SAFE AI GUIDE

Why South African SMEs Need an AI Usage Policy Before Another AI Subscription

A practical, plain-language framework for deciding which AI tools staff may use, which data stays out, who approves use cases, and where human review is required.

By Suvan SinghPublished 12 July 2026About 6–8 minutes

The policy should answer decisions staff face every day

Most AI risk does not begin with an advanced autonomous system. It begins when someone pastes a proposal, customer record, contract, spreadsheet, meeting transcript, or employee document into a convenient tool without knowing the data terms or the business rule.

A useful policy therefore reads less like a technology manifesto and more like an operational playbook. It should help a team member decide what is allowed, what requires approval, and what must stop immediately.

  • Which AI products and account types are approved for work.
  • Which information classes may be used in each approved tool.
  • Which tasks are prohibited or require written approval.
  • When a person must verify facts, calculations, legal wording, or customer-facing output.
  • How staff report a suspected data exposure, inaccurate output, or unsafe automation.

Separate tools, data, and use cases

A common policy mistake is to approve a brand name without approving a specific product, plan, configuration, and purpose. Consumer and business versions of the same product can have different administrative controls and data commitments. The decision record should identify the exact service and the settings the business relies on.

The policy should also separate low-risk drafting from sensitive or consequential work. Rewriting public marketing copy is not the same as analysing employee records, producing advice for a client, or automating a decision that affects a person.

Make accountability visible

Name an owner for AI governance even if the role is part-time. That person should maintain the approved-tool register, coordinate reviews, record incidents, and escalate legal or security questions to qualified specialists.

The NIST AI Risk Management Framework describes governance as a continuous function that supports mapping, measuring, and managing risk. For an SME, that can be translated into a lightweight monthly review rather than a large committee.

A practical first version

Start with a two-to-four-page policy, an approved-tool register, a one-page data classification guide, and a short staff briefing. Test the policy against ten real tasks from the business. If a capable employee cannot apply it without guessing, revise it.

Review the policy whenever a material tool, provider term, business process, or use case changes, and schedule a formal review at least annually. The goal is not to freeze AI use. It is to make responsible experimentation repeatable.

Primary sources and further reading

Turn the guidance into an operating system

Start with the free five-minute AI Risk Check, or discuss a fixed-scope AI Safety Diagnostic.