Skip to main content

Growthcurve Group | Outsourced HR Management

Generative AI tools like ChatGPT and Copilot have entered almost every South African workplace, often faster than employers can write rules to govern them. AI does not, however, create a law-free zone. Existing employment, privacy, discrimination, confidentiality, and intellectual-property principles still apply. Employers are nevertheless encouraged to develop clear AI rules to remove uncertainty and manage new risks properly.

What Is the Legal Landscape for AI at Work?

South Africa does not yet have a standalone AI Act. A Draft National Artificial Intelligence Policy was published in April 2026 but withdrawn after fictitious sources were found in its references – a reminder of the risks of unverified AI-generated material. Government is continuing work on a revised national policy, but in the meantime, existing law already applies to AI use at work, including:

  • the Labour Relations Act (LRA)
  • the Protection of Personal Information Act (POPIA)
  • the Employment Equity Act (EEA)
  • the Copyright Act
  • common-law employee duties (honesty, confidentiality, care, competence)

Can an Employer Prohibit Employees from Using ChatGPT at Work?

Yes. An employer is generally entitled to regulate how work is done and which tools are used, provided that the rule or instruction is lawful and reasonable. A clear, reasonable instruction, whether banning AI tools outright or allowing only approved ones, is a lawful instruction, and ignoring it can amount to misconduct. The key requirement is that the rule must be communicated, so that employees are aware, or could reasonably be expected to be aware, of it before it is enforced.

What Are the Risks of Using AI to Draft Reports, Emails or Legal Documents?

AI is a powerful research, drafting, and productivity tool, but it carries risks, particularly around:

  • Accuracy: AI can generate incorrect information or “hallucinated” facts and references.
  • Confidentiality: Sensitive information may be exposed through AI platforms.
  • Honesty: The source and verification of AI-assisted work may not be disclosed.

An employee remains responsible for the work they submit and generally cannot avoid accountability simply because AI produced it. Submitting unchecked AI text, particularly with invented facts or references, can breach professional standards and the duty to work competently and in good faith.

What If an Employee Feeds Confidential or Personal Information into ChatGPT?

This is the highest-risk scenario. Entering confidential, client, or employee information into an AI tool can create significant confidentiality and data-protection risks, particularly where employees use public or personal AI accounts that have not been approved by the employer.

POPIA continues to apply, including its requirements concerning:

  • lawful processing
  • security safeguards
  • operators
  • cross-border transfers

Employers should identify which AI platforms may be used, what information may be entered into them, and what data-protection safeguards must be in place.

In the absence of a formal AI policy, employers should consider requiring employees to seek guidance or approval before using AI in connection with their work, particularly where confidential, personal, proprietary or otherwise sensitive information may be involved.

Can Using AI Constitute Misconduct?

It can, but not automatically. The issue is not the use of AI itself, but what the employee did with it, and whether that breached a workplace rule, lawful instruction, or existing duty. This could include, for example:

  • using a tool in breach of workplace rules
  • disclosing confidential or personal information
  • being dishonest about how work was produced
  • generating output that breaches professional obligations
  • failing to check AI-generated work where accuracy is required

Can an Employer Discipline an Employee for an AI Breach if There Is No AI Policy in Place?

An employer does not necessarily need an AI-specific policy before misconduct can arise. Employees are already bound by established duties such as honesty, confidentiality, care, and compliance with lawful instructions. However, a clear AI policy removes uncertainty and makes it much easier for employees to understand what is and is not permitted.

If AI-Generated Work Contains Errors, Is That Misconduct or Poor Performance?

It depends on the nature of the failure and the circumstances.

  • Misconduct: Carelessly failing to check AI output where the employee knew verification was required (negligence); or deliberately representing unchecked AI-generated work as verified, or concealing AI use where disclosure was required (dishonesty).
  • Poor performance: The employee genuinely lacked the knowledge, skill, or ability to produce work to the required standard, which should generally be managed through a supportive incapacity process.

The distinction matters: poor performance is remedial and supportive, while negligence and dishonesty are dealt with as misconduct.

What Happens When AI Detects That an Employee Is Underperforming?

AI monitoring tools can flag apparent underperformance, but a flag is a starting point, not a verdict. Underperformance must still be managed through a fair incapacity process: identifying the specific shortfall, telling the employee, giving them a genuine opportunity and support to improve, and only then considering dismissal if the standard still isn’t met. An algorithm’s output does not shortcut any of these steps.

Can AI-Generated Productivity Scores Be Relied on in Disciplinary Proceedings?

Only with real caution.

  • POPIA restricts decisions based solely on automated processing where they have legal consequences for a person or substantially affect them.
  • The EEA prohibits practices that unfairly discriminate in employment policies and practices – a real risk where an algorithm carries bias, even unintentionally.

A productivity score should therefore not automatically be treated as conclusive proof of misconduct or poor performance. Its accuracy, reliability and underlying methodology should be capable of being scrutinised, and the employee should have a meaningful opportunity to respond to the information on which the employer relies. Relying solely on an unexplained or untested productivity score could create significant fairness and evidentiary risks.

A dismissal resting on nothing more than a productivity number is vulnerable at the CCMA.

Who Owns AI-Generated Work Produced by an Employee?

As between employer and employee, copyright in work created in the course and scope of employment will generally vest in the employer, subject to the terms of the employment agreement and the Copyright Act. The position becomes more complex where AI is involved. South African copyright law recognises “computer-generated” works and provides that the author is the person who undertook the arrangements necessary for the creation of the work. However, how these provisions apply to modern generative AI, particularly where there is limited human input, is still developing and may depend on the circumstances in which the work was produced. Employers should ensure that their contracts and AI policies clearly address ownership of AI-assisted work, while also requiring appropriate human input, review, and accountability.

Can an Employer Rely on AI in Recruitment, Performance or Other HR Decisions?

AI can be a useful HR tool, but employers need to be alert to the risk of unintended discrimination. AI does not have human prejudice or intent, but discrimination can arise from the effect of the tool, even where nobody intended to discriminate. For example, a recruitment tool trained on historically successful, predominantly male, profiles could inadvertently rank male candidates more highly, disadvantaging women even though the employer never instructed the system to prefer men.

The EEA prohibits direct and indirect unfair discrimination in employment policies and practices, including recruitment, selection, performance evaluation, promotion and disciplinary measures. Employers remain responsible for checking whether AI-assisted HR decisions can be properly scrutinised, are fair, and do not produce unfairly discriminatory outcomes. AI should support human decision-making, and not replace it. The accountability principle works both ways: employees remain responsible for AI-generated work they submit, while employers remain responsible for employment decisions made with the assistance of AI.

What Should an Employer’s AI Acceptable Use Policy Say?

While a policy is not strictly required before misconduct can arise, a clear AI Acceptable Use Policy removes uncertainty and gives employees a clear understanding of what is and is not permitted. At minimum, address:

  1. Approved tools and permitted uses: Name which AI tools may be used, for which tasks, and which are off-limits.
  2. Confidentiality and data protection: Prohibit entering confidential, client, or personal information into public AI tools, aligned with POPIA obligations.
  3. Accuracy and human accountability: Require employees to verify AI output and remain personally responsible for what they submit.
  4. Disclosure: State when and how employees must disclose that AI was used in producing their work.
  5. Ownership and consequences: Clarify ownership of AI-assisted work, ensure contracts deal with IP rights, and confirm that breaches may result in disciplinary action.

Conclusion

South Africa does not yet have dedicated AI legislation, but the LRA, POPIA, the EEA, the Copyright Act and long-standing common-law duties already govern many aspects of how employees may use these tools. The real question is therefore seldom simply whether an employee used AI, but how it was used, what duty or rule was breached, and what risk or consequence resulted. Employers who put clear, practical AI rules in place will be far better positioned to manage these issues consistently and fairly as the technology continues to evolve.

Sources and Verification

This article was researched and verified against primary South African legislation, official Government Gazette publications, and relevant government sources.

Growthcurve Group provides practical support with AI and other workplace policies, as well as broader labour consulting and HR requirements. Contact our team for assistance.

This article is a general information sheet and should not be used or relied on as legal or other professional advice. No liability can be accepted for any errors or omissions nor for any loss or damage arising from reliance upon any information herein. Always contact your adviser for specific and detailed advice. Errors and omissions excepted (E&OE).

We use cookies to improve your experience on our website. By continuing to browse, you agree to our use of cookies
X