Thought leadership Risk and POPIA

The AI tool nobody approved

Staff are already pasting company data into chatbots. Under POPIA the live question is not whether it is happening, but whether you could show what happened to it.

Every organisation I have looked at has unsanctioned AI in it. Someone in finance is summarising a supplier contract. Someone in HR is rewriting a disciplinary letter. Someone in support is pasting a customer complaint, name and account number included, into a free tool to get a politer version back. None of them think they are doing anything wrong, and in fairness nobody told them otherwise.

The usual first response is a ban, circulated by email. It does not work, and it makes the position worse. The use continues on personal phones and personal accounts, where there is no log, no retention control and no record. You have converted a visible risk into an invisible one and written yourself a policy you cannot evidence.

POPIA does not care how the data got there. If personal information is being processed, the responsible party has to secure it, has to have a written arrangement with whoever processes it on their behalf, has to have a lawful basis, and faces real conditions on sending it outside South Africa. A free chatbot account opened by an employee satisfies none of that. There is no operator agreement. There is often no clarity on where the processing happens or whether the content trains a model. And when the Information Regulator asks what was disclosed, the honest answer is that you have no idea, which is a materially worse answer than a mistake you can describe.

The practical position is not prohibition. It is to give people a sanctioned route that is better than the one they are using. A business account with training on your content turned off and retention configured. A short, readable line on what may and may not go into it — customer records, ID numbers, health information, anything covered by a client confidentiality clause. Logging, so there is a record. And one named person who can approve an exception, because a rule with no exception path gets routed around.

The piece organisations skip is telling people why. Staff are not trying to leak anything. They are trying to get work done with the only tool that helped. Explain which categories of information create a legal obligation and most people will cooperate immediately, because the ask is finally specific rather than a general instruction not to use the useful thing.

There is also a question worth asking in the other direction. If several people independently reached for an AI tool to do the same job, that job is a candidate for building properly — inside your systems, with the data staying where it belongs and an approval step before anything leaves. Shadow AI is a fairly reliable signal of where the real friction is. Most businesses treat it only as a breach to close.

I hold Certified Data Protection Officer and Certified Information Privacy Manager certifications, and I spend a reasonable amount of time on POPIA and GDPR questions attached to exactly this. The pattern is consistent: the organisations in trouble are not the ones whose staff used AI. They are the ones who cannot say what was used, by whom, on what.

Want this applied to your operation?

Next pieceThe dull work is the work