SAFE AI GUIDE

A Simple AI Data Classification Model for South African SMEs

A practical four-tier model that helps staff decide what information may be used with approved AI tools and what requires specialist review.

By Suvan SinghPublished 12 July 2026About 6–8 minutes

Tier 1 — Public

Information already intentionally published, such as website copy, public brochures, public job adverts, or public product information. Even here, staff should still verify copyright, accuracy, and whether the task creates a misleading representation.

Tier 2 — Internal

Routine information intended for employees but not the public, such as process notes, internal templates, and non-sensitive operational guidance. Use only approved business tools and remove unnecessary names, identifiers, and confidential details.

Tier 3 — Confidential

Commercial plans, contracts, pricing, unpublished financial information, customer information, employee information, credentials, or proprietary records. AI use should require an approved business environment, a documented purpose, appropriate provider terms, access control, and a named reviewer.

Tier 4 — Restricted

Special personal information, identity documents, authentication secrets, highly sensitive client material, regulated records, security data, or information where incorrect processing could seriously affect a person or business. Default to no external AI processing until legal, privacy, and security specialists approve the exact use case and environment.

Make the classification usable

Place examples from the actual business under each tier. Connect the model to the approved-tool register and prompt staff to classify information before use. Review classifications when the purpose changes: combining several harmless fields can create a sensitive record.

Classification is not a legal conclusion and does not replace POPIA analysis. It is a practical control that helps employees recognise when more review is required.

Primary sources and further reading

Turn the guidance into an operating system

Start with the free five-minute AI Risk Check, or discuss a fixed-scope AI Safety Diagnostic.