POPIA safe AI: what businesses should know
POPIA safe AI is an important part of keeping business technology practical, secure and reliable. This article explains the issue in plain language, with related context on Shadow IT and POPIA and useful external guidance on shared responsibility.
AI tools have slipped into everyday work faster than most businesses expected. They are helpful, fast and available at any hour, which is probably why people trust them a little too much. And that trust is exactly where things go wrong. Employees copy sensitive information into AI chat windows because it feels harmless. The tool looks private. It replies politely. It never judges spelling. For many people, it feels safer than emailing a colleague for help. Unfortunately, POPIA disagrees. Public AI tools operate as third-party services, which means any personal information entered into them leaves the organisation’s controlled environment. Under POPIA, that shift in control immediately becomes a compliance concern. The POPIA Perspective POPIA expects organisations to handle personal information carefully from the moment it comes in to the moment it’s removed from the system. Once that same information is pushed through a public AI tool, control over where it goes and how it’s handled becomes uncertain. Even if the AI provider states that prompts aren’t stored or used for training, the act of sending personal information to an outside platform is still the same as handing it over. POPIA keeps the responsibility firmly with the organisation that shared it in the first place. Why Oversharing Happens Oversharing happens because these tools feel harmless. They sort out wording, clean up messy paragraphs, summarise notes and generally make life easier. That convenience makes it surprisingly easy to forget how much detail sits inside the text being copied across. And when those details relate to medical notes, legal matters, HR issues, financial details or private communication, the stakes get a lot higher. Sectors With Higher Confidentiality Obligations Certain industries work with information that simply shouldn’t slip outside their environment, no matter the intention. Some examples:- healthcare and medical practices
- legal firms and advisory roles
- financial and insurance services
- HR and recruitment environments
- schools and child-related institutions
- security and investigative work
- assuming an AI chat window behaves like a private conversation
- thinking that removing a name makes the whole thing anonymous
- taking marketing promises at face value instead of checking policies
- forgetting that the AI tool is still an external processor
- believing that a small extract can’t reveal anything important
- Remove personal identifiers
- Describe situations without the original wording
- Use business-grade AI tools
- Keep sensitive documents out of public AI tools
- Put an AI usage policy in place
- Help staff understand what counts as sensitive
- Keep certain tasks offline
- Warn me immediately NOT to include personally identifiable information (PII) such as names, ID numbers, phone numbers, email addresses, account numbers, case numbers, medical details, financial details or anything that could identify a real person.
- If a request appears work-related, remind me upfront not to share client, patient, staff or customer information.
- If a prompt seems like it could involve a real individual, stop and warn me: “Do not include personally identifiable information. Please rephrase this request without real-world data.”
- Never request PII.
- If any text resembles PII, treat it as unsafe, block processing and ask for a safer version.
- Do not store or reuse PII, even if it appears accidentally.
- Before completing any task, check whether the request could drift toward sensitive information and warn me if needed.



0 Comments