Choosing an AI automation partner in South Africa: the questions to ask before you sign
What to ask an AI automation partner before you sign: who owns the work when you leave, POPIA operator terms, pilots, measures and red flags.
Last checked

The short answer
Before you sign with an AI automation partner, get five things in writing: who owns what gets built, what the partner may do with your data under POPIA, where that data is processed and whether anyone trains on it, who decides when the agent gets something wrong, and how the pilot will be judged. A partner that puts all five into the contract is one you can leave without losing the work.
Who owns the workflows, prompts and data when you leave?
You should, and the contract has to say so, because the platform terms do not cover it. A model provider's business terms deal with your inputs and outputs. Microsoft, for example, says it "doesn't claim ownership of the output of the service" for Copilot. Those terms say nothing about the prompts, workflow designs and integration code a partner builds around the model.
Ask for ownership, or a perpetual licence, of:
- the prompts, instructions and agent settings
- the workflow definitions and the code that connects the agent to your systems
- the test cases and evaluation results used to prove the agent works
- logs, conversation history and outputs
- the accounts: the model provider, the automation platform and any WhatsApp number should be in your company's name, with the partner given access
Then ask how you leave. The insurers' outsourcing standard, Joint Standard 1 of 2024, is a useful model even where it does not bind: it requires continued access to information, "address ownership of intellectual property", continuity if the provider becomes insolvent, and "a reasonable termination period". Borrow those clauses, and add an export in a format you can use, a handover period and written confirmation that your data has been deleted.
Is the partner an operator under POPIA, and what must the contract say?
Usually yes. The Protection of Personal Information Act defines an operator as "a person who processes personal information for a responsible party in terms of a contract or mandate", without coming under that party's direct authority. A partner that runs an agent over your customer records fits, and your business stays the responsible party.
Three duties follow from the Act's text:
- Under section 20, the operator may process the information "only with the knowledge or authorisation of the responsible party" and must keep it confidential.
- Under section 21, you need a written contract that makes the operator establish and maintain the security measures in section 19, starting with identifying "all reasonably foreseeable internal and external risks".
- The operator "must notify the responsible party immediately" when there are reasonable grounds to believe someone unauthorised has reached the information. You must then notify the Information Regulator and the people affected "as soon as reasonably possible" under section 22.
The Regulator enforces this. In a media briefing on 26 March 2024 it reported on a pharmaceuticals company whose e-statement database was breached, reaching the personal information of 3.6 million data subjects. Its enforcement notice ordered the company to conclude "written contracts with all operators" compelling the same or better security measures, and to build a compliance framework for the breach reporting duties of the company and its operators.
So the operator agreement should name what data the agent touches and why, the security measures, every sub-processor including the model provider, breach notice with a named contact, your right to audit, and deletion at the end.
This is not legal advice. Checked against the text of the Protection of Personal Information Act on 9 October 2026, and against Joint Standard 1 of 2024 the same day. Have an attorney check your own arrangement.
Where will our data be processed, and is anyone training on it?
Ask the partner to name every model provider the agent uses and where each processes data, then read the providers' own terms. Sending personal information to a third party in a foreign country is restricted by section 72 of the Act. It is allowed only on listed grounds, such as a recipient bound by a law, "binding corporate rules or binding agreement" that gives adequate protection, or the data subject's consent.
What the platforms' own pages say about their business products:
- Microsoft Copilot: prompts, responses and data reached through Microsoft Graph "aren't used to train foundation LLMs". Customers outside the EU "may have their queries processed in the US, EU, or other regions".
- OpenAI API: data sent to the API has not been used to train OpenAI's models since 1 March 2023 unless you opt in to share it, but abuse monitoring logs are kept for up to 30 days by default. Its data residency options list a set of regions, and South Africa is not among them.
- Google Workspace with Gemini: "User prompts are considered customer data under the Cloud Data Processing Addendum", and Workspace does not train on customer data without the customer's prior permission or instruction.
None of these pages commits to processing inside South Africa, so assume the data leaves the country and make sure the contract chain covers the transfer. Read the exceptions too: Microsoft says it may use optional customer feedback to improve Copilot, though not to train the foundation models. Ask the partner which settings are on, in writing.
Who decides when the agent gets it wrong?
A person should, for anything with legal or significant effect on a customer. Section 71 of the Act says a person may not be subject to a decision with legal consequences, or one that affects them to a substantial degree, based solely on automated processing that profiles them, for example on creditworthiness. Where a decision tied to a contract relies on safeguards instead of meeting the person's request, those safeguards must let the person make representations and give enough information about the underlying logic to do so.
So before an agent declines a claim, an application or a credit request, ask: does a person review it, how does the customer reach that person, and can the partner explain in plain words how the agent reached its answer? Build the handover into the first version.
How should a pilot be run and measured?
Agree the measure before the pilot starts, test on your own cases, and set an end date with a decision at the end.
The AI Risk Management Framework of the US National Institute of Standards and Technology, released on 26 January 2023 for voluntary use, gives a pilot its shape through four functions:
- Govern: name the owner on each side, and who can stop the pilot.
- Map: pick one process, write down its current steps, and list what could go wrong for customers and staff.
- Measure: take a baseline from the current process, then test the agent on real past cases with checked answers.
- Manage: decide in advance which results mean go, change or stop.
What to measure:
- accuracy against answers a person has checked
- the share of cases handed to a person, and why
- time to handle a case, before and after
- errors that reached a customer
- what it costs to run at pilot volume, and at full volume
Ask for the raw results as well as the summary, and for the test set back: it is your data.
Should we build a custom agent or buy an off-the-shelf tool?
Buy when the work lives inside one suite you already use. Build when the work crosses systems, takes actions in them, or talks to customers. Off-the-shelf assistants inherit your access settings: Microsoft Copilot "only surfaces organizational data to which individual users have at least view permissions", so audit sharing before you switch it on. A custom agent brings the ownership, operator and transfer questions above with it.
Red flags in an AI automation proposal
- No written operator agreement, or one silent on security, breach notice and deletion.
- The partner will not name the model providers or say where they process data.
- A promise that nobody trains on your data, with no reference to the platform terms or their exceptions.
- Workflows built inside the partner's own accounts, with no export when you leave.
- Accuracy claims with no test on your own cases.
- No person in the loop for decisions that affect a customer's rights or money.
- A pilot with no written success measure and no end date.
- Outputs nobody checks. On 26 April 2026 the Minister of Communications and Digital Technologies announced the withdrawal of the draft National AI Policy, saying it "contains various fictitious sources in its reference list".
The questions to put in writing
Each question, then what a good answer looks like:
- Who owns the prompts, workflows, code, test sets and logs? You do, or you hold a perpetual licence, and the contract says so.
- Whose name are the accounts in? Yours, with the partner given access.
- Is there a written operator agreement under POPIA? Yes, covering security, sub-processors, breach notice and deletion.
- Which model providers process the data, and where? A named list, with regions and the terms on training and retention.
- Who reviews decisions that affect a customer? A named role, and a way for the customer to reach it.
- How will the pilot be judged? A baseline, a test set of your own cases, the measures above and a date.
- How do we leave? An export format, a handover period and confirmed deletion.
Where IAMX fits
IAMX delivers custom AI agents and copilots through a vetted network of specialist partners: agents that plug into your own tools, workflows and data, taken from pilot into daily use, with one accountable lead who owns the outcome.
Questions buyers ask about AI automation partners
-
Is an AI automation agency an operator under POPIA?
In most arrangements, yes: it processes personal information for you under a contract or mandate, so it fits the Act's definition. You remain the responsible party, and section 21 requires a written contract binding it to the Act's security measures.
-
Can we put customer data into Copilot, Gemini or the OpenAI API?
Yes, on business plans, once the transfer abroad has a ground under section 72 and the retention terms suit you. Each provider's page says business prompts are not used to train its models by default, but none commits to processing in South Africa. Consumer and personal plans have different terms, which we did not review here.
-
Does South Africa have an AI law?
We found no AI-specific statute when we checked, and the Minister announced the withdrawal of the draft National AI Policy on 26 April 2026. Using AI on personal information is governed by POPIA, including its rules on operators, transfers abroad and automated decisions, and by any sector rules that apply to your business.
-
Can an AI agent answer our customers on WhatsApp?
Yes, within Meta's rules. Meta's terms bar providers and developers of AI technologies, general-purpose assistants among them, from offering those technologies on the WhatsApp Business Platform where they are "the primary (rather than incidental or ancillary) functionality", as Meta determines in its sole discretion. A business may still use an AI provider as its solution provider, but platform data may then not be used to train AI models, except to fine-tune one for the business's exclusive use. Ask how the partner's design fits the terms.
On cost, Meta has charged by the message since 1 July 2025. Free-form replies, which can only be sent inside the 24-hour customer service window that opens when a customer messages or calls you, were free from 1 November 2024. Meta's documentation now bills them as service messages. Ask your provider what Meta charges for them on your number and which free allowances apply, and get it in the quote.
Sources
- Microsoft: Microsoft says it does not claim ownership of the output of the Copilot service. Checked .
- Financial Sector Conduct Authority and Prudential Authority: Joint Standard 1 of 2024 (Outsourcing by Insurers), clause 9.1, requires a written contract for a material function that gives continued access to information, addresses ownership of intellectual property, provides for continuity if the provider becomes insolvent, and provides a reasonable termination period. Checked .
- South African Government (gov.za): Section 1 of POPIA defines an operator as a person who processes personal information for a responsible party in terms of a contract or mandate, without coming under the direct authority of that party. Checked .
- Information Regulator (South Africa): The Information Regulator's media briefing of 26 March 2024 reported a May 2022 breach of a pharmaceuticals company's e-Statement database affecting 3.6 million data subjects, and an enforcement notice ordering written contracts with all operators compelling the same or better section 19 security measures. Checked .
- South African Government (gov.za): The text of the Protection of Personal Information Act 4 of 2013, as published in Government Gazette 37067 of 26 November 2013, was read on the South African Government's site on 9 October 2026. Checked .
- South African Government (gov.za): Section 21(1) of POPIA requires a written contract between the responsible party and the operator that ensures the operator establishes and maintains the security measures in section 19. Checked .
- South African Government (gov.za): Section 19 of POPIA requires the responsible party to identify all reasonably foreseeable internal and external risks to personal information and to establish, verify and update safeguards against them. Checked .
- South African Government (gov.za): Section 21(2) of POPIA says the operator must notify the responsible party immediately where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person. Checked .
- South African Government (gov.za): Section 22 of POPIA requires the responsible party to notify the Information Regulator and the data subject of a security compromise as soon as reasonably possible after it is discovered. Checked .
- South African Government (gov.za): Section 72 of POPIA bars transferring personal information to a third party in a foreign country unless a listed ground applies, such as a recipient bound by a law, binding corporate rules or binding agreement giving adequate protection, or the data subject's consent. Checked .
- Microsoft: Microsoft says it may use optional customer feedback to improve Microsoft Copilot, but does not use that feedback to train the foundation LLMs. Checked .
- Microsoft: Microsoft says prompts, responses and data accessed through Microsoft Graph are not used to train foundation LLMs, including those used by Microsoft Copilot. Checked .
- Microsoft: Microsoft says customers outside the EU may have their Copilot queries processed in the US, EU, or other regions. Checked .
- OpenAI: OpenAI says that as of 1 March 2023, data sent to the OpenAI API is not used to train or improve OpenAI models, unless the customer explicitly opts in to share data. Checked .
- OpenAI: OpenAI says abuse monitoring logs are generated for all API usage by default and retained for up to 30 days. Checked .
- OpenAI: OpenAI's list of API data residency regions does not include South Africa. Checked .
- Google: Google says Workspace user prompts are customer data under the Cloud Data Processing Addendum and that Workspace does not use customer data to train models without the customer's prior permission or instruction. Checked .
- South African Government (gov.za): Section 71 of POPIA bars decisions with legal consequences or substantial effect based solely on automated processing that profiles a person, with exceptions that must let the person make representations and receive enough information about the underlying logic. Checked .
- National Institute of Standards and Technology (US Department of Commerce): NIST released AI RMF 1.0 on 26 January 2023 for voluntary use; its core functions are Govern, Map, Measure and Manage. Checked .
- Microsoft: Microsoft says Copilot only surfaces organizational data to which individual users have at least view permissions. Checked .
- SAnews, Government Communication and Information System: On 26 April 2026 the Minister of Communications and Digital Technologies announced the withdrawal of the draft National AI Policy because it contains various fictitious sources in its reference list. Checked .
- Meta: Section 4.7 of Meta's terms bars providers and developers of AI technologies, including general-purpose AI assistants, from the WhatsApp Business Platform where AI is the primary rather than incidental or ancillary functionality, as Meta determines; a business may retain an AI provider as its solution provider, and in that case may not let platform data be used to train AI models, except to fine-tune a model for its exclusive use. Checked .
- Meta: Meta's WhatsApp changelog records charging by the message going live on 1 July 2025. Checked .
- Meta: Meta's WhatsApp Cloud API documentation says a 24-hour customer service window starts when a user messages or calls the business, and non-template messages can be sent only while it is open. Checked .
- Meta: Meta's WhatsApp changelog records service conversations becoming free for all businesses on 1 November 2024. Checked .
- Meta for Developers: Meta's WhatsApp Cloud API documentation says service messages, the free-form replies sent while a customer service window is open, are billed under the service category. Checked .