Dispatches
Essays··13 min read

Sunday Essay — The Supervisor Who Missed the Branch Era

Three African central banks are opening AI supervision regimes, each with a different first sentence. Pretoria waits on the Financial Stability Board — Abuja has written AI into its anti-money-laundering code — Nairobi has published nothing while mobile lending runs at 1.5 billion shillings a day. The common gap sits outside all three perimeters.

Supervising a financial system is a different trade when the system you supervise skipped a generation of branches. The regulator who grew up with teller windows and clearing houses reads her inherited rulebook as the territory. The one who grew up with mobile money reads it as a translation, with the original missing.

That is the spread this essay sits in. Three African capitals are each writing the opening page of their artificial-intelligence supervision regime for banks and payment companies, and each is choosing a different first sentence. Pretoria is waiting on Basel. Abuja is writing straight into the anti-money-laundering code. Nairobi is lending at a cadence the rulebook has not yet caught up with. The three bets will settle in different weather.

The common claim is that African regulators are late. The honest reading is that they are supervising a stack their counterparts in London, Frankfurt and Washington have never had to supervise, which is one in which the account, the credit line, the fraud screen and the collections workflow are routinely stitched together through a single mobile-money rail owned by a telco. Writing a rule about model risk inside a bank's own perimeter is one thing. Writing it when the model recommends, the agent disburses, and the account the money lands in is a stored-value wallet governed by a different ministry is a materially different exercise. The three regimes about to form will tell us which pattern a supervisor can hold in practice.

Pretoria, in the posture of waiting

On 18 September 2026, Bloomberg reported the South African Reserve Bank's governor telling an audience in Pretoria that the country would hold off on standalone artificial-intelligence rules for its banks until the Financial Stability Board had published a settled view. The piece carried the quote in full and is the cleanest primary record of the decision. Read in isolation, it is a cautious, defensible posture from a central bank whose cross-border banking book is large relative to its domestic supervisory capacity.

Read against the ground, the posture asks for more work than it looks like. The FSCA and the Prudential Authority (the SARB's banking-supervision arm) had already published the deepest regulator-authored read of AI use inside the South African financial sector in late 2025. The joint report runs through the deployment patterns across banks, insurers, retirement funds and collective-investment schemes, with a specific inventory of fraud-detection, credit-scoring and KYC applications. It is a serious piece of supervisory ethnography. It is also an inventory, which is not the same as a rule.

The speech from SARB Deputy Governor Fundi Tshazibana a few months earlier is the connective tissue. Tshazibana set out her reading of what the age of AI asks of financial supervisors, framed around three questions: whether the existing rulebook can be re-read to cover the new technology, what the gaps are, and how a mid-sized emerging-market supervisor should sequence its response. The implicit answer in the speech is that the existing rulebook does more work than its critics assume, that explicit new rules are coming, and that the SARB would rather align them with international practice than lead the drafting itself. That is the posture Bloomberg heard in September. It did not come from nowhere.

What it costs is a quarter or two of supervisory initiative. The institutions the Prudential Authority supervises are not standing still. Standard Bank, the largest banking group by assets in the Southern African Development Community, spent most of 2026 moving from a project-level view of artificial intelligence toward what its own leadership describes as an AI-enabled operating model. That reframing is more than a slogan. It changes who signs the model-risk sign-off, who holds the vendor contract, and how an incident is reconstructed after the fact. A supervisor waiting on a global playbook is a supervisor whose supervised entity is choosing its operating pattern in the interim.

Abuja, writing straight into the AML code

The Central Bank of Nigeria made the opposite bet. On 12 March 2026, Techcabal reported that the CBN had written AI explicitly into its anti-money-laundering compliance rules for banks and other financial institutions, a step the piece correctly flagged as a first for a major African regulator. The rule itself is narrower than the headline. It does not legislate how models are governed. It writes AI into the specific perimeter of AML monitoring, where the technology was already being used and where regulatory language that pretended otherwise was becoming an active liability for auditors.

The context the rule lands in is a sector that had been running ahead of it. A CBN survey released on 3 February 2026 found that 87.5 percent of licensed Nigerian fintechs reported using artificial intelligence in some form for fraud detection, the highest penetration rate the central bank has ever recorded for a specific analytical technique inside its licensed perimeter. Take the self-reported number with the care any survey deserves, including the one that respondents may be over-counting rules-based scoring as AI. The direction is still unambiguous. The CBN wrote a sentence into its AML code because the sentence was already true at the counter.

The pattern worth sitting with is the sequence. The Nigerian regulator picked the narrowest supervisory surface, the one where the enforcement is clearest and the counterparty is already a licensed obliged entity, and wrote into it first. It did not open with a general model-risk regime. It did not open with a consumer-protection framework. It did not wait for the FSB. It chose a bite small enough to supervise and large enough to matter.

Whether that bite scales is the question. An AML rule that reaches generative models reaches them through transaction monitoring and name screening, where the explanation requirement is already strong. It does not reach a bank's underwriting model, which runs on a different cycle, with a different review calendar, and in Nigeria is still mostly tended by the credit department rather than the compliance one. The CBN's bet is that the AML wedge, once it holds, becomes the template for the harder perimeter. The alternative reading is that the AML wedge is where the CBN had the cleanest statutory authority and that writing it there was the opening it could get, not the opening it would have chosen.

Nairobi, already lending

Nairobi is the capital where the regulatory tempo matters least, because the lending is already happening. On 13 May 2026, the Pulse Kenya newsroom reported that the Kenya Commercial Bank's rebuilt mobile scoring models had pushed its daily mobile-loan disbursement run-rate to roughly 1.5 billion Kenyan shillings per working day, the highest in the KCB M-Pesa product's history. Read that against the shape of the Kenyan credit market and the number is more consequential than it looks. KCB is one of two commercial banks whose mobile-loan books now move faster, in flow terms, than the branch-based consumer-credit books of several larger African banks move in a month.

The scoring stack behind that number is a model stitched out of mobile-money transaction patterns, airtime history, device signals and prior-loan performance, fed into an underwriting engine whose decision horizon is measured in seconds. The supervisor who would audit it has to be able to reconstruct, in a specific declined-loan file, which inputs the model saw, which it weighted, and what the counterfactual version of the applicant would have been offered. The Central Bank of Kenya has the statutory authority to ask that question. It has not yet published the rule that would standardise the answer.

Safaricom, which owns the M-Pesa rail every one of those loans crosses, is also expanding into direct lending. A Techcabal brief from 1 July 2026 traced M-Pesa's reasoning for pushing further into the credit layer, framed around a gap the company reads as a structural underweight of working-capital finance to the Kenyan small and medium enterprise. The company is a licensed money-remittance operator in Kenya. Its credit activity sits in a joint-venture structure with partner banks. The model that triggers an SME offer, however, lives in the telco. The regulator who wants to audit that model is reaching across two statutory perimeters at once.

The disconfirming reading on the Kenyan picture is the sharpest. A piece in HapaKenya on 7 May 2026 argued that Safaricom's internal use of AI, including the application layers facing M-Pesa customers, needs a materially larger overhaul than the company's own communications admit, with specific weaknesses in model documentation, in uneven uptake across the business, and in the thin skills base beneath the deployment. The author's argument deserves a direct answer. It is a reminder that cadence is not the same as capability, and that the firm whose loan-decision latency is the lowest in the market is not necessarily the firm whose documentation would survive a thorough supervisory review. The CBK's absence of a published rule means that review has not yet been forced. When it is, the firm with the longest audit trail will not be the firm with the fastest ledger.

What the FSB document says

The playbook the Pretoria regulator is waiting on is less of a rulebook than its coverage suggests. In June 2026, the Financial Stability Board published its sound-practices framework for responsible adoption of artificial intelligence by financial institutions, followed in August by a public summary of the industry and civil-society responses to its earlier consultation. The framework is deliberately principles-based. It names agentic AI as the frontier risk category, calls for human-on-the-loop review with specified escalation triggers, and asks national supervisors to publish their own expectations against the framework rather than importing it unmodified.

That last phrase is the one Pretoria is leaning on. An FSB framework that leaves implementation to national supervisors is not a rule a national supervisor can simply adopt. It is a scaffold a national supervisor still has to clad. The real supervisory work on the South African AI rulebook is still, after the FSB publication, a project the Prudential Authority has to resource itself. Waiting on the FSB is a defensible posture for a quarter. For a year, the delay starts to look like a decision not to resource the drafting team.

The BIS speech given in Basel on 20 May 2026 makes the point more directly. Agustín Carstens, speaking for the Bank for International Settlements on regulation and supervision of the financial sector in the age of artificial intelligence, argued that principles-based international guidance is a floor and not a ceiling, and that supervisors who treat it as a ceiling will find their systems supervised, in effect, by the firms the guidance is addressed to. That line was aimed at every supervisor leaning on Basel's work rather than resourcing their own. The three African regimes are three different reads of exactly that warning.

Why the three bets settle differently

The Pretoria bet is that an aligned, globally comparable rulebook is worth more to a mid-sized emerging-market supervisor than a bespoke one, even if the alignment costs a quarter or two of initiative. For a central bank whose supervised banks operate across fourteen African jurisdictions and list on three continents, that is not an unreasonable calculation. The cost it carries is that the supervised institutions will have their operating patterns set by their own project cycles rather than by the rulebook. Standard Bank's shift into an AI-enabled operating model, Absa's deployment of its own AI customer-facing stack, and the retail-bank pilots across Nedbank and Capitec are each a fact on the ground the rule will have to be fitted around rather than the other way round.

The Lagos bet is that a narrow wedge, enforced early, is worth more than a wide framework published late. The AML rule is a wedge. If it holds, the CBN will have the muscle and the precedent to extend it into model governance proper, into consumer-protection rules for AI-mediated credit, and into the licensing conditions for the next cohort of digital banks. If it does not hold, the wedge becomes a performative line item in a compliance file that nobody tests. The second scenario is the one every supervisor who writes a rule has in the back of her mind.

The Nairobi bet is the hardest one to call because it is a non-bet. The CBK has not published a general AI supervisory rule. The Communications Authority has not published one. The Office of the Data Protection Commissioner has data-protection authority over the inputs but not over the model's outputs. In that gap, the lenders are lending, the telco is extending credit through partner structures, and the question of who audits the model that priced a declined applicant's loan has no settled answer. For some period the gap will not matter. The scale of the KCB daily disbursement run-rate is the first signal that the period during which the gap does not matter is finite.

Where the three capitals meet

The three postures are reading the same conditions and choosing different first moves. None of them is obviously wrong, and none of them is obviously enough. The common piece underneath all three is that the specific object that will matter most sits outside each of the three drafting perimeters so far, which is the agent that chains a credit decision to a disbursement to a collection to a cross-border settlement without a human on the loop at any point in the chain. The FSB framework points at it. TechCentral's read of the June publication caught the same emphasis: that global supervisors are, for the first time, naming the agentic risk category as the one that the existing rulebook does not reach. No African supervisor has yet published its answer. The one that does first will set a template the other two will reach for.

Done well, that template will not look like the European one. European supervision writes against a banking system whose primary payments rail is a traditional bank-to-bank interchange with mobile money layered on top. African supervision has to write against a system in which the mobile-money rail is primary and the banks are counterparties to it, with the model that assesses the SME borrower frequently sitting in a telco joint venture rather than inside the bank itself. A rule copied from the European draft would miss the perimeter that most matters. A rule drafted locally, by a supervisor who was willing to work ahead of her international body's playbook, could set a reference that Lagos and Johannesburg both read.

For the credit officer at her desk tomorrow

A credit officer at a mid-tier Nairobi commercial bank will open her screen on Monday morning. The queue in front of her is a backlog of declined mobile-loan applications flagged for a human review. The scoring engine has written its reason codes in a column she can read. The counterfactual, the version of the applicant the model would have approved if a single input had been different, is not in that column. The vendor's documentation does not provide it. The internal data-science team is tracking a backlog of such reviews that is growing. Her supervisor at the Central Bank has not yet published a rule that would require her bank to be able to reconstruct, for every declined applicant, which inputs decided the file. Monday morning, that is still a bank problem. By the time it is a regulator problem, the queue in front of her will be longer. She knows this. She will work through the queue anyway.


Tarry Singh is the founder and CEO of Real AI, an enterprise AI advisory and deployment firm working with global enterprises on production agent systems, model risk, and AI sovereignty strategy. He also leads Earthscan for Energy AI startup, and is a founding contributor to the EU-funded HCAIM and PANORAIMA programmes for responsible AI education across European universities. He writes at tarrysingh.com.

Cartouche
Sunday Essay — The Supervisor Who Missed the Branch Era · Dispatches, 4 October 2026 · T. Singh