# What happened
At 02:13 on a Tuesday, a corporate compliance engine matched invoices, emails, access logs and emissions data and flagged a "rounding issue" that resembled fraud. The machine raised the alarm. Humans then debated certainty, circulation and whether to turn the system off.
# Why this matters now
# Legal and governance gaps
- Statutory protection: South Africa's Protected Disclosures Act and the Companies Act protect disclosures made by identifiable people. An algorithm is neither an employee nor a worker and therefore cannot claim statutory protection.
- Custodian risk: the human who acts on a machine alert—an engineer, a compliance officer, an auditor—remains legally and professionally exposed. They can be victimised or blamed even if the alert originated in code.
- Ownership and accountability: the machine owns nothing. Organisations must determine who owns the alert, who decides to investigate, and who documents every decision.
- Privilege confusion: routing an alert to Legal does not magically convert pre-existing business records into privileged communications. Legal privilege protects confidential communications created for legal advice or litigation, not ordinary records placed near counsel.
# Practical controls to adopt
- Define ownership and governance: allocate an accountable owner for machine alerts, record escalation paths, and require documented human decisions before adverse actions against staff.
- Design a lawful kill switch: a pause mechanism should prevent external transmission while preserving the alert, underlying data, model version, timestamps and access history. It must trigger an independent review within a fixed period.
- Preserve an audit trail: retain original records, model inputs and outputs, calibration settings and who accessed or altered the alert. That record enables reconstruction if regulators or courts require it.
- Calibrate thresholds and validation: tune detection thresholds and build feedback loops so investigators can mark false positives and improve model reliability over time.
# Operational implications for boards and executives
Boards and senior leaders must treat autonomous monitoring as a governance program that requires policy, resourcing and independent assurance. Effective oversight includes periodic independent audits of model performance, change management controls and incident response procedures that protect both the integrity of investigations and the rights of implicated individuals.
# Bottom line
AI internal audits can be a valuable detection tool, but they shift, rather than remove, governance responsibilities. Organisations should stop treating the machine alert as an endpoint and start treating it as the start of a documented, human-led assurance process that preserves evidence, protects people and subjects the system itself to oversight.