AI Is Already in Your Workplace – Is Your Business Managing the Risk?

24 August 2026

Artificial intelligence is no longer something businesses are preparing to use in the future.

It is already being used in workplaces every day.

Employees are using AI tools to draft emails, summarise documents, prepare reports, conduct research, create presentations, analyse information and respond to clients. In many cases, this happens without formal approval, management oversight or clear rules governing how the technology may be used.

AI can undoubtedly improve efficiency. However, unmanaged use can expose a business to confidentiality breaches, inaccurate work, privacy concerns, unfair employment decisions and reputational damage.

The question is therefore no longer whether employees will use AI.

The more important question is whether the business understands how it is being used and has put appropriate safeguards in place.

South Africa’s Existing Laws Still Apply

South Africa does not currently have a dedicated AI law regulating the use of artificial intelligence in the workplace.

A Draft National Artificial Intelligence Policy was published in April 2026 but was formally withdrawn in June 2026 to allow it to be reworked.

This does not mean that workplace AI use is unregulated.

Existing legislation, contractual obligations and common-law duties continue to apply. Depending on how an AI tool is used, employers may need to consider the Protection of Personal Information Act, the Employment Equity Act, employment contracts, confidentiality obligations, intellectual property rights and general principles of fair labour practice.

An employer cannot avoid these responsibilities simply because a decision or work product was assisted by technology.

Protecting Personal and Confidential Information

One of the most immediate risks arises when employees enter information into an external AI platform.

This information may include:

  • Employee records
  • Client information
  • Financial information
  • Legal advice
  • Trade secrets
  • Internal reports
  • Unpublished business plans
  • Commercially sensitive documents

Employees may view an AI tool as a private digital assistant. However, information entered into an external platform is being shared with and processed through a third-party system.

Before using an AI tool, employers should understand what happens to the information entered into it. This includes where the information is stored, who may access it, whether it is used to improve the system and whether it may be transferred outside South Africa.

POPIA requires personal information to be processed lawfully and reasonably. It must also be adequate, relevant and not excessive in relation to the purpose for which it is processed. The responsible party remains accountable for ensuring compliance with the conditions for lawful processing.

Removing a person’s name may not always resolve the risk. A person could still be identifiable from information about their position, circumstances, location or relationship with the business.

A practical workplace rule is therefore:

If an employee would not be authorised to send the information to an unknown third party, they should not paste it into an unapproved AI tool.

AI-Assisted Recruitment and Employment Decisions

AI tools are increasingly capable of screening applications, comparing qualifications, ranking candidates and analysing employee performance.

These tools may help employers process large amounts of information efficiently. However, they may also produce unfair or discriminatory outcomes.

An automated system can appear neutral while reflecting bias contained in its training data, design or selection criteria. It may disadvantage candidates because of rigid keyword requirements, employment gaps, language patterns or historical data drawn from an unrepresentative workforce.

The Employment Equity Act requires employers to promote equal opportunity and eliminate unfair discrimination in employment policies and practices. Recruitment and selection form part of those employment practices.

POPIA also places limits on certain decisions that are based solely on automated processing where the decision has legal consequences or substantially affects a person. In applicable circumstances, safeguards must include an opportunity for the person to make representations and access to sufficient information about the underlying logic of the automated process.

AI may support a recruitment or employment decision, but meaningful human oversight should remain part of the process.

Employers should be able to explain what information was considered, how the recommendation was generated and why the final decision was made.

Who Is Responsible When AI Gets It Wrong?

AI-generated content can appear professional, compelling  and complete while still being inaccurate.

An incorrect output could lead to:

  • Inaccurate advice being given to a client
  • A flawed financial or legal document
  • False information being included in a report
  • An incorrect business decision
  • Reputational damage
  • A breach of contractual or professional obligations

Employees should understand that using AI does not transfer responsibility for their work to the technology provider.

AI should generally be treated as a tool that supports the work, rather than as the final decision-maker.

The level of human review should be proportionate to the risk. A routine internal draft may require one level of checking, while legal, financial, safety-critical or client-facing work may require far more careful verification.

Businesses should also determine when employees must disclose that AI was used and when approval is required before AI-generated content is shared externally.

Can an Employee Be Disciplined for Misusing AI?

An employee may potentially face disciplinary action for misusing AI.

Examples could include uploading confidential information, ignoring an instruction not to use AI for a particular task, fabricating information or submitting unchecked AI-generated work that causes harm.

However, not every incident  involving AI will automatically justify dismissal.

The employer should consider whether there was a clear rule or instruction, whether the employee knew or should have known about it, the seriousness of the conduct, the harm caused and whether the rule has been applied consistently.

This is why employers should establish clear rules and expectations before attempting to enforce them.

A business that has never addressed AI use may find it more difficult to prove that an employee understood the boundaries.

What Should an AI Workplace Policy Cover?

An effective AI policy does not necessarily need to prohibit the technology.

It should create clear boundaries for responsible use.

The policy should address:

  • Which AI tools are approved
  • What information may not be uploaded
  • When management approval is required
  • How AI-generated work must be reviewed
  • When AI use must be disclosed
  • How personal information must be protected
  • Who is accountable for the final work product
  • What employees should do when uncertain
  • The consequences of breaching the policy

The policy should be supported by practical training and should reflect the actual work, systems and risks of the organisation.

A generic policy copied from another business may not adequately address the organisation’s clients, information or regulatory responsibilities.

Start by Understanding Current Use

Before introducing new software or imposing a complete ban, employers should first understand how AI is already being used.

This can begin with five questions:

  1. Which AI tools are employees currently using?
  2. What tasks are they using them for?
  3. What company, client or employee information is being entered into these tools?
  4. Who reviews the work before it is relied upon or shared?
  5. Do the business’s existing policies and training address these risks?

AI can bring meaningful benefits to the workplace.

But responsible adoption requires more than access to technology. It requires leadership, oversight, appropriate human judgement and clear accountability.

Businesses that establish those safeguards now will be better positioned to benefit from AI without allowing convenience to create unnecessary legal and commercial risk.

AI Is Already in Your Workplace – Is Your Business Managing the Risk?

24 August 2026

Artificial intelligence is no longer something businesses are preparing to use in the future.

It is already being used in workplaces every day.

Employees are using AI tools to draft emails, summarise documents, prepare reports, conduct research, create presentations, analyse information and respond to clients. In many cases, this happens without formal approval, management oversight or clear rules governing how the technology may be used.

AI can undoubtedly improve efficiency. However, unmanaged use can expose a business to confidentiality breaches, inaccurate work, privacy concerns, unfair employment decisions and reputational damage.

The question is therefore no longer whether employees will use AI.

The more important question is whether the business understands how it is being used and has put appropriate safeguards in place.

South Africa’s Existing Laws Still Apply

South Africa does not currently have a dedicated AI law regulating the use of artificial intelligence in the workplace.

A Draft National Artificial Intelligence Policy was published in April 2026 but was formally withdrawn in June 2026 to allow it to be reworked.

This does not mean that workplace AI use is unregulated.

Existing legislation, contractual obligations and common-law duties continue to apply. Depending on how an AI tool is used, employers may need to consider the Protection of Personal Information Act, the Employment Equity Act, employment contracts, confidentiality obligations, intellectual property rights and general principles of fair labour practice.

An employer cannot avoid these responsibilities simply because a decision or work product was assisted by technology.

Protecting Personal and Confidential Information

One of the most immediate risks arises when employees enter information into an external AI platform.

This information may include:

  • Employee records
  • Client information
  • Financial information
  • Legal advice
  • Trade secrets
  • Internal reports
  • Unpublished business plans
  • Commercially sensitive documents

Employees may view an AI tool as a private digital assistant. However, information entered into an external platform is being shared with and processed through a third-party system.

Before using an AI tool, employers should understand what happens to the information entered into it. This includes where the information is stored, who may access it, whether it is used to improve the system and whether it may be transferred outside South Africa.

POPIA requires personal information to be processed lawfully and reasonably. It must also be adequate, relevant and not excessive in relation to the purpose for which it is processed. The responsible party remains accountable for ensuring compliance with the conditions for lawful processing.

Removing a person’s name may not always resolve the risk. A person could still be identifiable from information about their position, circumstances, location or relationship with the business.

A practical workplace rule is therefore:

If an employee would not be authorised to send the information to an unknown third party, they should not paste it into an unapproved AI tool.

AI-Assisted Recruitment and Employment Decisions

AI tools are increasingly capable of screening applications, comparing qualifications, ranking candidates and analysing employee performance.

These tools may help employers process large amounts of information efficiently. However, they may also produce unfair or discriminatory outcomes.

An automated system can appear neutral while reflecting bias contained in its training data, design or selection criteria. It may disadvantage candidates because of rigid keyword requirements, employment gaps, language patterns or historical data drawn from an unrepresentative workforce.

The Employment Equity Act requires employers to promote equal opportunity and eliminate unfair discrimination in employment policies and practices. Recruitment and selection form part of those employment practices.

POPIA also places limits on certain decisions that are based solely on automated processing where the decision has legal consequences or substantially affects a person. In applicable circumstances, safeguards must include an opportunity for the person to make representations and access to sufficient information about the underlying logic of the automated process.

AI may support a recruitment or employment decision, but meaningful human oversight should remain part of the process.

Employers should be able to explain what information was considered, how the recommendation was generated and why the final decision was made.

Who Is Responsible When AI Gets It Wrong?

AI-generated content can appear professional, compelling  and complete while still being inaccurate.

An incorrect output could lead to:

  • Inaccurate advice being given to a client
  • A flawed financial or legal document
  • False information being included in a report
  • An incorrect business decision
  • Reputational damage
  • A breach of contractual or professional obligations

Employees should understand that using AI does not transfer responsibility for their work to the technology provider.

AI should generally be treated as a tool that supports the work, rather than as the final decision-maker.

The level of human review should be proportionate to the risk. A routine internal draft may require one level of checking, while legal, financial, safety-critical or client-facing work may require far more careful verification.

Businesses should also determine when employees must disclose that AI was used and when approval is required before AI-generated content is shared externally.

Can an Employee Be Disciplined for Misusing AI?

An employee may potentially face disciplinary action for misusing AI.

Examples could include uploading confidential information, ignoring an instruction not to use AI for a particular task, fabricating information or submitting unchecked AI-generated work that causes harm.

However, not every incident  involving AI will automatically justify dismissal.

The employer should consider whether there was a clear rule or instruction, whether the employee knew or should have known about it, the seriousness of the conduct, the harm caused and whether the rule has been applied consistently.

This is why employers should establish clear rules and expectations before attempting to enforce them.

A business that has never addressed AI use may find it more difficult to prove that an employee understood the boundaries.

What Should an AI Workplace Policy Cover?

An effective AI policy does not necessarily need to prohibit the technology.

It should create clear boundaries for responsible use.

The policy should address:

  • Which AI tools are approved
  • What information may not be uploaded
  • When management approval is required
  • How AI-generated work must be reviewed
  • When AI use must be disclosed
  • How personal information must be protected
  • Who is accountable for the final work product
  • What employees should do when uncertain
  • The consequences of breaching the policy

The policy should be supported by practical training and should reflect the actual work, systems and risks of the organisation.

A generic policy copied from another business may not adequately address the organisation’s clients, information or regulatory responsibilities.

Start by Understanding Current Use

Before introducing new software or imposing a complete ban, employers should first understand how AI is already being used.

This can begin with five questions:

  1. Which AI tools are employees currently using?
  2. What tasks are they using them for?
  3. What company, client or employee information is being entered into these tools?
  4. Who reviews the work before it is relied upon or shared?
  5. Do the business’s existing policies and training address these risks?

AI can bring meaningful benefits to the workplace.

But responsible adoption requires more than access to technology. It requires leadership, oversight, appropriate human judgement and clear accountability.

Businesses that establish those safeguards now will be better positioned to benefit from AI without allowing convenience to create unnecessary legal and commercial risk.

Copyright ©
2026
Website developed & managed by
Cetaya Digital