YOUR BUSINESS IS USING AI. HAVE YOU ASKED WHO'S LIABLE WHEN IT GETS SOMETHING WRONG?
- Gittins Attorneys
- Jul 28
- 3 min read

Picture this: your HR team uses AI to shortlist candidates, your accounts team leans on it to review financial information, and the person at the next desk uses it to draft a contract clause or pull together research for a report, without noticing the mistake buried inside or a client chats to your AI-powered support bot, gets the wrong advice and acts on it.
Who carries the blame?
It's a question more South African professionals and businesses are being forced to ask in 2026, AI has become a genuine time-saver for drafting and research as much as it has a decision-making tool, and right now, the honest answer on liability is: it's complicated, and mostly still lands on you.
There's no “AI law” in South Africa yet
South Africa doesn't currently have legislation written specifically for artificial intelligence. The Draft National AI Policy, published for public comment in April 2026 — signals where government wants to go, but it's policy, not law, and there's no timeline yet for binding legislation.
In the meantime, existing law has to do the work. The most relevant hook is section 71 of the Protection of Personal Information Act 4 of 2013 (POPIA), which restricts decisions based solely on automated processing where those decisions have legal or similarly significant effects on a person — think credit scoring, hiring, or insurance underwriting.
If your business lets an algorithm make that call without meaningful human oversight, and it produces a discriminatory or unfair outcome, you can be on the hook for a POPIA complaint. Directors who haven't put governance controls in place around AI use may also be exposing themselves personally, given their fiduciary duty to manage risk on behalf of the company.
Insurers are already moving, are you?
This is where it gets interesting for business owners. The insurance market isn't waiting for legislators. Internationally and locally, insurers are:
Adding exclusions to standard commercial liability and professional indemnity policies for losses “arising out of” generative AI use;
Building new AI-specific products covering things like AI governance failures, algorithmic decision-making claims, and business interruption caused by a model simply getting it wrong; and
Asking harder questions at renewal about what AI tools you use, how they're supervised, and what controls you have in place.
The uncomfortable truth: many businesses assume their existing professional indemnity or cyber cover will simply extend to cover an AI mistake. Increasingly, it won't — not without an explicit endorsement.
What this means for you, practically
Map where AI touches your business. HR, finance, marketing, customer service — know where a machine, not a person, is making or influencing decisions.
Don't let AI be the sole decision-maker on anything with legal or financial consequences for a client, employee, or third party. Keep a human meaningfully in the loop.
Check your policy wording — don't assume. Ask your broker directly whether your professional indemnity, cyber, or general liability cover responds to an AI-caused loss, or whether it's excluded.
Put a basic AI governance policy in writing. Even a short internal policy on approved tools, review steps, and accountability materially strengthens your position if something goes wrong — with regulators, with insurers, and with clients.
AI isn't going away, and neither is the liability question. The businesses that get ahead of it now — rather than finding out the hard way at claims stage — will be in a far stronger position than those that don't.
If your business has adopted AI tools in the last year or two and hasn't reviewed either your governance position or your insurance cover since, it's worth a conversation before it's forced by an incident or a renewal date.
Get in touch with our team if you'd like us to review your AI exposure, your policy wording, or your vendor contracts.



Comments