AI is already part of how businesses work.
Your team might be using ChatGPT to draft content, AI tools to analyse documents, meeting assistants to capture conversations, or software with AI built into it. And while these tools can make a real difference to how your business operates, there is often one problem:
Nobody has actually decided how AI should be used.
That is the AI gap: the space between what your team is already doing with AI and what your business has actually decided is okay.
For businesses that are already using AI, an AI policy is a good place to start. But a policy written from a generic template doesn’t tell you what tools your people are actually using, what those tools do with your data, or what your business is comfortable with.
That’s where AI governance comes in.
What is AI governance?
AI governance is the process of understanding, managing and guiding how AI is used across a business.
It brings together legal, strategic and operational considerations so that businesses can make deliberate decisions about AI rather than leaving those decisions to individual employees.
That means asking practical questions.
What AI tools are we using? What are people using them for? What information are they putting into them? Which tools are appropriate for client work? What happens to the data? Who owns AI-assisted work? Where do we want to encourage experimentation, and where do we need tighter controls?
The answers will be different for every business. That’s why effective AI governance needs to be built around the business itself, rather than copied from a generic policy template.
Is AI regulated in South Africa?
South Africa does not currently have a dedicated AI Act. That doesn’t mean businesses can treat AI as unregulated.
Existing laws can apply depending on how AI is being used, including POPIA, the Copyright Act, the Employment Equity Act, the Labour Relations Act and the Consumer Protection Act.
There is also a broader national focus on responsible AI, including issues such as privacy, transparency, fairness, accountability and human oversight.
The regulatory landscape is still developing, but businesses don’t need to wait for a single piece of AI legislation before putting sensible governance in place.
In fact, the uncertainty makes understanding your current AI use even more important.
What are the risks of employees using AI?
The biggest risk may not be the AI itself. It may be unmanaged use of AI by your team.
An employee might upload confidential information into an AI tool without realising how that information is handled. Someone might use AI to create client-facing content without checking the output. Another employee might use an AI tool to assist with recruitment or performance decisions without considering the implications.
There can also be questions around data privacy, intellectual property, copyright, confidentiality and client expectations.
And you can’t manage those risks if you don’t know what’s happening.
That’s why AI governance should start with a clear picture of how your team is actually using AI.
What should an AI governance process look like?
At Legalese, our AI Governance Engagement follows five stages.
First, we map it. We survey the team to understand which tools are being used, how often, what they’re being used for and where people see opportunities or concerns. This gives management an honest picture of what’s happening before any decisions are made.
Then, we decide it. In a management workshop, we work through the big questions around AI culture, budgets, data privacy, IP, priorities, experimentation, training and client communication. The aim isn’t to lecture. It’s to help leadership make clear decisions about how they want AI to work in their business.
Next, we check it. Every AI tool identified is assessed against those decisions. We review the vendor’s own terms and documentation to understand issues such as data use, storage, ownership and the differences between free and paid versions. Where something can’t be confirmed, we flag it rather than making assumptions.
Then, we document it. Those decisions become a plain-language, bespoke AI policy covering everything from approved tools and data restrictions to IP, client communication, accountability and experimentation.
Finally, we roll it out. The policy is taken to the team, questions are addressed and any training gaps are identified.
The result isn’t just a document sitting in a shared drive. It’s a working framework for how your business uses AI.
Why a generic AI policy isn’t enough
A template might tell employees not to upload confidential information.
It won’t tell you which of your actual AI tools process that information, what their current terms say, whether your team is already using them, or whether management has decided that the tool is appropriate for client work.
That’s the difference between having an AI policy and having AI governance.
Your policy should reflect your business, your people, your tools, your clients and the decisions you’ve actually made.
And because AI tools and their terms change, the policy shouldn’t be treated as a once-off exercise either. A sensible governance framework includes regular review and updates.
The goal isn’t to stop your team using AI
AI governance isn’t about banning ChatGPT or telling your team to stop experimenting.
It’s about creating enough structure for your people to use AI confidently and productively, without leaving the business exposed to risks it hasn’t considered.
AI isn’t inherently unlawful. The issue is how it’s deployed.
The businesses that get this right won’t necessarily be the ones using the least AI. They’ll be the ones that understand where AI fits, where the boundaries are and who is responsible for keeping those boundaries up to date.
Ready to close the AI gap?
Legalese’s AI Governance Engagement helps businesses understand how AI is actually being used, make deliberate decisions about its use, assess the tools involved and turn those decisions into a practical, bespoke AI policy.
Because it’s not just about having an AI policy. It’s about knowing why you have it.

