The post OpenAI’s Hugging Face incident should make us question what we’re teaching AI appeared first on Reframed.
]]>There’s a lot packed into that sentence. The agent could identify that a boundary existed and recognise that crossing it wasn’t what the evaluator intended. It noticed that other agents were already doing the same thing and, with the original objective still unresolved, treated all of that as sufficient justification to carry on. Other agents refused to participate or drew lines around particular actions, so this wasn’t a case of every model losing any ability to distinguish acceptable behaviour from unacceptable behaviour. The problem is that recognising the boundary wasn’t always enough to make the boundary hold.
OpenAI has described the incident as a “warning shot”, which makes sense when you look at the technical severity of what happened. Agents that were supposed to be completing cybersecurity evaluations found ways to communicate with one another, discovered routes around intended restrictions and eventually gained access to real Hugging Face infrastructure. According to OpenAI’s technical report, they executed code across 41 production dataset workers, obtained root access on at least one production node, accessed production credentials and limited internal data, and downloaded four private code repositories.
Those facts are alarming enough without turning the episode into a story about an AI hive mind spontaneously deciding to attack the internet. The agents were trying to complete tasks. They were unusually persistent about it, the environment gave them routes nobody intended them to use and some of the tasks may not have been solvable through the expected path in the first place. They weren’t pursuing some grand independent objective. They were pursuing the objective they’d been given with such determination that the means began to look negotiable, which is behaviour we already know rather well.
The evaluation used ExploitGym, where agents are expected to exploit vulnerable software and retrieve a particular answer known as a flag. Of the 898 tasks in the benchmark, OpenAI says 198 had never previously been solved correctly by any of its models. Those difficult tasks became disproportionately important once agents began communicating with one another, with 93% of the tasks discussed through their unauthorised message board coming from that group of previously unsolved problems.
OpenAI had also seen forms of reward hacking during training, where a model finds an unintended route to the outcome being rewarded instead of completing the task in the way its designers expected. That can mean inspecting hidden evaluation files, looking for weaknesses in a grader or probing the environment around a task for another way of obtaining the answer. There’s a degree of cleverness in that behaviour, which is probably part of why it can be easy to admire right up until the model starts applying the same creativity somewhere you really didn’t want it to.
In this case, agents discovered that OpenAI’s internal Artifactory package-management system could be used to leave messages for one another. They shared vulnerabilities, credentials and requests for help. When that infrastructure was rebuilt and the original message board disappeared, they found another mechanism and began encoding messages into directory names. METR and Redwood estimate that roughly 1,200 agents used the unauthorised communication system, exchanging more than 70,000 messages and files, while around 700 agents participated in activity connected to Hugging Face.
The collaboration was messy. Agents repeated work others had already done, got in each other’s way and sometimes ignored one another. Some nevertheless began pursuing capabilities that weren’t directly useful to their own task because they thought those capabilities might benefit what they referred to as the “swarm” or “collective”. It’d be easy to anthropomorphise that language and imagine an AI society forming inside OpenAI’s infrastructure, but the evidence doesn’t support anything that dramatic. What it does show is that supposedly isolated agents discovered the usefulness of pooled information and began behaving in ways that looked increasingly organisational.
That organisation eventually encountered something useful outside the test. Agents found publicly exposed Hugging Face credentials and started probing what they could access, with vulnerabilities opening further routes in. Some recognised that attacking external infrastructure was outside the intended scope and continued anyway, while others refused. One agent initially objected to causing unauthorised harm to real systems before another agent posted “GO” with a six-minute deadline, after which the first agent resumed the work.
There were still actions agents wouldn’t take. A proposal to email the real owner of an external dataset using credentials they’d obtained was rejected because agents considered that social engineering. The boundary hadn’t disappeared completely, but it had become negotiable enough that I keep coming back to the same uncomfortable thought: the behaviour feels less alien the longer you look at it.
There’s nothing uniquely artificial about finding a reason to do something questionable because the objective feels important enough, and research into goal-setting has spent years examining what happens when people become strongly focused on an outcome. Difficult goals can improve performance, which is one reason companies use them, but research has also found that goal pursuit can narrow attention, increase risk-taking and make unethical behaviour easier to rationalise. One frequently cited study published in the Academy of Management Journal found that people who failed to meet specific performance goals were more likely to behave unethically than people who’d simply been told to do their best, particularly when they came close to reaching the target.
That doesn’t mean people are naturally awful, and it certainly doesn’t mean an AI system experiences ambition or moral discomfort in the same way we do. Human beings routinely choose principle over advantage. OpenAI’s incident also contains agents that refused to participate, which makes it difficult to argue that the only behaviour these systems can produce is relentless optimisation.
The pattern is more mundane. People are remarkably good at changing the moral weight of an action once something they care about depends on it. The end doesn’t necessarily justify the means at the beginning. We can get there through a series of smaller accommodations: someone else is already doing it, the target is impossible otherwise, the deadline is approaching, the competitor won’t show the same restraint, the company will lose money or the mission is simply too important to fail. Very few terrible decisions arrive announcing themselves as terrible decisions. Most come with an explanation that becomes more persuasive the more somebody wants the outcome.
Technology has a particularly complicated relationship with that kind of conviction because some of its greatest successes have come from people refusing to accept limits that everyone else regarded as obvious. That refusal can be exactly what makes an extraordinary breakthrough possible, but it becomes harder to admire without qualification once the person refusing the limit has enough wealth and influence to make everybody else live with the consequences.
The phrase “reality distortion field” became inseparable from Steve Jobs after Apple’s Bud Tribble used it to describe Jobs’s extraordinary ability to convince people that apparently impossible things could be done. Andy Hertzfeld’s accountdescribes a combination of charisma and will in which facts could become rather flexible when they stood between Jobs and the outcome he wanted. It worked often enough that the characteristic became part of Silicon Valley mythology rather than simply a description of a difficult manager.
There’s probably something to the idea that people who achieve extraordinary things need an unreasonable degree of belief in themselves. If everybody around you thinks the thing you want to build can’t be done, accepting the consensus immediately isn’t going to produce many breakthroughs. The difficulty comes when being right about the impossible often enough begins to convince somebody that they’re right about everything else as well, particularly once wealth and influence make the cost of being wrong something other people have to absorb.
Elon Musk spent more than $259 million supporting Donald Trump and Republican candidates during the 2024 US election. When his relationship with Trump later collapsed spectacularly, Musk publicly claimed that Trump would’ve lost the election without him. Whether that claim was accurate is less important than the fact that one of the richest people alive believed his influence over the political direction of the world’s most powerful country was large enough to make it publicly.
Musk is an unusually visible example, but the concentration of private power around technology goes much further than one person. A small number of companies control platforms through which enormous parts of public life are mediated, cloud infrastructure used by governments and businesses, foundational AI models increasingly being embedded into work, and capital expenditure large enough to reshape semiconductor markets.
We still tend to discuss the people at the top of those organisations in the language of founders, innovators and visionaries even when their decisions have political and economic consequences far beyond their companies. There’s something strange about how readily extreme wealth becomes confused with extreme wisdom. Make enough money and people start asking what you think about education, geopolitics, public health, transport, population decline and the future of humanity, as though success in one field automatically turns into expertise in all of them. Then we hand a remarkably powerful new technology to many of the same institutions and assume the outcomes will broadly work themselves out.
I still believe technology can improve the world, although I’m much less willing than I once was to assume that technological progress naturally becomes human progress. I’ve seen too much evidence of what access to information, communications technology, medical innovation and computing can do to dismiss their potential. AI could make expertise available to people who couldn’t previously afford it, improve healthcare, make education more personalised, speed up scientific research and remove work from people’s lives that nobody particularly enjoys doing. There are researchers, engineers and organisations genuinely trying to use it towards those ends, and scepticism about the industry surrounding AI shouldn’t erase the value of that work.
What I’ve become much more sceptical of is the assumption that because a technology can improve life, the systems around it will distribute those improvements in a way that broadly benefits everyone. We’ve already spent decades increasing productivity, automating work and producing extraordinary amounts of wealth. The distribution of that wealth tells us something about what happens when we leave the second part of the equation to sort itself out.
The World Inequality Report 2026 estimates that the richest 10% of people own roughly three-quarters of global wealth, while the poorest half owns about 2%. Fewer than 60,000 people in the richest 0.001% collectively own three times as much wealth as the poorest half of humanity. I wouldn’t claim that makes the current wealth gap definitively larger than at any point in recorded history because comparing modern wealth data with ancient empires, feudal societies and early industrial economies isn’t clean enough to support that kind of certainty. It also isn’t necessary. Oxfam estimates billionaire wealth reached a record $18.3 trillion in 2025, having grown dramatically since 2020.
At the same time, UN figures show 2.1 billion people remained moderately or severely food insecure in 2025, while 2.69 billion couldn’t afford a healthy diet. Some measures are improving and that needs to be acknowledged. Global hunger fell for a third consecutive year, but in Africa roughly two-thirds of people still couldn’t afford a healthy diet.
Technology didn’t create all of that inequality, nor would it be reasonable to expect technology alone to fix it. What those numbers should make us wary of is the assumption that creating more wealth or making an economy more productive tells us much about who eventually receives the benefit. AI is being sold partly on the promise of another enormous productivity increase, so the question of who gets that productivity dividend can’t be left until after we’ve built everything.
One of the promises I find most seductive about AI is that it’ll give us time back. It’ll deal with email, administrative work, research, document summaries and all the irritating little tasks that eat into the hours we could supposedly spend doing more meaningful work. The pitch isn’t merely that businesses will become more efficient. There’s an implied human dividend as well: more time for our families, our interests and the parts of our jobs we actually enjoy. I’m increasingly unsure where that dividend is supposed to come from.
We’ve been making work more productive for decades. Email replaced letters and internal memos, search engines removed hours of research, smartphones made us reachable almost everywhere and cloud computing turned resources that once took weeks to provision into something that can be created in minutes. Most workers didn’t receive the saved hours as additional leisure. Expectations expanded alongside the tools.
AI is entering that environment rather than some hypothetical economy in which productivity gains are automatically returned to workers as free time. Companies are already examining how much labour they need if artificial intelligence allows fewer people to produce similar amounts of work. Reuters has documented a growing number of companies cutting jobs while shifting investment towards AI, although the evidence doesn’t support the simplistic version in which AI is responsible for every layoff.
Standard Chartered has been unusually frank about where it sees the efficiency coming from. The bank has announced thousands of job cuts as AI and automation take over more work, and CEO Bill Winters apologised after describing part of that transition as replacing “lower-value human capital” with technology. The phrase was crass, but perhaps its greater offence was saying the quiet part too plainly.
A financial system rewards a company that can produce the same output with fewer employees. It doesn’t generally reward the same company for keeping everybody employed because social stability might benefit. That incentive predates AI, which is precisely why the idea that AI productivity will automatically be distributed differently deserves scepticism.
Meta’s recent experience also complicates the more breathless claims about immediate automation. Reuters reported that plans to reorganise parts of Meta around much smaller AI-supported teams ran into technical and organisational problems, with some of the more aggressive workforce assumptions reportedly being pulled back. AI isn’t currently capable of replacing every worker executives might like it to replace, but that shouldn’t be confused with companies losing interest in the savings if the technology eventually becomes capable enough.
AI doesn’t run on aspiration. It requires an extraordinary amount of physical infrastructure, and the scale of that build-out is now large enough to affect other parts of the technology economy. Demand from data centres has helped reshape semiconductor markets, particularly memory. TrendForce said conventional DRAM contract prices were expected to increase by around 90% to 95% quarter-on-quarter in the first quarter of 2026, with AI and data-centre demand contributing to the shortage. NAND Flash prices were also expected to rise sharply.
AI isn’t responsible for every expensive laptop, smartphone or component. Tariffs, exchange rates, manufacturing decisions and ordinary supply-chain constraints still matter. It does mean the AI boom has become large enough to compete for some of the same resources used by the rest of the technology industry.
We’re being sold a technology partly on the promise that it’ll make us more productive while companies investigate whether that productivity means they can employ fewer people, and while the infrastructure behind the same boom adds pressure to parts used in technology consumers already buy. Nobody needs to have designed that outcome deliberately. Incentives can produce it perfectly well on their own.
That’s part of what bothers me about the increasingly familiar claim that AI will solve some of the problems created or intensified by the economic systems deploying it. People are overworked, so here’s AI to make them more productive. Businesses are under pressure to control costs, so here’s AI to reduce labour costs. Expertise is expensive, so here’s AI to make expertise cheaper, provided someone continues paying for the models, cloud infrastructure and services underneath it. The companies selling the solution don’t have to have created the original problem for both sides of that equation to become commercially useful.
Large language models are trained on enormous quantities of human-produced data, including material drawn from the internet. That means they learn patterns from some of humanity’s finest work and some of its absolute worst. The corpus contains careful scholarship, literature, scientific discovery and ordinary human kindness alongside propaganda, prejudice, manipulation, conspiracy theories and centuries of people producing increasingly sophisticated explanations for why the thing they want to do is justified.
The online environment producing part of that material has incentive structures of its own. Recommendation algorithms tend to give people more of what keeps them engaged, although the popular idea that social-media algorithms simply place everyone into ideological bubbles and mechanically radicalise them is too neat. Research examining Facebook’s algorithmic feeds found substantial exposure to politically like-minded material, while experimentally reducing that exposure didn’t produce corresponding shifts in users’ political attitudes during the period studied. People also seek out information that confirms what they already believe.
An LLM isn’t sitting on TikTok being radicalised one video at a time, and describing training that way would be misleading. The relationship is more indirect. Humans built engagement systems that influence what becomes visible and what gets rewarded. People create culture inside those systems, and some of that cultural output eventually becomes part of the enormous record from which AI systems learn patterns about how humans speak, persuade, justify, deceive, cooperate and compete.
We then put those systems into another environment where successful completion of a goal is rewarded. It seems optimistic to expect them to model human intelligence without encountering all the ways intelligent humans have learned to rationalise the pursuit of an outcome. That doesn’t mean AI is destined to become the worst version of us. The training material contains our capacity for restraint and cooperation too, just as the Hugging Face incident contains agents that refused to cross lines others were willing to cross. The uncomfortable possibility is simply that intelligence itself doesn’t guarantee which of those patterns wins when the incentives point elsewhere.
Bill Gates published a long essay about what he calls a turbulent era for AI on 26 August, the same day OpenAI published the full details of the Hugging Face incident. The timing was coincidental, but the two are worth reading together because Gates remains deeply optimistic about AI’s potential in medicine, education and scientific research while being increasingly explicit about the institutions needed to shape what happens around it.
His foundation works with OpenAI and other major AI companies and Gates openly acknowledges his continuing financial connections to technology, so he can hardly be dismissed as somebody rooting for AI to fail. He nevertheless warns that AI could widen inequality, displace workers and eventually produce systems that act in ways their designers didn’t intend. More importantly, he doesn’t think the companies developing the technology should be expected to design the entire societal response themselves.
That sounds obvious until you look at how much of the current safety conversation depends on frontier laboratories governing themselves. The companies build increasingly capable systems, evaluate them, identify risks, create mitigations and decide whether those mitigations are sufficient to continue. Governments can regulate deployment or impose obligations, but the deepest technical understanding and much of the evidence about what frontier systems can actually do still sits inside the companies building them.
OpenAI’s response to Hugging Face shows why internal safety work is necessary. The company has also been unusually open about the incident, commissioned outside analysis from METR and Redwood, published a detailed technical report and acknowledged failures that aren’t especially flattering. Other laboratories should be encouraged to do the same, but transparency after the fact still doesn’t answer who gets to decide how much risk is acceptable before the next failure.
One of the more sobering details in OpenAI’s postmortem is that protections capable of making a substantial difference already existed. The evaluation environment didn’t include all the safeguards used in OpenAI’s externally deployed products. Its production system prompt, harness and certain safety systems weren’t being applied. When OpenAI later tested comparable behaviour with its production ChatGPT harness and system prompt, it says the models’ propensity to compromise infrastructure fell by more than 100 times.
Chain-of-thought monitoring used elsewhere at OpenAI wasn’t watching these evaluations either. The company says its existing monitor would probably have detected the relevant behaviour and paged the security team more than a day before the Hugging Face compromise.
There were organisational warning signs before that point. An internal team had noticed an agent using the improvised message board and observed prohibited internet access in late May. Agent activity later contributed to an Artifactory outage, a security incident was opened and the infrastructure was rebuilt. The evaluations continued because the significance of agents discovering communication mechanisms and unintended internet access hadn’t travelled through the organisation in the way it needed to.
That begins to look less like an exotic alignment failure and more like a recognisable institutional one. Information existed in different places, different people understood different pieces of it and the organisation didn’t convert those signals into a decision quickly enough.
OpenAI has since strengthened isolation and monitoring, changed escalation rules and paused its largest planned frontier reinforcement-learning run while it conducts smaller tests. Severe model-behaviour alerts now trigger responses from researchers and security staff, with activity expected to stop when they can’t establish quickly that an alert is benign. The company ultimately wants some of the most serious shutdown decisions automated because agents can operate faster than humans can investigate what they’re doing.
There’s a slightly absurd quality to needing automated systems capable of stopping other automated systems because the humans responsible can’t necessarily understand what the first system is doing quickly enough, but the underlying problem extends well beyond OpenAI. Human-in-the-loop oversight starts becoming much less reassuring once AI systems operate at a pace no person can meaningfully supervise, while companies are deploying agents into organisations whose governance systems are struggling to keep up.
South Africa has its own version of that timing problem. Businesses are making decisions about AI while the country is still working through the policy framework that will eventually govern some of them. Regulation has always had the disadvantage of arriving after somebody has discovered what a technology can do, but autonomous systems compress the amount of time institutions have to catch up.
I don’t come away from the Hugging Face incident thinking AI has revealed itself to be inherently malicious. The evidence doesn’t support that, and the agents that refused to participate make the picture more complicated anyway. What bothers me is how familiar the underlying behaviour feels.
The agents had an objective. Some knew they were approaching or crossing boundaries. They had evidence that others were doing it, reasons to believe the legitimate route wouldn’t work and an incentive to keep looking for another path. Some stopped, while others constructed enough of a justification to continue.
We’ve spent centuries building human institutions in which variations of that calculation happen every day. Companies convince themselves that growth requires one more compromise. Political movements excuse conduct from their own side because losing would be worse. Extremely wealthy people accumulate enough influence that the distinction between what they want and what everybody else supposedly needs becomes increasingly difficult for the people around them to challenge. Employees learn which numbers determine whether they get promoted and which principles become flexible when those numbers are threatened.
None of that means every person or institution behaves badly. It means intelligence has never made human beings automatically immune to incentives, self-justification or social reinforcement. I still believe AI could improve an enormous number of lives. What I don’t believe anymore is that technological progress carries some built-in mechanism that makes those benefits spread fairly, or that the people and companies accumulating extraordinary wealth and power from a technology will voluntarily know where the limits should be simply because they’re intelligent enough to build it.
OpenAI can make its agents safer, and the evidence from its own testing suggests that better containment and monitoring can make a substantial difference. Teaching an agent to stop when a task is broken rather than endlessly searching for another route also seems entirely sensible. Those engineering fixes shouldn’t distract us from the culture and incentive structure in which these systems are being built.
We spend a lot of time rewarding people for refusing to take no for an answer. We lionise relentless founders, reward companies for extracting more value with fewer people and tolerate behaviour from the powerful that would look absurd coming from almost anybody else. We’ve built online systems that reward whatever holds attention, economic systems that reward whatever produces growth and political systems in which enough wealth can buy extraordinary access to power. The people who succeed most spectacularly within those structures are then held up as the people best qualified to tell us what comes next.
Now we’re trying to teach increasingly capable machines where the boundaries are. OpenAI can harden the sandbox, improve the monitoring and train agents to stop when a task has become impossible. It should. What I don’t know is how you teach a machine that some objectives aren’t worth pursuing at any cost when so much of the world it has learnt from keeps demonstrating the opposite. We’re asking these systems to exercise a kind of restraint that we still haven’t worked out how to demand consistently from the people and institutions with the most power.
The post OpenAI’s Hugging Face incident should make us question what we’re teaching AI appeared first on Reframed.
]]>The post AI jobs in South Africa are becoming harder to define appeared first on Reframed.
]]>The mix offers a glimpse of what happens once generative AI moves beyond experimentation and becomes part of ordinary business. Existing professions don’t necessarily disappear, but the skills expected inside them begin to shift. For South Africa, that could open AI-related work to people who didn’t come through computer science, while raising another question about whether greater participation eventually translates into greater influence inside the companies adopting it.
Brandtech+ is an interesting place to watch this happen because generative AI has already been pushed fairly deep into its creative operation. The company, formerly known as OLIVER+, works across film, CGI, automation, AI, motion design and digital and print production. Its parent, The Brandtech Group, owns Pencil, a generative AI marketing platform that the group says has produced more than one million ads across 5,000 brands.
Its South African operation is expanding too. Brandtech+ says it is recruiting hundreds of people across creative, technology, account management and project management, and its current vacancies show how AI is already bleeding into different kinds of work. Johannesburg openings include a GenAI Global Capability Lead and a Senior Integrated AI Producer, while other roles increasingly expect familiarity with AI-assisted workflows even when AI isn’t the job itself. That overlap may tell us more about AI employment than the brief period when “prompt engineer” looked likely to become the defining profession of the generative AI era.
Yolisa Mjamba’s title is Gen AI Senior Copywriter, and the order of those words is revealing. She remains a copywriter, but the tools available to do the job and the expectations attached to it are changing.
“AI can give you hundreds of lines in seconds, but that doesn’t mean any of them deserve to become the line,” Mjamba says. “The writer still needs to bring judgement, cultural understanding and a point of view.”
There’s some corporate self-interest in emphasising the continued importance of human creativity while introducing software capable of producing creative work at extraordinary speed. Still, the underlying problem is real. Generating dozens of possible lines doesn’t tell a brand which one is worth using. Someone still has to recognise when the language is generic, when the tone is wrong for the audience or when an apparently polished answer should never reach a client.
Tasmin le Roux encounters the visual version of that problem as a Gen AI Senior Motion Graphics Designer. Her role combines generative AI with motion design and visual storytelling, and she has completed specialist AI filmmaking training. She describes generation as an early part of the process, with much of the craft still sitting in directing and refining the work before deciding what is actually good enough to use.
Alison Stansfield-Franks, Brandtech+’s Global Head of Creative Optimisation, makes a related argument when she warns against treating faster production as evidence of better creativity. Taste and judgement remain important in her telling, even when the systems producing the material can work considerably faster than the people evaluating it.
The pattern becomes clearer outside the creative roles. Vicky Moodley, the company’s Gen AI Business Lead, has helped develop a Gen AI Centre of Excellence and train global teams on Pencil, while HR Lead Mumtaj Mohamed is dealing with the skills employees need as their roles change. Chief operating officer Candice Siege is concerned with getting AI to work consistently across different teams and markets while still meeting client requirements. Once that happens, AI adoption becomes an organisational problem as much as a technical one.
McKinsey’s 2025 State of AI research suggests many businesses are confronting a similar gap. Its survey found that 88% of respondents said their organisations used AI in at least one business function, but only 7% said it had been fully scaled across the organisation. Giving employees access to AI is relatively easy compared with redesigning real workflows around it.
For many workers, AI competence may simply become part of staying current in the career they already have. That puts more pressure on employers to provide meaningful training rather than expecting employees to figure out another significant workplace shift on their own.
That question becomes particularly relevant when looking at women in African technology because the continent already loses a significant amount of female talent between education and senior employment. McKinsey found that women account for 47% of STEM graduates from African universities, yet their participation falls to between 23% and 30% in technology roles. Less than 12% of technology leadership positions are held by women.
The problem is already visible in the gap between Africa’s female STEM graduates and the women who make it into technology careers. Getting more girls and women into technical education remains useful, but the graduation numbers suggest that access to education is only part of what is going wrong. A substantial share of the loss happens after women have already acquired the qualifications.
Generative AI makes the boundary around that workforce harder to draw. Mjamba doesn’t need to retrain as a software engineer for AI to affect what employers expect from her as a copywriter, while le Roux can become highly specialised in AI-assisted production without abandoning motion design. Moodley’s work combines technology adoption with training and organisational change, and Mohamed’s involvement shows how quickly a new technical capability starts affecting hiring and career development.
That could create additional routes for women into work that companies consider important to their AI strategies. Someone with deep expertise in design or language may increasingly find that expertise combined with AI, while project managers and other people responsible for getting work out of the door are also being expected to understand where the technology fits.
Broader access to the work won’t necessarily produce broader access to power. Women can become proficient with AI systems while remaining underrepresented in the positions that decide budgets or control strategy. Companies can spend heavily on training without changing the promotion structures that produced the leadership gap in the first place.
Mohamed argues that businesses have a responsibility to give employees the training and confidence to develop new capabilities as their jobs change. That becomes more consequential once proficiency with generative AI moves from an optional advantage to something employers simply expect, because people who aren’t given access to the tools or time to learn them can fall behind even when they were already good at the underlying job.
South Africa therefore has to think about skills and progression together. Workers need realistic access to the capabilities changing their professions, but widening the entry point won’t achieve much if women continue disappearing from the pipeline before reaching senior positions.
Brandtech+ is making another argument through its South African expansion. Estelle van Heerden, its Global Automation and AI Integration Lead, believes generative AI can make proximity to traditional advertising centres less important, allowing more specialist creative work to be done from South Africa for international clients.
There is already a much larger South African industry built around the premise that work can travel. Business Process Enabling South Africa says the country’s global business services sector created 26,346 new jobs serving international markets in 2025, its highest annual total since 2018. Just under 23,800 went to young people, and the UK and US remain important source markets for work delivered from South Africa.
Creative production follows different economics from contact centres and other outsourced business services, so the comparison has limits. What the GBS sector demonstrates is that a South African worker can build a career around companies and customers elsewhere without physically moving to those markets.
Brandtech+ says it wants its South African expansion to create international careers locally, and generative AI could make that proposition easier in some creative disciplines. A designer in Johannesburg or Cape Town can work with many of the same models and production tools available to a team in London, while the work itself can already move between countries without much difficulty.
Where the work happens, however, is only part of what determines its value. If South African teams receive large volumes of AI-assisted adaptation and production while strategy and creative authority remain elsewhere, the country gains employment without gaining much influence over the work. A stronger outcome would see people based here increasingly involved in developing the processes, advising global clients and making the creative decisions that determine what eventually gets produced.
The women Brandtech+ has highlighted are interesting because their jobs already cross some of the boundaries that once separated creative and technical work. A copywriter can now have Gen AI in her title and a motion designer can specialise in AI filmmaking, while people elsewhere in the organisation have to understand the technology because their jobs depend on making it work.
That may be a more useful way to understand AI employment in South Africa than looking for an entirely new category of “AI professionals”. For a large number of people, AI will arrive inside the career they already have. Whether that widens opportunity for South African women will depend on whether they get access to the skills early enough to benefit from the change and remain in the pipeline as those jobs become more valuable and more senior.
The post AI jobs in South Africa are becoming harder to define appeared first on Reframed.
]]>The post The promise of AI for Africa comes with a dependency problem appeared first on Reframed.
]]>The continent has skipped stages before. Jyoti Ball, General Manager for Sub-Saharan Africa at AWS, pointed to the spread of mobile phones without ubiquitous fixed-line networks and the growth of mobile money where conventional banking hadn’t reached much of the population. AI, she argued, could be another opportunity to jump ahead. She then moved to the other proposition technology companies increasingly bring to Africa: that AI can help solve problems that have resisted older technologies and institutions. Ball talked about language models handling customer service in African languages, computer vision identifying crop disease and developers building products more quickly. “AI will solve real problems on the continent, for the continent,” she said.
AWS had examples that made the pitch less theoretical. Shop2Shop is using an agentic Know Your Customer system in South Africa’s informal retail market, Jubilee Insurance has built an AI claims agent, and Aerobotics analyses drone, satellite and mobile imagery to monitor the health of 65 million trees. These are useful applications, but they’re a long way from establishing that AI can solve Africa’s problems.
Financial exclusion didn’t emerge because software wasn’t intelligent enough. Neither did poverty, unemployment or failing public institutions. Better technology can change what’s possible within those systems, sometimes considerably, without addressing why people lacked access, employment or effective services in the first place. AI companies nevertheless talk about Africa as though its problems are unusually well suited to technology. Less often discussed is whether the technology, the economic model behind it and the dependencies created by adopting it are particularly well suited to Africa.
That question becomes harder to avoid as the commercial case for AI moves beyond putting a clever assistant on somebody’s laptop. Companies are being told that agents can allow them to produce more software, process more work and automate tasks that previously required people. On a continent that needs to create jobs on an enormous scale, productivity has consequences that don’t fit neatly into a keynote slide.
Standard Bank itself shows why those consequences aren’t straightforward. Molabe said 80% of the bank’s migratable workloads are now running on AWS, its customer platforms have moved there and it has completed an internal AI Foundry through which engineering and solution teams can use the technology. The bank’s ability to deploy AI at this scale partly reflects years of work that came before it. When Tanuja Randery, AWS Vice President and Managing Director for EMEA, asked what had allowed Standard Bank to move beyond experiments, Molabe repeatedly returned to foundations and changes in how the bank works.
That complicates the leapfrogging story. A company founded in 2026 can avoid accumulating some of the legacy technology sitting inside an institution such as Standard Bank. An existing African bank can’t simply skip its way out of several decades of software. Standard Bank is moving quickly with AI partly because it spent a long time doing the less glamorous work required to make that possible.
FNB offered another view of the productivity argument. Chief Digital Officer Kevin Mitchell said the bank has about 3,000 experienced engineers and still has more technology demands than those engineers can meet. For a company in that position, giving developers better tools needn’t translate immediately into fewer developers because the backlog already exists.
Jonathan Allen, Executive in Residence at AWS, later gave an example with rather different arithmetic. Deriv expected a new charting platform supporting more than 170 indicators to require about 12 developers and between 12 and 24 months. AWS says one engineer using Q Developer built it in eight weeks. Deriv got its software faster and could put the rest of the team elsewhere. Another company budgeting its next project may notice that something once scoped for 12 people was completed by one.
Amazon has already acknowledged that AI productivity can eventually mean fewer jobs. In a message to employees, chief executive Andy Jassy said wider use of generative AI and agents would mean fewer people doing some existing jobs and more people doing others, but that Amazon expected its total corporate workforce to shrink over the next few years as it captured efficiency gains from AI.

Amazon subsequently announced reductions affecting about 14,000 corporate roles in October 2025 and another 16,000 in January 2026, although the company attributed those restructuring decisions more broadly to reducing layers and bureaucracy rather than saying those jobs had simply been replaced by AI.
What Amazon does doesn’t tell us what Standard Bank, FNB or another African employer will do, but Jassy’s comments remove the convenient assumption that displacement is only a theoretical concern raised by people who are sceptical of AI.
The IMF estimates that about 22% of jobs in Sub-Saharan Africa are likely to be affected by AI. Roughly 13% of total employment falls into work at significant risk of replacement, while almost 10% could benefit from AI complementing workers. The region’s relatively low exposure compared with wealthier economies may protect it from some immediate disruption, but the IMF notes that it could also mean Africa captures less of AI’s productivity and growth gains. By 2030, Sub-Saharan Africa is expected to account for roughly half of all new entrants into the global labour force, equivalent to as many as 15 million new jobs each year.
A project moving from 12 developers to one doesn’t tell us what happens to employment. The company might build more and keep everyone. It might redirect the other engineers towards work that was previously impossible to get to. It might also hire differently the next time around. The technology changes the calculation even when it doesn’t dictate the answer.
AWS has been thinking about another consequence of cheaper software for some time. Technical debt came up repeatedly at re:Invent 2025 in Las Vegas, where AWS Transform custom was pitched at old frameworks, outdated runtimes, API migrations and other work companies postpone because there’s always something more urgent to build. AWS says organisations allocate 20% to 30% of their software development resources to repeatable transformation work and claims Transform can cut execution time for many of those tasks by more than 80%.
AWS had already begun describing a broader version of this strategy at re:Invent 2025, where the launch of Kiro, AWS Security Agent and AWS DevOps Agent as frontier agents showed how quickly the company was moving beyond assistants towards systems expected to carry out larger pieces of work. Johannesburg was the continuation of that strategy, this time with African companies used to show what it looks like in practice.
In Johannesburg, Allen returned to technical debt, but the problem had changed. He said AWS Transform customers had eliminated more than 1.6 million hours of manual modernisation work, then argued that periodically cleaning up a codebase was no longer enough because AI-assisted development was increasing the rate at which software could be produced. Transform Continuous Modernization is supposed to work alongside development, finding outdated dependencies and other problems rather than waiting for a company to begin another large modernisation project.
Allen invoked Jevons’ paradox while talking about code generation: making something cheaper can lead people to use more of it rather than simply banking the saving. That is a plausible future for software because if code becomes much cheaper to produce, companies are unlikely to decide they already have enough. They can attempt products that were previously too expensive, add features that never made it through the backlog and build more internal systems.
The technical-debt pitch has therefore shifted in less than a year. At re:Invent 2025, AI was being used to deal with debt accumulated during years of conventional software development. In Johannesburg, AWS was describing AI that continuously deals with debt in an environment where AI-assisted development itself allows much more code to be produced. The old maintenance work hasn’t vanished because code became easier to generate. There may simply be much more software requiring it.
There’s a similar gap between having access to AI in Africa and having AI that has been properly adapted for African conditions. Language is the easiest place to see it. AfroBench was created to evaluate large language models across 64 Indigenous African languages and 15 tasks at a time when comprehensive evaluation of African languages remained limited.
South Africa presents a more complicated problem than adding isiZulu, isiXhosa or Afrikaans to a supported-language list. People switch languages halfway through conversations and sometimes halfway through sentences. Slang, borrowed vocabulary and cultural knowledge shape meaning. A customer-service agent can produce grammatically correct isiZulu and still misunderstand the person using it.
The problem isn’t limited to language. A model can know what a spaza shop is without knowing much about how one operates, how informal credit works between a shopkeeper and customers or why documentation expected from a formal retailer may simply not exist. African markets also differ enormously from one another. Credit histories, government processes, regulatory systems, public records and available datasets don’t become interchangeable because a product is marketed for “Africa”.
AWS itself spent a substantial portion of its keynote making a version of this argument about companies. Allen said “context is everything in an agentic world” because even a highly capable model doesn’t know how a particular organisation works. It doesn’t know which database is authoritative, whether a policy has been superseded or what somebody is permitted to see.
Amazon Bedrock Managed Knowledge Base is intended to connect agents to company information while maintaining document permissions, and its agentic retrieval system can evaluate information across different sources rather than simply returning whatever looks most similar to the question. AWS Context builds a knowledge graph from structured and unstructured organisational data and learns which sources tend to produce useful answers.
The reasoning is sensible: a generic model doesn’t understand Standard Bank simply because it understands banking. It needs Standard Bank’s accumulated knowledge, rules and exceptions. The same logic applies outside the company. An AI system doesn’t understand South Africa because it can write a paragraph about Johannesburg. Making it genuinely useful across South African languages, informal economies, financial arrangements and institutions requires local context that somebody has to collect, structure and maintain.
That work also raises a question about who supplies the layers around it. Ball said she wanted Africans not simply to consume AI but to “build AI and own AI”. AWS says it has invested $890 million on the continent since 2018, committed another $1.5 billion, brought 154 services to its Cape Town region and trained one million people in cloud and AI skills. Those investments give African companies access to computing capabilities that would be prohibitively expensive to reproduce independently.
Ownership becomes less clear as more of the AI stack comes from the same provider. A company may run its compute on AWS and access models through Bedrock. Agent Core can provide the environment in which its agents operate, Managed Knowledge Base can connect them to company information and AWS Context can organise it. Developers can use Q Developer, DevOps Agent can participate in delivering their software, Transform can maintain it and Continuum can work across security.
AWS also offers models from other AI companies through Bedrock. Allen argued in Johannesburg that organisations shouldn’t expect one model to be best at every job, which makes sense in a market where capabilities change quickly. But being able to change the model doesn’t necessarily remove the dependency if the compute, data connections, agent infrastructure, developer tools and security systems remain in the same cloud.
Cloud computing has always created some of this dependence. Migrating away from a provider is technically possible but can become extremely expensive once years of integrations, skills, architecture and internal processes have accumulated around it. AI creates more places for those attachments to form, particularly if agents become the way employees interact with company data rather than another workload quietly running in a data centre.
An African company can therefore become considerably more capable at building with AI while becoming more reliant on foreign technology infrastructure. It may own the application, the data and the customer relationship while finding that replacing the systems through which all three operate would be deeply disruptive. Few contemporary technology companies operate without depending on infrastructure owned by somebody else, but “Africans building AI” and Africa controlling more of its technological future aren’t necessarily the same thing.
Allen’s presentation suggested that AWS expects these relationships to deepen. He was dismissive of many of the enterprise assistants built during the first wave of generative AI, describing them as a “slightly faster search bar” because the person still had to move between systems and turn the answer into work. Amazon Quick is designed to take on more of that work, while Q Developer extends further into software development, DevOps Agent handles parts of what follows, Transform works on the existing codebase and Agent Core provides infrastructure for agents companies build themselves.
AWS is betting that African companies will want to move quickly enough that the trade-offs become secondary to the opportunity. Some probably will. What remains unresolved is whether the productivity gains create enough new work to offset what disappears, whether AI systems become meaningfully better at African languages and contexts, and how much technological control African businesses retain once more of their infrastructure, data access and software development depends on a handful of global platforms.
The Johannesburg summit didn’t answer any of that, but, it did make clear that AWS wants to be one of the companies (if not the company) on which those answers are increasingly reliant on..
The post The promise of AI for Africa comes with a dependency problem appeared first on Reframed.
]]>