
South African Experts Discuss AI Risks and Data Resilience
An executive roundtable hosted by Veeam in partnership with ITWeb in Johannesburg recently highlighted that existing cybersecurity guardrails are insufficient to protect against the escalating risks posed by agentic AI, emphasizing the urgent need for new approaches to data resilience and trusted AI. This discussion, featuring insights from Andre Troskie, EMEA field CISO at Veeam, and Nerushka Bowan, a technology and privacy lawyer, underscored the rapid evolution of AI-enabled threats, which now extend across both virtual and physical realms, and the potential for catastrophic misuse if not properly managed. The World Economic Forum's Global Cybersecurity Outlook 2026 and Global Risks Report 2026 further corroborate these concerns, identifying AI vulnerabilities and adverse outcomes of AI as top short-term and long-term global risks, respectively, with AI being the most significant driver of change in cybersecurity. The consensus was that AI's growth is outpacing its regulatory and protective frameworks, demanding machine-speed recovery capabilities.
This development carries significant legal significance for practitioners, businesses, and the public in South Africa, as it signals an impending wave of regulatory challenges and compliance requirements. The rapid advancement of agentic AI necessitates a re-evaluation of existing data protection and cybersecurity frameworks, particularly the Protection of Personal Information Act (POPIA) and the Cybercrimes Act. POPIA's principles of lawful processing, data minimisation, security safeguards, and accountability will be severely tested by AI systems that process vast amounts of data, often autonomously. Businesses must anticipate increased scrutiny regarding their AI governance models, data handling practices, and incident response capabilities, as the legal landscape struggles to keep pace with technological innovation.
The legal context in South Africa, while robust in areas like data privacy and cybercrime, currently lacks specific, comprehensive legislation addressing AI governance and liability. This creates a regulatory vacuum that exposes organisations to unforeseen risks. The discussion implicitly calls for a proactive legislative response, potentially drawing inspiration from international developments such as the European Union's AI Act, to establish clear guidelines for the ethical development, deployment, and use of AI. The key parties involved in this discourse include technology vendors like Veeam, media platforms like ITWeb, legal experts such as Nerushka Bowan, and international bodies like the World Economic Forum, all contributing to a growing awareness of the legal and ethical implications of AI.
For legal practitioners, the takeaway is clear: proactive engagement with AI-related risks and opportunities is no longer optional. Attorneys should advise clients on conducting thorough AI risk assessments, developing robust AI governance frameworks, and updating data protection and cybersecurity policies to specifically address AI-driven threats. This includes reviewing contractual agreements for AI service providers, ensuring compliance with evolving data residency and sovereignty requirements, and preparing for potential litigation arising from AI-related data breaches, algorithmic bias, or misuse. Monitoring legislative developments both locally and internationally will be crucial to guide clients through this rapidly changing technological and legal landscape, ensuring they remain compliant and resilient in the face of agentic AI.
Furthermore, legal professionals should consider specialising in AI law, as the demand for expertise in this niche will undoubtedly grow. This involves understanding the technical aspects of AI, its ethical implications, and how it intersects with existing legal principles across various sectors, from finance to healthcare. Educating clients on the importance of 'trusted AI' – ensuring accuracy, security, governance, and availability of data – will be paramount to mitigate legal and reputational risks. The discussion serves as a stark reminder that yesterday's legal and technical guardrails are inadequate for tomorrow's AI challenges, necessitating a forward-thinking and adaptive legal strategy.
How does this affect you?
Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.
Finish Reading the Full Story and the Expert Analysis.
Wansom is AI and can make mistakes.
