The Problem Services Why Us How It Works Get in Touch →
Pietermaritzburg, South Africa

Your business uses AI.
Is it compliant?

Practical AI governance and compliance — built for South African small businesses, grounded in POPIA and the Cybercrimes Act, and delivered by people who understand both law and technology.

Why this matters now
60%+
of SA workers already use AI tools regularly — most without any formal guidance
R10M
maximum POPIA fine for data compliance violations involving AI tools
64%
of SA enterprises using AI without a formal ethics or compliance framework
Scroll

Most small businesses don't know the risk they're carrying.

Your employees are already using ChatGPT, Google Gemini, and WhatsApp automation — often without any guidance on what they can and cannot share. Without a policy, every use of a free AI tool is a potential POPIA exposure waiting to happen.

Free tools are not private

Free versions of ChatGPT, Gemini, and Copilot may store user inputs and use them to train AI models. Anything your employees type — including client names, financial records, or contract details — could be retained by an overseas platform. Under POPIA, this is a transborder data transfer with serious legal implications.

No policy means no protection

Without a documented AI usage policy and signed employee acknowledgements, your business has no legal defence if a data breach occurs. POPIA requires you to notify the Information Regulator within 72 hours of a breach — but without a system, you may not even know one has happened.

Regulation is accelerating

South Africa's National AI Policy Framework has completed public consultation and is approaching Cabinet approval. A dedicated AI Act is expected to follow. Businesses that build governance frameworks now will face significantly lower disruption and compliance cost when formal regulation arrives.

Three tiers of AI governance, built to scale with your business.

From foundational compliance to ongoing advisory — every tier is customised for your industry, your team size, and the tools you actually use.

Tier 1
Compliance Foundation
Once-off engagement

Everything a small business needs to establish a defensible, POPIA-aligned AI compliance baseline — delivered in a single engagement.

  • Customised AI User Usage Policy (employee-facing, plain language)
  • AI Business Strategy and Compliance Policy (management-facing)
  • 45–60 minute facilitated staff training session
  • AI Incident Report Form
  • Signed employee acknowledgement forms
Tier 3
Ongoing Advisory
Monthly retainer

Continuous compliance support as AI tools evolve and South African regulation develops — so your business stays ahead of change.

  • Annual policy review and update
  • Regulatory monitoring and alerts
  • Annual staff re-training session
  • Priority advisory access
  • Vendor and Operator Agreement review
  • Employee self-assessment tracking

We don't sell generic templates. We build frameworks that work in South Africa.

Most AI governance services are designed for large enterprises or built for international markets. We focus on small and medium South African businesses — with the legal grounding, plain language, and practical delivery that actually makes a difference.

Legal and technical expertise, combined

Our team spans legal (specialising in cyber law and cybersecurity), enterprise IT management, and actuarial risk — the exact disciplines AI governance requires. Most competitors bring only one of these. We bring all three.

Built for South African SMEs, not adapted for them

Our frameworks are grounded in SA law, written in plain language, and calibrated for businesses without dedicated legal or IT departments. Not international templates repurposed for local use — built from scratch for this context.

Compliance frameworks, not legal advice

We provide governance frameworks and responsible use training — clearly distinguished from legal opinions. This distinction protects both parties and keeps our service accessible and affordable for growing businesses.

We deliver working systems, not documents

We do not hand over a folder and leave. Your engagement ends with trained staff, signed acknowledgements, and a functioning compliance system. Everything is customised to your business, your tools, and your industry.

Already binding. Right now.

You do not need to wait for a dedicated AI Act to face legal obligations. POPIA, the Cybercrimes Act, and King V Corporate Governance principles already apply to how your business uses AI. Most small businesses are non-compliant today — not through negligence, but because no one has explained what compliance looks like in practice.

POPIA 2013
Cybercrimes Act 2020
King V 2025
National AI Framework

A clear, four-step engagement process.

From first contact to signed acknowledgements — a structured process designed to be low-friction for busy business owners.

1

Discovery

We assess your current AI tool use, team size, industry context, and data exposure to understand exactly what your business needs.

2

Customise

We tailor your policy documents, approved tools list, and training content to your specific business, industry, and team.

3

Deliver

We facilitate the training session in person, walk employees through the policy, and collect signed acknowledgement forms.

4

Support

Ongoing advisory available via retainer as regulation evolves and your AI tool use grows.

Ready when you are.

We operate from Pietermaritzburg and serve businesses across KwaZulu-Natal and nationally. Sessions can be delivered in person or remotely. Engagements typically take two to three weeks from initial contact to training completion.

Book a Consultation

Let's talk about what your business needs.

Whether you are starting from scratch or looking to build on existing policies, we will give you a clear picture of your current compliance gaps and what it takes to address them.

Pietermaritzburg, KwaZulu-Natal
shivaan@inai.co.za
Response within 1 business day
Send us a message
Tell us about your business and we will get back to you within one business day.

This form does not constitute legal advice. We will respond within one business day to discuss your needs.