AI governance is a records problem before a policy one
If a regulator or a court asks what your staff typed into an AI tool about a contract, you may have to hand it over. Discovery reaches drafts, communications and other electronically stored information, and a United States court has already ordered the production of an expert's AI prompts. AI governance in most South African businesses stops at an acceptable use policy. The employee behaviour it needs to reach is the record.
That is the argument in a piece by Tebogo Sibidla, a Director at Werksmans, and it is a sharper argument than the headline suggests.
What the courts have actually done
Werksmans sets out a run of recent decisions and draws one line through them: long established principles about confidentiality, privilege and evidential integrity apply whatever the technology.
- In United States v Heppner, the Southern District of New York held that a defendant's exchanges with a public AI platform carried neither privilege nor work product protection. He had been preparing a defence. The court called it a question of first impression. No lawyer was party to the exchange, and the platform's terms said inputs were not confidential.
- The Upper Tribunal held that putting client letters and Home Office decision letters into an open source AI tool places that information in the public domain. Confidentiality is breached and privilege is waived. The case is UK and R (Munir) v Secretary of State for the Home Department [2026] UKUT 81 (IAC), heard under the tribunal's Hamid jurisdiction. A closed tool running inside a secure network was treated differently.
- In Conservation Law Foundation v Shell Oil, on 18 May 2026, Magistrate Judge Thomas Farrish of the District of Connecticut ordered production of the AI prompts an expert had used to cull a document set. An expert's methodology is discoverable, and the prompts were part of the methodology.
- In Godwin v Godwin [2026] EWHC 923 (Ch), HHJ Klein treated witness evidence with caution where draft statements had been uploaded to ChatGPT before being finalised.
- AI communications formed part of the evidence in Fortis Advisors LLC v Krafton Inc in the Delaware Court of Chancery.
None of those judgments bind a South African court. They are worth reading anyway, because they show how courts in comparable systems are treating the same facts, and because the local example is closer to home.
Communications minister Solly Malatsi withdrew the Draft National AI Policy in April 2026, weeks after publishing it, once News24 reported that references in it did not exist. ITWeb reported the formal retraction, gazetted on 12 June 2026. The policy meant to govern AI was withdrawn over what looks like unchecked AI output, and accountability for it stayed with the humans who signed it.
Read the Werksmans article in full. It is one of the few pieces on this subject written for the people who create the risk rather than for the lawyers who inherit it.
The half your policy does not cover
Almost every write up of this will land on the same recommendation, which is to publish an acceptable use policy. That is the easy half, and it is the half that costs nothing.
The conclusion Werksmans actually reaches is a records conclusion. Organisations should preserve original source documents, avoid relying only on AI generated summaries in significant matters, and make sure legal advisers can reach the primary evidence. Prompts, uploaded documents and AI generated outputs on significant matters may one day require disclosure.
Now put that against how a 60 person business actually stores things. The signed contract is in the managing director's inbox. The negotiated version before it is in an attachment on a thread with the client. The board pack is in a shared drive folder named after the month it was made in.
A business in that position cannot preserve the original source document, because it cannot find the original source document. It cannot show a lawyer the primary evidence either, and the AI summary somebody generated in March is now the most complete account of a contract anybody has. That is the exposure, and no policy fixes it.
What separates a governed rollout from an ungoverned one
Werksmans draws a distinction that is easy to skip past. An enterprise AI environment with contractual safeguards is not the same thing as a public platform, and the two should not be governed as though they are.
The difference shows up in what happens to an uploaded document. Moneyweb reports Standard Bank saying that around a third of its technology staff now use AI enabled coding applications, with early productivity gains of roughly 20%. That is a measured rollout inside chosen tools, with a number attached to it.
Most businesses have the opposite arrangement. Staff adopted the tools first, individually, on free accounts, and nobody knows which ones. The productivity is probably real. The visibility is not.
The practical governance question is not whether to allow AI. It is which matters require legal review regardless, which tools may touch a confidential document at all, and whether the original of that document still exists somewhere a second person can find it.
Joining a document store, a contract register and an email archive so that the executed version of an agreement has one findable home is unglamorous work. It is also the work that makes the rest of an AI policy enforceable, and it is the ordinary shape of what Zorah does. The automation is worth very little if the record underneath it is scattered.
What to do on Monday
Pick the last three contracts your business signed. Ask one person to produce the executed original of each, in under five minutes, without phoning anyone.
If that fails, you have found the problem before a regulator does. If it succeeds, run the same test on the last two regulatory letters you answered.
Then ask your three heaviest AI users one question, without making it a disciplinary matter: what have you uploaded this month. The answer is the scope of the work, and you cannot govern what you have not counted.
