Whether or not your organisation has an AI policy, your employees are almost certainly using generative AI tools such as ChatGPT, Microsoft Copilot or Gemini to draft emails, summarise documents and analyse data. Used well, these tools save hours every week. Used carelessly, they can leak personal information, produce confident nonsense and put your organisation on the wrong side of the Protection of Personal Information Act (POPIA).
This guide sets out a practical, proportionate approach.
The three real risks
- Personal and confidential information leaving your control. Pasting a client list, a disciplinary record or a medical note into a public AI tool may disclose personal information to a third party and, in some cases, move it outside South Africa.
- Wrong answers that look right. Generative AI predicts plausible text. It can invent figures, case law and references, and present them convincingly.
- Unfair or opaque decisions. Using AI to screen job applicants or assess customers without human oversight raises fairness concerns and specific POPIA questions about automated decision-making.
What POPIA means in practice
POPIA sets eight conditions for lawful processing of personal information. Several apply directly to AI use:
- Purpose specification and processing limitation. Only use personal information in AI tools for the purpose it was collected for, and only as much as you need.
- Security safeguards. You must take reasonable technical and organisational measures to protect personal information, which includes choosing tools whose data handling you understand.
- Openness. People should know how their information is used.
- Automated decisions. Section 71 limits decisions that have legal or similarly significant effects on a person when they are based solely on automated processing. Keep a human genuinely involved.
- Cross-border transfers. Section 72 restricts sending personal information outside South Africa unless conditions are met, which matters because most AI services process data overseas.
A simple traffic-light policy
Many organisations start with a one-page policy that staff can actually remember:
| Green: go ahead | Amber: approved tools only | Red: never |
|---|---|---|
| Drafting generic emails and documents | Summarising internal documents | Client or employee personal information in public tools |
| Brainstorming and outlines | Analysing anonymised data | Passwords, bank details, ID numbers |
| Explaining concepts | Writing code for internal systems | Final decisions about people without human review |
"Approved tools" usually means enterprise versions, such as Microsoft 365 Copilot under your organisation's tenant, where your data is not used to train public models and access respects existing permissions.
Good habits to teach every user
- Anonymise first. Replace names and identifiers before pasting text.
- Check everything that matters. Verify facts, figures and references against the source.
- Say when AI helped. Be transparent with managers and clients where appropriate.
- Keep a prompt library. Share prompts that work so the team improves together.
Start with training, not prohibition
Banning AI tools rarely works; people use them on their phones instead. A short, practical training session combined with a clear policy and approved tools gives you the productivity benefits with far less risk.
Our Generative AI at Work course trains staff to use AI productively and safely, POPIA and Data Protection covers the legal obligations in depth, and AI Governance and Ethics helps leaders put the right policies and oversight in place.
This article is general information, not legal advice. Consult your information officer or legal adviser about your specific circumstances.