Financial-sector regulation cannot remain anchored to business models that technology is rapidly changing.
That was among the issues raised by Financial Sector Conduct Authority Commissioner Unathi Kamlana (pictured) during a public lecture at the University of Cape Town on 6 August, titled “Governing the invisible: leadership, innovation, and accountability in the financial sector”.
Kamlana examined three technological frontiers – artificial intelligence, decentralised finance (DeFi), and open finance – and the implications for regulation and governance.
Together, they are changing how financial products are designed, distributed, and consumed, while redistributing risk and challenging assumptions on which regulatory frameworks have traditionally been based.
For the FSCA, the question is no longer whether innovation should be embraced. It is how regulation keeps pace with activities increasingly conducted through technology that may be difficult to see, understand, or attribute to a particular actor.
AI and the accountability gap
Kamlana highlighted the shift from AI systems that assist human decision-making to agentic AI capable of acting with limited human intervention.
In financial services, such systems can execute trades, assess credit applications, and make lending decisions, or process insurance claims through automated decision chains.
Who is accountable when an autonomous system causes harm?
Responsibility could potentially sit with the software developer, financial institution, technology vendor, cloud provider, data provider, or executive who authorised the system.
Kamlana described this as an “accountability fracture” – a separation between those making decisions and those who can ultimately be held responsible for them.
Technology providers may be part of the decision-making chain, but accountability cannot simply move with them.
“Financial institutions must remain accountable for the decisions made in their name,” Kamlana said, regardless of how many technology providers contribute to those decisions.
The regulatory work is already under way. The FSCA has submitted comments to the Financial Stability Board’s consultation on the responsible adoption of AI in finance. Kamlana also said the FSCA, South African Reserve Bank, and Prudential Authority are developing a joint discussion paper on AI, including agentic AI.
The regulators intend to incorporate high-level governance principles for the use of AI by financial institutions into the Joint Standard on Culture and Governance requirements.
DeFi: follow the function
DeFi presents a different regulatory problem. Traditional financial regulation assumes an identifiable intermediary – a bank, insurer, broker, or other institution that can be licensed, supervised, and held accountable.
DeFi can remove that intermediary and replace its functions with distributed networks and smart contracts.
“The intermediary has not disappeared; it has simply become invisible,” Kamlana said.
South Africa has established a licensing framework for crypto asset service providers (CASPs), with more than 300 CASPs licensed by the FSCA, according to Kamlana. But activity is increasingly moving beyond centralised, licensed entities, and into DeFi protocols.
Kamlana argued that regulation should focus on economic function rather than legal form.
“If a protocol performs the economic role of an exchange, a lending platform, or another regulated financial service, then it must meet the standards that are commensurate with that activity,” he said.
That would place regulatory responsibility on those exercising effective control over a protocol, including through governance tokens, software upgrades, or key operational parameters.
The FSCA is also updating its 2023 Crypto Asset Market Study to assess changes in the market, consumer behaviour and the development of DeFi.
“You cannot govern what you cannot measure,” Kamlana said, pointing to evidence, data, and market intelligence as important components of the regulatory approach.
Open finance and the ownership of data
Open finance introduces another question: who controls financial data and how is consent obtained for its use?
The model allows customers, with their consent, to share financial information with other institutions and authorised third-party providers. It can support new products and services and lower barriers to entry for new firms.
It also creates new risks.
Financial information can move between institutions, platforms, and third-party providers without customers necessarily having a clear understanding of where it goes, how it is used, or who benefits from it.
Kamlana pointed to consent buried in lengthy terms and conditions, as well as “dark patterns” designed to steer users towards particular decisions.
Third-party data aggregators may also hold sensitive financial information at a scale comparable to traditional financial institutions without necessarily falling within the same regulatory perimeter.
“If third-party providers become trusted custodians of consumers’ financial information, they cannot remain outside an appropriate regulatory framework simply because they are technology companies rather than traditional financial institutions,” Kamlana said.
South Africa is developing its policy approach to open finance through the Intergovernmental Fintech Working Group, of which the FSCA is a member.
Governance moves to the centre
Kamlana returned to governance.
Technology will continue to develop faster than legislation can be written. The regulatory response cannot depend on anticipating every technological development individually.
Existing principles – fairness, accountability, integrity, and public trust – must continue to apply as the way financial services are delivered changes.
“Regulation, however effective, cannot by itself determine the character of the financial sector,” Kamlana said. “The character of our sector will ultimately be shaped by the daily decisions of its participants.”
Financial institutions, technology firms and other market participants will need to embed responsible innovation into their governance frameworks.
For boards and executives, Kamlana identified four questions to consider before deploying new technology:
- Can the institution explain how the technology reaches its outcomes?
- Can it identify who remains accountable when something goes wrong?
- Does the innovation improve outcomes for customers, or only efficiency for the institution?
- Would the institution be comfortable explaining its decisions to customers, the regulator and the public?
The questions put technology adoption squarely within governance and accountability, rather than treating it solely as an operational or IT decision.
Kamlana’s closing argument was that the digital financial sector does not require an entirely new set of regulatory principles. It requires existing principles to remain effective as technology changes.
“Technology may expand what is possible, but it cannot determine what is right,” he said.
For financial institutions, adopting new technology does not transfer responsibility for its outcomes. The technology may become invisible. Accountability cannot.




