Your team is already using AI at work. Someone is pasting a customer email into a chatbot, drafting a quote, or summarising a contract — usually without approval. This unsanctioned use, known as Shadow AI, can expose personal information and breach POPIA long before anyone notices. This article explains the risks in plain terms, gives you a practical governance plan you can start this week, and shows how AI security and governance in South Africa lets your business adopt AI with confidence.
What is Shadow AI, and why is it already in your business?
Shadow AI is any artificial intelligence tool your staff use for work without approval or oversight. It is the free chatbot a salesperson uses to sharpen an email, the app that transcribes a client meeting, or the browser plugin that summarises a long report. None of it is malicious. People reach for these tools because they save time and help them get the job done under pressure.
The problem is that this activity is invisible to the people responsible for data and security. Your team may be sending client names, ID numbers, pricing and signed contracts to services you have never assessed. Every one of those tools is a doorway your data can walk through unseen. You cannot protect what you cannot see, and most South African businesses have no record of which AI tools are in use, what information those tools receive, or where that information finally ends up.
Where does AI use collide with POPIA and GDPR?
The Protection of Personal Information Act (POPIA) governs how you collect, use and share personal information. When an employee pastes a customer’s details into an AI tool, several duties can be broken at once. You may be processing personal information without a lawful basis, sending it across borders to servers outside South Africa, and losing any control over how long it is retained. Consent given for one purpose does not automatically cover feeding that same information into an external AI tool.
Many AI services also use the data you submit to improve their models. That means information about your clients could be absorbed into a system you do not own and cannot get back. For businesses that also serve customers in Europe or the United Kingdom, the same actions can breach GDPR. POPIA is not a paper exercise. For the most serious offences it allows administrative fines of up to R10 million and, in some cases, imprisonment of up to 10 years — alongside the reputational damage that follows a public breach.
What are the hidden risks of ungoverned AI at work?
Beyond compliance, ungoverned AI creates practical dangers that tend to surface at the worst possible moment. These are the ones we see most often:
- Data leakage: confidential information typed into a public tool can be stored, reused or exposed in a breach you never hear about.
- Inaccurate output: AI can produce confident, wrong answers. Acting on them in quotes, advice or reports carries real liability.
- Account and access risk: staff sign up with work emails and weak passwords, widening the ways an attacker can reach your systems.
- Third-party exposure: AI features added to the SaaS you already use can quietly change how your data is handled and stored.
- No audit trail: when something goes wrong, you have no record of who used what, which makes incident response and POPIA reporting far harder.
Banning AI outright rarely works. Staff move it further into the shadows, and you lose even the little visibility you had. The better path is to bring AI into the open and govern it properly.
Practical AI governance: a plan you can start this week
Good governance does not mean a thick policy that nobody reads. It means clear rules, sensible controls and a way to see what is actually happening. Begin with these steps:
- Discover what is in use: ask each team which AI tools they rely on, and check network and account logs. You need an honest inventory before anything else.
- Set an acceptable-use policy: state which tools are approved, what information must never be entered, and who to ask when someone is unsure.
- Choose safer tiers: paid business plans that exclude your data from model training and keep it in known regions are far safer than free consumer versions.
- Control access: use single sign-on, strong authentication and role-based permissions so AI accounts are managed by the business, not tied to individuals.
- Classify your data: decide what counts as personal or confidential so staff know exactly what is off-limits.
- Train your people: a short, practical session achieves more than any long document. People follow rules they understand and believe in.
Governance is ongoing, not a one-off. Review your tool list and policy regularly, because the AI features built into your everyday software change often and without warning.
How LDD secures and governs the AI you already use
LDD helps South African businesses adopt AI without losing control of their data. We do not build AI for you. Instead, we make the AI and SaaS tools you already rely on safe to use. Our AI security and governance service begins by finding the Shadow AI in your business, then puts practical controls and a workable policy around it, aligned to both POPIA and GDPR.
Because AI risk is part of your wider security picture, we connect it to the rest of your defences:
- Test the systems: our security testing checks the AI-enabled applications and integrations in your environment for real-world weaknesses.
- Build the framework: where you need formal structure, we design an ISO 27001 management system that includes your AI use and prepares you for certification.
- Govern for the long term: we set clear ownership, monitoring and review so your AI security and governance keeps pace as tools and threats change.
The outcome is confident, compliant AI adoption: the benefits of these tools, without the exposure that keeps business owners awake at night.
Adopt AI with confidence, not fear
AI is now part of how work gets done, and pretending otherwise only pushes it out of sight. The businesses that stay ahead are the ones that face it early. They know which tools are in use, they protect the personal information in their care, and they can prove it if a regulator or a client asks. Your customers increasingly expect this, and so does the Information Regulator. Governance turns AI from a hidden liability into a managed advantage.
You do not need to solve everything at once. Start with an honest inventory, agree a few firm rules, and build from there. With the right support, safe and compliant AI use is well within reach for any South African business.
Frequently asked questions
What is Shadow AI?
Shadow AI is the use of AI tools by employees for work without the approval or oversight of management or IT. It includes free chatbots, transcription apps and browser plugins used to handle company information. Because it is invisible to the business, it creates hidden security and POPIA compliance risks.
Is using AI tools at work a POPIA risk?
It can be. If staff enter customers’ personal information into AI tools without a lawful basis, or send it to servers outside South Africa, the business may breach POPIA. Many AI services also reuse submitted data to train their models, which removes your control over that information.
What are the POPIA penalties for mishandling personal information?
For the most serious offences, POPIA allows administrative fines of up to R10 million and, in some cases, imprisonment of up to 10 years. Beyond the penalties, breaches damage customer trust and can trigger mandatory notification of the Information Regulator and affected people.
Should we ban AI at work?
Outright bans rarely work, because staff keep using AI privately and push it further into the shadows. A better approach is to approve safe tools, set clear rules on what data may be used, and govern AI openly. This gives you the benefits while controlling the risks.
Does LDD build AI systems?
No. LDD focuses on AI security and governance in South Africa, which means securing and governing the AI and SaaS tools you already use, aligned to POPIA and GDPR. We help you discover Shadow AI, put controls and policies in place, and test the systems involved so you can adopt AI safely.
Speak to LDD today to bring your team's AI use into the open and govern it safely under POPIA and GDPR.
