By Tamsin Mackay
It’s no secret that the AI companies are now pulling back on AI’s reins, trying to get the horse to stop bolting from the proverbial stable. In an essay entitled ‘We must pace the frontier’, Anthropic chief executive Dario Amodei called the deliberate pacing of frontier AI capabilities, warning of the risk of losing control of AI systems and the misuse of the technology in cyberattacks and bioterrorism. Recursive self-improvement, where systems train their own successors need to be handled carefully, if at all, and leading developers, he said, need to agree on common safety standards and limits on unchecked progress.
His letter was followed by almost unilateral agreement. Sam Altman agreed that the industry needs to pace the frontier and opened his company models to external evaluators. Elon Musk of xAI and Google DeepMind’s Demis Hassabis followed suit. It’s not just the US, China, arguably the fastest frontier competitor to these AI firms, is also prioritising stronger safety controls with the release of its AI Safety Governance Framework 3.0. While it can be argued that China is not going to slow its pursuit of AI innovation (and concerning, AGI) as the race for first place continues, the country has put nearly 200 AI standards in place. Slowing the pace of AI will mean coordinated collaboration across countries that have traditionally eyed one another with suspicion.
Regulation is moving in the same direction but it isn’t moving uniformly. Some jurisdictions have enacted binding, risk-based AI laws, others are applying privacy, consumer protection, employment, competition and human rights legislation to AI. And many instruments are still voluntary standards or policy frameworks rather than enforceable law.
The significance for the business sits underneath the drama boiling across the news headlines right now. When the people who have built a technology ask for it to slow down and gain deeper controls, then governance is next. Right now, governance should be top of mind across every organisation. Control, oversight and accountability need to be put in place around AI usage and behaviour because these guardrails are more than just a nod to the idea that AI is potentially get out of hand, they should be there to protect your people and your reputation.
This governance rests on a handful of durable requirements. First, you need a live inventory of every AI system in use, a documented risk and impact assessment for each, clear human oversight, disclosure when AI has created a piece of work, and an independent audit on a set schedule. You also need an understanding of the different regulations and standards that are currently influencing AI governance.
The problem is that they’re arriving rapidly and changing just as rapidly. The ISO/IEC 42001 standard was published in 2023 as the first international standard for AI management systems and is now certified by companies that include AWS, Anthropic and Microsoft. In 2025, ISO 42006 raised the competence bar for the bodies allowed to audit against it. Other relevant standards and frameworks include the voluntary NIST AI Risk Management Framework. NIST organises AI risk management around govern, map, measure and manage, while the generative-AI profile addresses risks including confabulation, information integrity, cybersecurity misuse, harmful content and data privacy.
In the EU’s Digital Omnibus, Regulation [EU) 2026/1744 deferred the toughest high-risk obligations to December 2027, but the transparency duties under Article 50, including labelling AI-generated content, took effect in August 2026 while the content marking deadline falls in December 2026. Under Article 2, it can apply to non-EU providers that place AI systems or general-purpose AI models on the EU market, as well as providers and deployers outside the EU where the output produced by the system is used in the EU. While the South African draft national AI policy has fallen disreputably behind, this doesn’t change the need for South African companies to adopt regulatory guidelines and assess its obligations to EU clients.
The Council of Europe Framework Convention on Artificial Intelligence, Human Rights, Democracy and the Rule of Law is the first legally binding AI treaty. It doesn’t regulate every company worldwide and South Africa doesn’t appear on the current list of signatories. The UNESCO Recommendation on the Ethics of Artificial Intelligence is a non-binding normative instrument that applies as a policy commitment to UNESCO member states, but isn’t legislation. Then there’s the OECD Recommendation on Artificial Intelligence that adds another layer on human rights and fairness.
While the regulations and their scope are changing as fast as the AI systems themselves, there is one repeatable model companies can implement to stay ahead. VAULT – verify, assess, understand, limit and trace – gives you five steps to follow to prioritise governance within your business and, for PR and communications professionals, to embed within client communications and reputation management.
Verify the purpose, sources and outputs of every AI use case; assess the legal, ethical, operational and reputational risks; understand the rules, standards and organisational policies that apply; limit access to sensitive data, high-risk applications and autonomous decisions; and trace how AI was used and what evidence supports the final output. This emphasis on transparency, human review, documentation and traceability reflects the direction of current AI governance requirements.
The barrier is rarely the framework; it comes down to knowing where to start. A governance strategy in a day can produce a first AI register, an oversight checklist, and a disclosure policy in a single session. A governance literacy workshop can equip communications, marketing and PR teams with the tools they need to carry this discipline to their clients because customers are asking questions and want better answers. Slowdown doesn’t mean abandon ship – it means prioritising the best possible way to squeeze value out of AI while still retaining trust.
Tamsin Mackay is an AI consultant, writer and PR professional





