Wednesday, September 9, 2026
Subscribe
The Brief | Namibia's Leading Business & Financial News
  • Home
  • Companies
    • Finance
    • Agriculture
    • Technology
    • Property
    • Trade
    • Tourism
  • Business & Economy
  • E-PAPERreader
  • Mining & Energy
  • Opinions
    • Analysis
    • Columnists
  • Africa
No Result
View All Result
The Brief | Namibia's Leading Business & Financial News
  • Home
  • Companies
    • Finance
    • Agriculture
    • Technology
    • Property
    • Trade
    • Tourism
  • Business & Economy
  • E-PAPERreader
  • Mining & Energy
  • Opinions
    • Analysis
    • Columnists
  • Africa
No Result
View All Result
The Brief | Namibia's Leading Business & Financial News
Subscribe
No Result
View All Result
Home Latest

AI is already at employees’ desks. Is your board ready to govern AI?

by reporter
September 9, 2026
in Latest
6
A A

By Chisom Obiudo

A confidential board pack can leave the organisation in seconds. All it takes is an employee uploading it to an external AI tool for a quick summary.

The board may never know that the document was shared, where its contents were processed or whether the supplier retained them. By the time anyone asks, the disclosure has already happened.

Boards often face several AI risks at once: data may leak, AI outputs may be inaccurate, and autonomous systems may act without approval.

This can make AI seem too broad to govern. An AI-readiness review breaks the problem down into a practical sequence.

It establishes where AI is used, what information is exposed, which rules apply, who is accountable, and whether the organisation is ready for systems that can act autonomously.

For Namibian directors, AI oversight is not a new category of responsibility. It falls within duties they already carry.

Fiduciary duties require directors to act in good faith and in the company’s interests. The separate duty of care and skill requires informed judgement.

In practice, directors need a sufficient understanding of the organisation’s use of AI to question management, challenge assurances, and make informed decisions.

The NamCode reinforces this responsibility through its guidance on technology and risk. Approving an AI policy does not complete the board’s oversight; directors need evidence that the policy and its controls work in practice.

Layer 1: Visibility

The review begins by establishing where AI is already being used. Some use will be visible. Some will not. ‘Shadow AI’ refers to AI tools or features used without the organisation’s knowledge or approval.

It can include personal chatbot accounts, browser extensions and meeting-recording tools. AI capabilities added to software already in use must also be included. Approval of the original product does not automatically extend to every new AI feature.

 

Management should ask staff directly about their use of AI and compare their responses with procurement and expense records, software inventories and system settings.

The resulting AI register should identify each tool or feature, who uses it, the business task for which it is used, the information entered, the output relied upon and whether the use has been approved. This gives directors evidence of how AI is actually being used, not merely which software licences the organisation holds.

 

Layer 2: Data Exposure

Visibility alone is not readiness. The next step is to trace the information entered into each tool and determine where it goes.

A summarisation tool may retain an entire document even when the employee needs only a summary. Removing names does not necessarily make the document anonymous if job titles, transaction details or other information can still identify the people concerned.

For each use, management should establish where information is processed, who can access it, how long it is retained, and whether the supplier may use inputs or outputs to train its AI models.

Confidential information should not be uploaded until these arrangements have been verified and the use formally approved. No summary can undo a disclosure that should never have occurred.

Namibia’s draft Data Protection Bill makes this work more urgent. Its published provisions address the lawful processing of personal information, security safeguards and transfers of information outside Namibia.

However, organisations need not wait for the Bill to act. Article 13 of the Namibian Constitution already protects privacy.

Contractual confidentiality obligations and sector-specific rules, including those governing legal and banking services, may also restrict the handling of information.

The review should therefore identify which duties apply now and which additional safeguards the organisation is implementing in anticipation of future data protection legislation.

Layer 3: Written Governance

The findings from Layers 1 and 2 should be converted into clear rules that employees, executives and directors can apply without guesswork. An acceptable AI use policy should identify approved tools, specify what information may be entered, set the checks required before relying on any output, and explain when AI assistance must be disclosed, to whom, and when prior approval is required.

For a summary of board papers, verification means comparing figures, conclusions and recommendations with the original documents and checking for material omissions. Training should use realistic tasks to test whether users can apply these rules correctly.

The same discipline must apply to suppliers. Contracts should specify how suppliers may use the organisation’s data, prohibit unauthorised use for AI training, set retention and deletion periods, impose security and incident-reporting obligations, and govern subcontractor use. The organisation should also have the contractual right to obtain evidence that these commitments are being met. If a supplier will not provide adequate protection, the proposed use should not be approved.

Layer 4: Accountability and Oversight

Every approved use of AI should have a named manager accountable for its operation and outcomes. Technology teams should manage access and security, while legal and compliance teams assess legal obligations and supplier contracts. A designated executive should coordinate this work, resolve gaps, and report to the board. The review should also identify who has authority to approve changes, investigate incidents, and suspend a tool when its risks become unacceptable.

Board reporting should indicate whether the controls are working. Useful measures include unauthorised uses detected, data incidents, errors found in sampled outputs, and corrective actions not completed on time. Reported savings should account for the time and cost of verifying outputs and correcting mistakes.

The board or a designated committee should review these reports quarterly. If a committee conducts the review, material findings should be reported to the full board, and serious incidents should be escalated without delay. Internal audit can independently test the records and controls underpinning management’s reports. Assigning detailed monitoring to a committee does not relieve the board of its oversight responsibility.

Layer 5: Autonomous AI and Agents

AI agents are systems that can take actions via connected software, rather than merely producing content for a person to review. They can send messages, update records, place orders or initiate payments. These actions may affect customers or commit organisational resources before anyone intervenes. An organisation should not deploy autonomous agents until it can demonstrate that the first four layers are working in practice: visibility, data protection, written governance and accountable oversight.

Each agent should have a defined task, access only to the information and functions it needs, and clear limits on what it may do without human approval. For example, a payment above a predetermined amount should not proceed without approval. Management should test potential failures outside live operations, keep complete records of the agent’s actions, and show how a named person can halt the agent and restore affected operations. An agent acting outside its approved limits should be contained immediately while the cause is investigated.

International Frameworks Should Support the Sequence

ISO/IEC 42001 sets out requirements for establishing and maintaining an AI management system and can support independent certification. The NIST AI Risk Management Framework provides voluntary guidance on identifying and managing AI risks. Both can help an organisation strengthen its controls, but neither replaces basic operational readiness.

A board gains little from extensive framework mapping if management cannot identify who uploads confidential documents, what happens to them, or who can stop unsafe use. Baseline readiness should come first. International frameworks can then help formalise and improve a governance system that is already working.

The First Unanswered Question

The board can test readiness by asking five questions in sequence. Which AI tools and features are in use? What information enters them, and where does it go? Can employees apply the written rules, and do supplier contracts enforce them? Who is accountable for each use, and what evidence reaches the board? Where agents are operating or proposed, can their actions be limited, traced and stopped?

The first question that management cannot answer with evidence marks the organisation’s first operational failure point. Address that gap before the review moves to the next layer, with a named owner, a deadline, and clear evidence of completion.

Any AI use that exposes confidential information without adequate safeguards, or allows an agent to act beyond approved limits, should be immediately restricted or suspended.

The board then has a defensible basis for deciding which AI uses may proceed, which require additional safeguards, and which should not be authorised.

*Chisom Obiudo is an admitted legal practitioner of the High Court of Namibia specialising in corporate governance and AI governance. She facilitates AI governance training for boards and delivers professional AI skills training. She can be contacted at chisomokafor11@gmail.com

author avatar
reporter
See Full Bio
Previous Post

Metro – Hypermarket Grocery Basket, August 2026

Next Post

MTC, MVA Fund build 61 classrooms to ease rural school infrastructure shortages

Must Read

Group of six adults standing with plaques in front of a bright blue wall; woman sits front center in a dark dress with colorful accents.
Latest

MTC, MVA Fund build 61 classrooms to ease rural school infrastructure shortages

September 9, 2026
Seedlings sprouting from stacked coins on soil beside a moss ball labeled CO2, symbolizing green investment and sustainability.
Latest

Namibia eyes carbon markets as new source of climate finance

September 8, 2026
Close-up portrait of a woman wearing a gray blazer over a black-and-white striped top, facing the camera against a gray background.
Latest

Psychological safety: The missing ingredient in high-performing teams

September 4, 2026
Seven diverse professionals pose in a row in front of a green backdrop with repeating white logo marks.
Latest

Nedbank launches 30-person funeral cover including extended family, domestic workers

September 3, 2026
21st Centaury organisational learning and development at the backdrop of industrial-organisational psychology
Latest

Your network is your net worth: The relationships that shape Namibia’s opportunities

September 3, 2026
Workers in hard hats and gloves stretch a large gray fabric over a worktable in an industrial textile setting.
Agriculture

Meatco targets EU, Asian markets for Namibian leather

September 2, 2026
Load More

Related News

De Beers CEO sees stable natural diamond supply

De Beers CEO sees stable natural diamond supply

February 28, 2022
EU replaces travel ban on Namibia with testing requirements

EU replaces travel ban on Namibia with testing requirements

January 10, 2022
Ethics and the workplace

Ethics and the workplace

June 7, 2024

Browse by Category

  • Africa
  • Agriculture
  • Analysis
  • Business & Economy
  • Columnists
  • Companies
  • e-edition
  • Finance
  • Finance
  • Fisheries
  • Green Hydrogen
  • Health
  • Investing
  • Latest
  • Market
  • Mining & Energy
  • namibia
  • Namibia
  • News
  • Opinions
  • Property
  • Retail
  • Technology
  • Tourism
  • Trade
The Brief | Namibia's Leading Business & Financial News

The Brief is Namibia's leading daily business, finance and economic news publication.

CATEGORIES

  • Business & Economy
  • Companies
    • Agriculture
    • Finance
    • Fisheries
    • Health
    • Property
    • Retail
    • Technology
    • Tourism
    • Trade
  • e-edition
  • Finance
  • Green Hydrogen
  • Investing
  • Latest
  • Market
  • Mining & Energy
  • namibia
  • News
    • Africa
    • Namibia
  • Opinions
    • Analysis
    • Columnists

CONTACT US

Cell: +264814612969

Email: newsdesk@thebrief.com.na

© 2026 The Brief | All Rights Reserved. Namibian Business News, Current Affairs, Analysis and Commentary

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Companies
  • Mining & Energy
  • Business & Economy
  • Opinions
    • Analysis
    • Columnists
  • Africa

© 2026 The Brief | All Rights Reserved. Namibian Business News, Current Affairs, Analysis and Commentary

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.