THE POLICY GAP BUSINESSES CAN NO LONGER IGNORE
Artificial intelligence is already changing the workplace.
Recruitment platforms can screen applications. Software can analyse employee performance. Generative AI can draft correspondence, summarise information and produce reports within seconds.
The technology is moving quickly.
Workplace policies often are not.
That gap creates a growing governance challenge for South African employers.
The issue is bigger than AI
The real question for employers is not simply:
“Are employees allowed to use AI?”
It is:
“How is AI being used, what information is being processed, and who remains accountable for the resulting decision?”
This becomes particularly important when AI is used in recruitment, performance management, employee monitoring or disciplinary processes.
POPIA and automated decision making
Section 71 of POPIA provides important protections where decisions are based solely on automated processing of personal information and the decision has legal consequences or substantially affects the individual.
This can be particularly relevant where profiling relates to matters such as performance at work, reliability, conduct or other personal characteristics.
However, section 71 should not be reduced to the statement that “AI decisions are prohibited”.
The legislation contains exceptions and requires appropriate safeguards in certain circumstances, including an opportunity for the data subject to make representations and access to sufficient information about the underlying logic of the automated processing.
That distinction matters.
A system that assists a manager in making a decision is not necessarily the same as a system that makes the decision entirely by itself.
The employment law risk
Employers should also consider the Labour Relations Act and Employment Equity Act when introducing AI into people management.
For example, relying blindly on an automated performance score without considering the circumstances surrounding an employee's performance could create fairness concerns.
Similarly, an algorithm used for recruitment or promotion could produce discriminatory outcomes even where the employer did not intend to discriminate.
The fact that a decision was generated by technology does not remove the employer's responsibility for the decision.
What should an AI workplace policy cover?
A practical workplace AI policy should consider:
Approved AI tools
Which platforms may employees use for work?
Confidential information
What information may never be entered into an external AI platform?
Personal information
How will employee, customer and supplier information be protected?
Human oversight
Which decisions must always remain subject to meaningful human review?
Transparency
When should employees or candidates be informed that AI is being used?
Accountability
Who is responsible for reviewing AI generated outputs before they are acted upon?
Monitoring and review
How will the organisation identify errors, bias, inappropriate outputs or changes in how the technology is being used?
AI governance is now workplace governance
AI should not sit exclusively with the IT department.
HR, legal, compliance, information officers and senior management all have a role to play where AI affects employees or processes personal information.
The objective is not to prevent businesses from using AI.
It is to ensure that innovation does not move faster than governance.
The most important AI policy question for employers is not what the technology can do. It is whether the business has decided what the technology should be allowed to do.





