That's good to hear. But are you sure?
Most organisations that say this discover the opposite once they look closer. Studies show that up to 80% of employees use unapproved AI tools at work (often without telling IT).
A 30-minute conversation costs nothing. Not having one could cost millions.
Source: UpGuard, 2024 Shadow IT and AI Survey.
Your estimated POPIA exposure
—
—
—
In practice, enforcement outcomes are often settled at a fraction of statutory exposure, in some cases around 50% or less. This figure represents an estimate and is not a guaranteed outcome.
What this means for your organisation
Shadow AI users in your organisation
—
Unmanaged data transfers per year
—
Estimated fine per infringement
—
Compliance risk
POPIA Precedent: R5M Fine
The Department of Justice was fined R5 million for failing to renew basic security software, a passive oversight with no malicious intent. Allowing staff to process personal information through consumer AI tools with no governance in place represents an active and ongoing failure of data accountability the Regulator has signalled it will treat with increasing severity.
Source: Information Regulator media statement, July 2023; Regulator's 2026/27 enforcement priorities.
Why an enterprise agreement isn't enough
An enterprise subscription to an AI platform is not the same as data residency. When staff submit data to a frontier model hosted on foreign infrastructure, even under a paid enterprise plan, that constitutes a cross-border transfer of personal information. Under POPIA Section 72, transborder transfers require binding corporate rules, consent, or contractual necessity. Standard enterprise AI terms satisfy none of these. The data is still leaving South African borders. The accountability sits with your organisation.
—
IT governance and regulatory risk
POPIA Section 19 and accountability obligations
POPIA does not prohibit AI usage. The issue is governance. Under POPIA Section 19, your organisation must implement appropriate, reasonable technical and organisational measures to prevent loss of, damage to, or unauthorised access to personal information. When staff use consumer AI tools (ChatGPT, Claude, Gemini) outside any sanctioned framework, that data is processed on foreign infrastructure under terms that may permit model training. IT has no visibility. The organisation has no control. The Information Regulator does not require a breach to investigate; the absence of controls is independently actionable. AI is not the problem. Using AI without proper data governance is.
This can also mean: Personal liability for the responsible party named under POPIA. Regulatory investigation triggered by a complaint, audit, or third-party disclosure. Civil liability under Section 99, which is uncapped and pursued through the courts. Reputational damage that is significantly harder to contain once a regulator is involved.
This calculator provides illustrative estimates only and does not constitute legal, financial, compliance, or any other form of professional advice. The figures shown represent potential exposure under POPIA's enforcement framework. They are not predictions of actual fines, settlements, or penalties. Actual enforcement outcomes depend on the Regulator's discretion, the specific circumstances of each case, the degree of cooperation, and potential settlement negotiations. Consult qualified legal counsel for advice specific to your organisation. © Cuumulo Nymbis.