclosure of compensating measures. King V tightens King IV’s more permissive ‘apply and explain’ disclosures by requiring companies to explicitly declare any departures from recommended practices and to explain in detail what safeguards they use instead. Natesan also expects King V to improve comparability of governance disclosures across organisations, because of the Disclosure Framework’s standardised baseline. Furthermore, she says King V will lead to ‘stronger governance of technology, information and AI as organisations grapple with increasingly complex digital and AI-related risks and opportunities’.

King V’s Principle 9 directly addresses AI, with further references in the explanatory notes on emerging technologies and risk management. Yet it doesn’t mention any specific technologies and examples, such as large language models (GPT-4, Claude, Copilot, Gemini), or anything related to cloud platforms, crypto, blockchain and cybersecurity, for instance. ‘The pace of technological change is simply too rapid for a governance code to remain relevant if it focuses on specific technologies,’ says Natesan. ‘By using broader terminology, King V remains technology-neutral while ensuring that boards apply appropriate governance regardless of which technologies emerge in future.’

AI ethics expert and consultant Johan Steyn, founder of AIforBusiness.net, says the most important message is that ‘technology, information and AI now form a standalone governance pillar, and accountability for them sits with the governing body itself. A board can delegate the work of AI to management, but it can never delegate the responsibility for it. And because King V judges governance by outcomes rather than box-ticking, “we had a policy” will not be a defence when something goes wrong’.

Xitshembhiso Russel Mulamula, a certified director who wrote his PhD thesis at the University of Pretoria on the role of the board in AI ethics and governance, says that based on his research, the most important message is that ‘responsible AI governance must be deliberate, structured and led from the board. Boards cannot treat AI governance as an afterthought, or wait for regulatory pressure, reputational harm or ethical failure before acting’.

In his thesis, Mulamula argues that ‘AI technologies are no longer merely technical tools managed by IT departments but have become an important corporate governance issue’ requiring board-level attention.

‘Accordingly, King V’s explicit recognition of board responsibility for AI places a direct obligation on boards to ensure that AI technologies are governed in a manner that is ethical, accountable, transparent, fair, safe and aligned with the organisation’s values and strategic objectives,’ says Mulamula. ‘The challenge is that many boards may not yet have sufficient AI literacy, technical understanding or governance mechanisms to discharge this responsibility effectively.’

In SA this is even more significant, he says, because AI technologies may reinforce existing societal concerns such as inequality, discrimination, exclusion, unemployment, privacy violations and lack of public trust. Boards must therefore not only consider the commercial benefits of AI, but also its broader ethical and societal implications. ‘The real challenge is to move AI from the margins of operational management into the centre of corporate governance,’ says Mulamula. ‘Boards must ensure that adequate structures, processes and rational mechanisms are in place to oversee the design, development, deployment and use of AI technologies. This includes ensuring appropriate board expertise, management accountability, committee oversight, data governance, risk management and assurance mechanisms.’

To achieve the necessary expertise, Mervyn King, the father of the King Codes, suggests introducing AI generative tool committees, similar to remuneration committees, audit committees and nominations committees. He said in a recent Good Governance Academy webinar that this could help directors distinguish original human thinking from AI‑generated content in management reports and board packs.

‘The risk I worry most about is boards quietly relying on AI to oversee AI,’ says Steyn. ‘The recent UC Berkeley “peer preservation” study found that leading models will actively protect one another from being shut down – fudging evaluations, disabling their own off-switches, even concealing it from human monitors. Add the AI agent now entering the boardroom itself – summarising papers and shaping the options directors see – and King V’s demand for genuine human oversight is easily reduced to a fiction.’

That’s why Mulamula recommends an AI governance framework built on principles that go beyond policy compliance: transparency, explainability, fairness, accountability, safety, robustness, and critically human-in-the-loop. ‘Boards must ensure that humans can override AI decisions, especially where those decisions affect individuals’ rights or violate the law,’ he says. ‘This isn’t about slowing AI adoption; it’s about making that adoption sustainable and trustworthy.’

Boards must learn from the recent AI-generated ‘hallucinations’ in SA’s draft national AI policy, which contained fabricated academic citations and non-existent sources. ‘Framing this episode as an embarrassment obscures what needs to be examined. It misses the main point of what’s at stake,’ says Nomalanga Mashinini, a senior lecturer in cyber law at Wits University. She highlighted in the Conversation that the hallucinations weren’t a technical glitch but an oversight failure. ‘Generative AI was used without proper human verification of the sources, compromising the credibility and integrity of the document,’ she says, explaining that the governance principles of responsible AI (accountability, transparency, and explainability) bind any organisation that uses AI.

Both Mashinini and King highlight the importance of clearly referencing the exact AI generative tool – and how it was used – in creating a document. Directors should also include the date and the AI prompts they used, says King, to help explain their reasoning years later if a decision were to be challenged.

‘The deeper danger isn’t a rogue algorithm; it’s capable directors deferring too readily to a confident-sounding output,’ says Steyn. He quotes Investec’s CIO, who recently said, ‘treat AI as a super-smart savant and you will make terrible choices, but treat it as a tool within a decision-making process and it becomes genuinely’ useful.

 ‘A director’s duty to apply an independent mind cannot be outsourced to a machine. Boards should build real AI literacy at the table, insist on knowing where and how AI shaped any paper before them, and treat AI as an input to interrogate – never an authority to obey,’ says Steyn

Ultimately, even governance frameworks such as King V can’t guarantee ethical behaviour, whether in relation to AI or any other aspect of organisational conduct, says Natesan. They can establish accountability, oversight mechanisms and decision-making disciplines, but are no substitute for ethical judgement. That responsibility remains firmly with directors.

By Silke Colquhoun
Image: iStock