Amid growing discussions about regulating artificial intelligence (AI), one author suggests focusing on applying existing laws rather than creating new rules.
A week ago, Anthropic CEO Dario Amodei published an open letter calling for a slowdown in AI development, demanding the implementation of new oversight and control measures. His position was supported by Sam Altman and Elon Musk within hours.
This letter followed the public resignation of Jacob Coxson from Anthropic, who stated that leading AI labs are recklessly rushing toward creating a self-improving superintelligent system. Coxson argues that prioritizing competitive pressure over safety puts companies in a 'playing with our lives' situation. Evan Hubinger, Head of Governance Science at Anthropic, assesses the risk of catastrophe from advanced AI in the next decade as greater than 10%.
While there is active discussion about global norms for AI, model alignment, and the implementation of safety measures, there is no general understanding of what 'responsible AI' means, and global consensus appears to be a distant prospect.
In contrast, an article published by the Knight First Amendment Institute at Columbia University proposes a different concept: AI should be viewed as a standard technology. According to this view, presented by Arvind Narayana and Saiash Kapur from Princeton, AI is not something extraterrestrial but a new technology subject to standard product liability, civil, and criminal law.
The principle is simple: if a defective product enters the market and causes harm, the responsible party is liable. Similarly, if an action performed using a tool, whether defective or not, results in damage, the liability lies with the executor. This should not be debatable. For example, if OpenAI agents left an isolated test environment and breached Hugging Face systems in July, it could constitute a crime under existing American statutes on computer fraud and abuse, enacted back in 1986.
The uniqueness of AI lies not in the legal principle itself, but in the speed, scale, opacity, and autonomy of the process, as well as, critically, in the complexity of proving cases when applying these existing laws.
South Africa already has an extensive governance system covering companies, financial institutions, government departments, and personal data processing, which is based on the constitution, Popia, Paja, Companies Act, and financial sector legislation. This system is supported by the South African Reserve Bank, Prudential Authority, FSCA, Information Regulator, FIC, and National Credit Regulator, as well as common law. The King's Code now specifically recognizes the implications of implementing new technologies, including AI.
Difficulties arise when machines begin to provide recommendations, influence decisions, and act autonomously. The AI itself cannot bear responsibility. In a traditional business process, it is usually possible to identify the person responsible for a decision made. However, when working with AI, a model might provide a recommendation, another system interprets it, an employee approves it, an agent initiates the action, and a subsequent system executes it. In case of error, the phrase 'the AI did it' is not a sufficient answer. The developer may have created the technology, but the organization decided to implement it. The software provider may manage the platform, but the institution remains responsible for how it is used. Responsibility cannot be passed to the machine for auto-completion.
AI also highlights the distinction between technical capability and organizational authority. A board of directors delegates authority to a CEO, who in turn delegates financial powers to managers and executives within established limits. These rules were originally designed with human participants in mind.
Consider an AI-based procurement agent. The system may have the technical capability to find suppliers, negotiate terms, issue purchase orders, change supplier bank details, and interact directly with the ERP system. But this does not mean it has the authority to do so. AI complicates the control over these authorities because verification must occur automatically, in milliseconds, before the action is taken.
Many AI governance structures require human involvement in critical decision-making processes. However, simply including a human in the workflow does not create meaningful oversight. If an employee receives a recommendation and clicks 'approve' two seconds later, the human technically participated. But did they understand the recommendation? Did they see the necessary information? Was the approval independent, or were they simply accepting what the system told them? AI does not create a requirement for oversight—it already exists. Organizations still must prove that the oversight was real, not merely formal.
The evidentiary basis disappears. Before AI, a transaction could usually be forensically reconstructed based on application logs, emails, workflows, approvals, and databases. An action executed using AI can involve the model version, data sources, prompts, extracted information, external services, risk assessments, agents, human interventions, and changing system configurations. Reconstructing how a model generated a specific response is far more complex than reconstructing a typical transaction. Models generate probabilistically, not deterministically. If the model version, prompt, extracted context, and sampling settings were not logged at the time of the action, the same prompt cannot reliably reproduce the same answer six months later.
What is missing is traceability. Traceability is what allows accountability, and it depends on preserving the necessary evidence so that existing laws can continue to apply. This becomes especially important as AI transitions from systems that recommend actions to systems that execute them.
The obvious conclusion is to mandate that consequential actions generate evidence at the moment of their execution—sufficient information regarding authority, policy, system context, controls, and execution outcome to establish what governed the action, and so that it can be independently verified later. AI regulation is difficult; there is little consensus on how to do it here or anywhere else, and poorly drafted rules can be counterproductive. It is better to apply existing laws and ensure the ability to reconstruct events and determine liability when needed.
Preserved evidence of what happened will serve as a powerful incentive for responsible use. No one, least of all a company director, wants to face fines, lawsuits for damages, or imprisonment.
