the bull

AI without oversight

South African businesses are creating legal risks every time an employee uses AI without oversight

An employee asks ChatGPT to summarise a confidential contract. Another uploads internal company information into Microsoft Copilot to prepare a board report. A third uses artificial intelligence to draft client correspondence.

These are no longer hypothetical scenarios. They are happening in businesses across South Africa every day — usually unnoticed, and almost always unmanaged.

Yet while artificial intelligence has become an accepted workplace tool, governance around its use has failed to keep pace, leaving many organisations vulnerable to legal, regulatory and commercial risk.

According to Justin Klingbiel, Director at Macgregor Erasmus Attorneys Inc., many business leaders mistakenly believe that AI is simply another productivity tool.

“AI has moved into the workplace far faster than governance has. Most organisations already have employees using AI, but very few have policies governing what information may be entered into these systems, who is accountable for AI-assisted decisions or how the associated legal risks should be managed.”

While South Africa has yet to introduce comprehensive AI-specific legislation, existing laws already apply. Businesses remain accountable under legislation governing data protection, cyber security, corporate governance, intellectual property, contractual obligations and director duties. South African courts have also begun encountering matters involving AI-generated legal authorities, highlighting the risks of relying on AI outputs without appropriate human verification. In a recent matter, a judge encountered legal submissions containing AI-generated case authorities that did not exist — a clear example of how reliance on unverified AI outputs can create professional, ethical and legal complications.

 “The biggest misconception is that AI risk only applies to technology companies. In reality, any organisation whose employees use AI to analyse information, draft documents, communicate with clients or assist with decision-making is already operating within an existing legal framework.”

Klingbiel says organisations should be asking practical questions now, rather than waiting for AI legislation. Businesses need to understand whether employees are uploading confidential information into AI platforms, who owns AI-generated content, how AI-generated advice is verified before it reaches clients, and who ultimately remains accountable for decisions influenced by AI.

Managing AI risk, he says, cannot simply be delegated to the IT department. It requires coordinated oversight across management, legal, information security, human resources and the board. The focus should not only be on which AI tools are being used, but also on what information they receive, what decisions they influence and who remains accountable for the outcome.

He adds that AI governance should also form part of an organisation’s broader cyber security strategy. AI-related risks should be incorporated into cyber incident response, disaster recovery and business continuity planning to ensure organisations can respond effectively and recover quickly should an incident occur.

 “The question facing businesses is no longer whether they are using AI. It is whether they are using it responsibly.”