Bowmans, one of South Africa's largest law firms, has warned that employers using AI tools such as ChatGPT, Gemini, Claude and Grok at work face real legal risk under the Protection of Personal Information Act and the Employment Equity Act. South Africa has no dedicated AI law, so existing legislation applies.
Partners Melissa Cogger and Talita Laubscher set out the risks in a six-part series on AI in the workplace.
Insights on AI at work and POPIA
There are two separate risks. The first is automated decisions about people. Section 71 of POPIA says a person may not be subject to a decision with legal consequences, or one that affects them substantially, based solely on automated processing that profiles them, and it names performance at work specifically. Bowmans says that applies when an AI system generates a performance rating, flags someone for promotion or demotion, or recommends rejecting a candidate.
It is not an outright ban. The section has exceptions, but they come with safeguards: the affected person must be able to make representations, get enough information about how the system reached its result, and deal with a human decision-maker. That is harder than it sounds, because many third-party tools do not explain how they reach their outputs. The Employment Equity Act adds a discrimination risk if an AI tool screens people out on grounds linked to protected characteristics.
The second risk is everyday use. When an employee pastes a colleague's, customer's or supplier's personal information into a public chatbot, the employer is accountable, because under POPIA the employer decides the purpose and means of processing and must protect that information. Bowmans recommends an acceptable AI use policy, clear limits on what categories of personal information may be uploaded, and staff training.
What others are saying about AI at work and POPIA
MyBroadband reported Bowmans' warning on automated recruitment and employee uploads. EBnet carries the Bowmans series in full, including the point that POPIA's lawful processing principles still apply even where Section 71 is not triggered.
LabourNet notes that King V, effective for financial years starting 1 January 2026, makes data, IT and AI governance a standalone board principle for the first time, and that where no information officer has been designated, POPIA makes the head of the organisation the information officer by default.
The bigger risk is the one nobody is managing
Most businesses reading this do not use AI to screen candidates, so Section 71 will feel like somebody else's problem. It is the second risk that applies almost everywhere.
Staff are already pasting client emails, CVs and account details into free chatbots to save time, and the liability sits with the business, not the employee who did it. We made the same Section 71 point when Europe fined Uber over automated driver deactivations, and Standard Bank has written its own responsible AI framework precisely because the rules are thin.
For a small business, the fix is not expensive. Write a one-page policy saying which tools are approved and what information must never go into a public one, pay for business versions that carry data protection terms, and make sure a person signs off on any decision about hiring or performance. If nobody at your company has been named information officer, that person is you.
You might also like our piece on the FSCA holding back on AI rules, the Lego South Africa data breach and who stays liable under POPIA, and why SA enterprise AI adoption keeps outrunning its own strategy.
Get more SA tech and business news and subscribe to The Open Letter.


