You're accountable for the AI tools you don't know about
Estimate your organisation's POPIA exposure from shadow AI usage you may not have visibility over.
1. Your organisation's headcount
50
51,000
2. Do you believe anyone in your organisation could be inputting sensitive client, employee, or business information into AI tools without IT oversight?
3. Which of these sounds familiar? (select any that apply)
4. How many people does your organisation's data ecosystem cover?
That's good to hear. But are you sure?
Most organisations that say this discover the opposite once they look closer. Studies show that up to 80% of employees use unapproved AI tools at work (often without telling IT).
A 30-minute conversation costs nothing. Not having one could cost millions.
Find out how to give every person in your organisation access to every major AI model, with full governance and all data staying on South African soil.
In practice, enforcement outcomes are often settled at a fraction of statutory exposure, in some cases around 50% or less. This figure represents an estimate and is not a guaranteed outcome.
What this means for your organisation
Shadow AI users in your organisation
—
—
Unmanaged data transfers per year
—
—
Estimated fine per infringement
—
—
Compliance risk
POPIA Precedent: R5M Fine
The Department of Justice was fined R5 million for failing to renew basic security software, a passive oversight with no malicious intent. Allowing staff to process personal information through consumer AI tools with no governance in place represents an active and ongoing failure of data accountability the Regulator has signalled it will treat with increasing severity.
Source: Information Regulator media statement, July 2023; Regulator's 2026/27 enforcement priorities.
Why an enterprise agreement isn't enough
An enterprise subscription to an AI platform is not the same as data residency. When staff submit data to a frontier model hosted on foreign infrastructure, even under a paid enterprise plan, that constitutes a cross-border transfer of personal information. Under POPIA Section 72, transborder transfers require binding corporate rules, consent, or contractual necessity. Standard enterprise AI terms satisfy none of these. The data is still leaving South African borders. The accountability sits with your organisation.
—
IT governance and regulatory risk
POPIA Section 19 and accountability obligations
POPIA does not prohibit AI usage. The issue is governance. Under POPIA Section 19, your organisation must implement appropriate, reasonable technical and organisational measures to prevent loss of, damage to, or unauthorised access to personal information. When staff use consumer AI tools (ChatGPT, Claude, Gemini) outside any sanctioned framework, that data is processed on foreign infrastructure under terms that may permit model training. IT has no visibility. The organisation has no control. The Information Regulator does not require a breach to investigate; the absence of controls is independently actionable. AI is not the problem. Using AI without proper data governance is.
This can also mean: Personal liability for the responsible party named under POPIA. Regulatory investigation triggered by a complaint, audit, or third-party disclosure. Civil liability under Section 99, which is uncapped and pursued through the courts. Reputational damage that is significantly harder to contain once a regulator is involved.
Find out how to give every person in your organisation access to every major AI model, with full governance and all data staying on South African soil.