THE SIGNAL IN ONE SENTENCE
South African President Cyril Ramaphosa has proposed that BRICS create an international mechanism for independent scientific evaluation of artificial intelligence. He paired that idea with meaningful human control, mandatory reporting of serious incidents, safeguards that become stronger as capability increases, and investment in sovereign AI capacity for developing economies. It is a sharper proposal than another request to use AI responsibly, but it is still a proposal. No public charter says who would run the tests, which systems would be covered, what access evaluators would receive, what counts as a serious incident, or what happens when a system fails. The signal is that a major African government wants developing economies to help inspect powerful AI, not merely import it. The next signal must be the machinery that makes the inspector independent.
01
WHAT ACTUALLY CHANGED
Ramaphosa delivered the proposal on September 13 during the open session on inclusive global growth at the 18th BRICS Leaders' Summit in New Delhi. South Africa's Presidency published the full statement the same day. The speech says BRICS should establish an international mechanism for independent scientific evaluation of AI. It does not say that BRICS adopted or launched such a mechanism.
The proposal has four attached pieces. Ramaphosa called for meaningful human-control principles, mandatory reporting of serious incidents, progressively stronger safeguards as capability increases, and simultaneous investment in sovereign AI capacity for developing economy countries. Those pieces connect testing, operational accountability, release rules, and the ability to build locally.
Ramaphosa compared formal external checks, audits, and government authority for AI companies with oversight used in aviation, pharmaceuticals, nuclear power, and finance. The analogy is a policy argument, not evidence that one regulatory model can be copied directly. AI models change quickly, cross borders through software, and may be available through products that reveal little about the underlying version.
The speech lists potential benefits in medicine, education, scientific discovery, agriculture, productivity, and development. It also repeats warnings from frontier-model developers about cyber operations, assistance with biological weapons development, autonomous action, manipulation, mass surveillance, employment disruption, and systems becoming difficult to control. Those are stated risks and scenarios, not a claim that every current model can perform every listed act.
Neither the Presidency statement nor the accompanying SAnews report provides an evaluator, legal authority, membership rule, funding source, budget, access protocol, test suite, incident threshold, reporting channel, enforcement process, publication right, or implementation date. The proposal therefore creates a useful design question: what would BRICS have to publish before independent evaluation becomes more than a diplomatic phrase?
02
WHY THIS MATTERS
Developing economies have a direct stake in AI evaluation. Models used in public services, lending, hiring, education, health, agriculture, and security may perform differently across languages, infrastructure, law, and local conditions. If tests are designed only by the largest laboratories and their home regulators, failures that matter in Johannesburg, Jakarta, Addis Ababa, or rural clinics can remain invisible until deployment.
Independence is a structure, not a compliment. An evaluator needs technical competence, stable funding, protection from dismissal, rules for conflicts of interest, access to the actual model and relevant records, and the right to publish an unfavorable finding. A committee funded by the vendors it reviews may still do excellent work, but readers should be able to see who selected it, what was withheld, and whether a member government can bury the report.
Mandatory incident reporting can turn isolated failures into shared evidence. That requires a practical definition of serious. A system helping to expose private records, bypass safeguards, generate dangerous instructions, manipulate a public process, or cause a service failure may deserve rapid reporting. Minor glitches should not flood the channel. The useful rule will define thresholds, deadlines, recipients, public notice, protections for affected people, and consequences for hiding an incident.
Capability-linked safeguards sound sensible because not every model needs the same treatment. A small classifier and a frontier agent should not face identical tests. The hard part is deciding which measured abilities trigger stronger access controls, external review, monitoring, or a delayed release. A vague capability threshold can become a loophole. A reproducible threshold can become an engineering gate.
Sovereign capacity keeps oversight from becoming another dependency. A country cannot meaningfully challenge a vendor's evidence if it lacks researchers, secure computing, local datasets, evaluation tools, and public institutions able to run the tests. Investment in capacity should not mean each country rebuilding every layer alone. It should mean enough control to inspect, adapt, procure, refuse, and recover without asking a distant provider for permission.
03
WHERE IT COULD HELP
- Publish a BRICS evaluation charter naming the covered systems, evaluator-selection rules, funding, conflicts, access rights, test methods, disclosure duties, appeals, and remedies
- Create a protected incident channel with severity levels, reporting deadlines, affected-person notice, regulator access, public summaries, and penalties for concealment
- Define capability gates through reproducible tests and require stronger evaluation, monitoring, access controls, or release review when a model crosses them
- Fund regional test labs, secure compute, fellowships, local-language benchmarks, public-interest red teams, and procurement expertise across developing economies
- Require every report to identify the exact model version, test conditions, unavailable evidence, limits, local contexts, vendor response, and whether the evaluator could publish without approval
KEEP A HAND ON THE WHEEL
This article covers a South African proposal, not an adopted BRICS institution, treaty, regulator, laboratory, or testing program. The Presidency statement and SAnews report are primary government records of what Ramaphosa proposed. They are not independent evidence that the mechanism would work. No public source reviewed for this article names its legal authority, member participation, evaluator, host country, budget, funding safeguards, scope, access rights, methods, capability thresholds, incident definitions, reporting channel, confidentiality rules, publication rights, enforcement, or start date. The speech draws on warnings from AI executives, including Anthropic chief executive Dario Amodei. Those warnings mix observed technical progress with forecasts and policy preferences. BRICS members have different laws, security interests, technical capacity, political systems, and commercial relationships. A shared mechanism could widen scientific scrutiny, or it could become a geopolitical standards body with limited transparency. The evidence to watch is a negotiated charter, several participating countries, named independent institutions, inspectable methods, assured access, protected publication, funding disclosures, and a first report that includes inconvenient findings.
04
TERMS WORTH KEEPING
OPEN GLOSSARY CARD
Human control
The practical ability and authority of people to understand, direct, interrupt or stop an automated process before unacceptable harm occurs.
OPEN GLOSSARY CARD
Capability-based regulation
Rules that become applicable or stricter when an AI system demonstrates specified abilities or risks.
OPEN GLOSSARY CARD
Independent assessment
A review performed by a qualified party that is separate from the organization building or operating the system.
SOURCES AND VERIFICATION STATUS
This article was written from the materials below. Product claims and dates were checked against those sources on September 13, 2026.
PUBLICATION RECEIPT: Revision 1. Published September 13, 2026.
THE PUBLICATION ENGINE
WANT A SIGNAL OF YOUR OWN?
We build source-grounded publications, private briefings, and editorial systems for organizations with something useful to say.
WORK WITH US