South African organisations are no longer debating whether to adopt artificial intelligence. Across Africa, 64% of employees now report using AI at work in the past year, ahead of the 54% global average, and 76% believe generative AI improves the quality of their work according to PwC’s 2025 Africa Workforce Hopes and Fears Survey. AI has already moved from experimentation into everyday business practice.
The real question, the one keeping chief information officers awake at night, is whether any of it can be trusted: whether the data behind it is .accurate, whether access is properly controlled, and whether every decision it makes can be explained after the fact.
Businesses want the capability, customers want the convenience, and employees want the productivity gains, but few are asking whether the organisation is actually ready to carry that speed safely on every one of those dimensions at once.
This is not a uniquely South African problem, but it carries a distinctly South African weight. Local enterprises are operating AI ambitions on top of decades-old core systems, hybrid workforces, and a data protection regime: the Protection of Personal Information Act (POPIA) that was not written with generative AI in mind but applies to it in full force regardless. When AI is bolted onto fragmented legacy applications rather than built into a governed, unified platform, the risk is not theoretical; it is operational, financial, and legal, all at once.
The cost of moving fast without a foundation
The instinct to deploy first and govern later is understandable. Boards are demanding visible AI progress, competitors are moving, and vendors are promising quick wins. But the evidence from enterprises further down this road is sobering. A study of more than 350 senior finance and IT executives found that just 19% pull the majority of their AI inputs from a single, centralised enterprise system, even though 79% believe their data governance can support large-scale AI adoption.
That fragmentation is precisely where hallucinations, permission leaks, and compliance breaches take root. An AI assistant plugged into disconnected systems has no single, verified source of truth. It fills gaps with plausible-sounding but incorrect information, drawn from stale records or the wrong context entirely. Left unmanaged, the same fragmentation lets AI tools access data far beyond what a role should permit because permissions were designed for humans clicking through interfaces, not for agents querying data programmatically across every connected system.
For South African organisations, this collides directly with POPIA. The Act governs all processing of personal information, including how it is used to train, prompt, or fine-tune AI systems, and it places direct accountability on the organisation as the Responsible Party, not on the AI vendor and certainly not on the algorithm itself. An AI agent that cannot show its workings, or that was never designed with an audit trail, leaves an organisation exposed the moment the Information Regulator asks how a decision was reached.
This is why adoption without governance is reckless and expensive in ways that only become visible after the damage is done, through regulatory penalties, reputational harm, and the far quieter cost of decisions made on bad data that nobody thought to question.
Governance is the platform, not the brake
The instinctive framing of governance as the department that slows innovation down is precisely backwards, and it is increasingly out of step with what the data shows. A Gartner survey of 360 organisations found that those deploying specialised AI governance platforms are 3.4 times more likely to achieve high effectiveness in their AI governance than those that do not, and Gartner projects that effective governance technology can reduce regulatory compliance costs by roughly 20%. Governance, done properly, is not the obstacle between an organisation and AI value; it is the mechanism that makes sustained value possible at all.
And yet, governance, literacy, and oversight have not kept pace with South Africa’s increasing AI usage growth, and that gap is where the real exposure sits. Reframing governance as an enabler requires building permissions, data lineage, and audit trails into the AI architecture from the outset, not layering them on once a system is already live. It means the Information Officer, the compliance team, and the technology function are working from the same data model, not reconciling three different versions of the truth after an incident has already occurred.
From fragmented tools to trustworthy, auditable agents
The technical root of most AI governance failures is deceptively simple: AI assistants are only as reliable as the data feeding them, and most enterprises are feeding them from a patchwork of disconnected applications, spreadsheets, and point solutions that were never designed to share a common system. An AI layered onto that patchwork inherits every inconsistency, duplicate record, and outdated field within it. The result is context-blind output that looks confident and is frequently wrong.
Unified data ecosystems change this equation entirely. When every business application draws from the same governed dataset, an AI assistant is not guessing at context; it is working from a single, current, permissioned source of truth. This is also the only realistic foundation for autonomous agents, which are being asked to do considerably more than answer questions. Agents that can initiate workflows, update records, and trigger transactions need strict, role-based permissions that mirror exactly what a human in that role would be allowed to touch, and every action they take must be logged, explainable, and reversible.
The real return is trust, not hype
The organisations that will benefit most from AI in South Africa over the next few years will not be the ones that built a governed, unified foundation first and let automation compound steadily on top of it, through daily workflow gains that are measurable, auditable, and defensible under POPIA rather than speculative headline announcements that cannot survive scrutiny.
Governance before scale is a call to build the platform that makes speed sustainable. For enterprises and SMEs alike, the organisations asking the harder question now (whether their AI is accurate, controlled, and grounded in reliable data) are the ones that will still be operating with confidence and without incident when the regulator, the client, or the board eventually asks them to prove it.
- Andrew Bourne, Regional Head, Southern Africa at Zoho

