AI Systems and POPIA: Moving from Intentions to Operational Controls

Why responsible AI statements are not enough, and how a structured PIIA turns intention into workable controls

Many organisations express a commitment to responsible artificial intelligence. Policies speak of fairness, transparency and respect for privacy. These statements are important, but they do not by themselves satisfy the requirements of the Protection of Personal Information Act (POPIA), nor do they provide sufficient evidence of control when AI systems process personal information.

POPIA applies whenever personal information is processed, including by AI systems. Responsible parties must ensure that processing is lawful, that data is minimised to what is necessary, that information remains accurate, and that appropriate technical and organisational measures are in place to protect it. Information Officers are also required to ensure that a Personal Information Impact Assessment (PIIA) is conducted so that adequate measures exist to comply with the conditions for lawful processing.

AI systems introduce particular challenges. They often rely on large datasets, involve complex processing operations, and can produce outcomes that significantly affect individuals. Training data may contain biases. Models may generate decisions that are difficult to explain. Data flows can extend across multiple systems and, in some cases, across borders. These characteristics increase the potential impact on data subjects and raise the importance of careful assessment.

A high-level commitment to responsible AI does not automatically address these issues. What matters is whether the organisation has examined the specific processing activity, identified the personal information involved, assessed the risks to data subjects, and determined whether existing controls are adequate. This is the practical work that a structured PIIA is intended to support.

When conducted properly, the assessment moves the organisation from intention to operational detail. It requires clarity on the purpose of the processing, the legal basis relied upon, the necessity of the data being used, and the safeguards applied throughout the data lifecycle. It also provides a basis for deciding whether residual risks are acceptable or whether further controls are required before the system proceeds.

This level of discipline is particularly relevant as South African organisations adopt AI tools and as boards face clearer expectations under King V regarding the governance of data, information and technology. Governing bodies are expected to oversee the use of emerging technologies and to ensure that accountability is maintained. Evidence that privacy risks associated with AI systems have been examined and addressed forms part of that oversight.

The distinction is practical. An organisation may state that it takes privacy seriously, or it may be able to show how a specific AI system was assessed, what risks were identified, and what measures were put in place in response. The second approach creates a clearer record of decision-making and a stronger foundation for ongoing management as systems evolve.

AI does not change the core obligations under POPIA. It does, however, increase the complexity of meeting them. Organisations that rely only on policy statements risk underestimating that complexity. Those that treat privacy assessment as real analytical work are better placed to identify issues early, to justify their processing activities, and to demonstrate that personal information is being handled with appropriate care.

Responsible AI begins with clear intentions. It is sustained by operational controls that can be examined, challenged and improved. A structured approach to Personal Information Impact Assessment helps close the gap between the two.