Search legal guides

Search MJ Kotze Inc legal guides and articles

Software & Technology

AI Features Addendum in South Africa

The rider that bolts onto a SaaS or cloud contract once a product ships AI features — drawing clear lines around inputs, outputs, model training, accuracy and liability, and keeping all of it inside POPIA.

Written by

Martin Kotze

Attorney, Conveyancer & Notary Public

Last reviewed:

Quick answer

What is an AI features addendum?

An AI features addendum — sometimes called an AI terms rider, generative-AI addendum, or AI services schedule — is a contractual add-on to a SaaS or cloud services agreement that governs the artificial-intelligence and machine-learning features inside the product. It exists because AI features raise questions an ordinary software contract never had to answer: who owns the inputs a customer feeds in (prompts, documents, data) versus the outputs the model generates; whether the provider may use customer data to train or improve its models; how accurate the outputs are warranted to be; what the customer may and may not do with an AI feature; and who carries the risk when the AI is wrong or produces something that infringes a third party’s rights. The addendum typically also flows through the terms of the underlying foundation-model provider (for example a large language model accessed through an API), so the customer is bound by those third-party terms too. In South Africa there is no dedicated AI statute, so the addendum does the heavy lifting contractually, while staying inside the boundaries set by the Protection of Personal Information Act 4 of 2013 (POPIA) and the Copyright Act 98 of 1978.

Is an AI features addendum legally binding in South Africa?

Yes. An AI features addendum is binding in South Africa as an ordinary contract — it supplements the SaaS or cloud agreement it attaches to and is enforced under the common law of contract, provided there is consensus, a lawful purpose, certainty and no conflict with public policy. Where the addendum is accepted by clicking “I agree” or ticking a box, formation is supported by the Electronic Communications and Transactions Act 25 of 2002 (ECTA), which gives legal effect to agreements concluded electronically and to data messages. But binding does not mean unlimited. Two SA-specific constraints sit above the contract. First, POPIA overrides any term that purports to authorise unlawful processing of personal information: section 71 gives a data subject the right not to be subject to a decision that has legal or similarly significant effects and is based solely on the automated processing of their personal information (including profiling), subject to defined exceptions and safeguards, and sections 11 and 13 require a lawful basis and a specified purpose before personal information may be used to train or run AI on it. A clause that lets an AI feature make solely-automated decisions about people, or quietly repurposes their data for training, is not saved by the customer’s click-acceptance. Second, the Copyright Act is uncertain on AI: it contemplates a “computer-generated work” and assigns authorship to the person who made the arrangements necessary for its creation, but whether a given AI output is protected at all, and who owns it, is unsettled. That uncertainty is exactly why a careful addendum allocates ownership and risk in inputs and outputs by contract, rather than leaving the parties to argue about what the Act gives them.
A data subject may not be subject to a decision which results in legal consequences for him, her or it, or which affects him, her or it to a substantial degree, which is based solely on the basis of the automated processing of personal information intended to provide a profile of such person — subject to defined exceptions and appropriate measures to protect the data subject’s legitimate interests.
Protection of Personal Information Act 4 of 2013 (POPIA), s 71
Personal information may only be processed where there is a lawful justification (such as consent) and must be collected for a specific, explicitly defined and lawful purpose — so customer data may not be used to train or run AI on personal information without a lawful basis and a defined purpose.
Protection of Personal Information Act 4 of 2013 (POPIA), ss 11 & 13
The Act recognises a “computer-generated work” and attributes authorship to the person by whom the arrangements necessary for the creation of the work are undertaken — but whether and how this applies to AI-generated output is unsettled, which is why ownership of AI inputs and outputs is best fixed by contract.
Copyright Act 98 of 1978

When you need a AI Features Addendum

  • When you launch AI or generative-AI features in an existing SaaS or cloud product and your current terms of service say nothing about prompts, outputs, model training, or AI accuracy.
  • When your product calls a third-party foundation model (such as a large language model via an API) and you need to flow that provider’s usage terms and restrictions through to your own customers.
  • When customers ask, during procurement or due diligence, whether you use their data or documents to train your models — and you need a clear, contractual opt-out or de-identification position to give them.
  • When an AI feature makes or assists decisions about individuals (scoring, ranking, screening, eligibility), bringing POPIA section 71 on solely-automated decision-making into play.
  • When customers feed personal information into AI features, so that you need a lawful basis and a defined purpose under POPIA sections 11 and 13 before that data is processed or used to improve a model.
  • When you need to disclaim reliance on AI output — making clear it is not legal, financial, medical or other professional advice, and that human oversight is required — to manage the risk of an AI error.

What a AI Features Addendum should contain

1

Ownership of inputs and outputs

State who owns the inputs (the customer’s prompts, data, and documents) and who owns the outputs (what the AI generates), and the licence each party grants the other. The usual position is that inputs stay the customer’s, outputs are assigned or licensed to the customer for their use, and the provider keeps the underlying models — but because the Copyright Act is uncertain on AI-generated material, the addendum must fix this expressly rather than assume the Act resolves it.

2

Model training and improvement (with opt-out / de-identification)

Say plainly whether customer inputs and outputs may be used to train, fine-tune, or improve the provider’s models. Where personal information is involved, POPIA requires a lawful basis and a defined purpose, so training use should be opt-out (or opt-in) and tied to de-identification or aggregation. Cross-refer to an aggregate and anonymised data addendum where de-identified data is reused so the two documents do not contradict each other.

3

Accuracy disclaimer and human oversight

Warrant the AI features “as is” and disclaim that outputs are accurate, complete, or fit for a particular purpose. Make clear the output is not legal, financial, tax, medical, or other professional advice, that it may be wrong or “hallucinated”, that the customer must not rely on it without independent verification, and that meaningful human oversight is required — especially where outputs feed a decision about a person.

4

POPIA and automated decision-making

Where AI features make or assist decisions about individuals, address POPIA section 71 directly: do not let the feature produce a decision based solely on automated processing that has legal or similarly significant effects on a person, unless an exception applies and the required safeguards (the ability to make representations, human review) are in place. Confirm each party’s POPIA roles (responsible party / operator) for personal information processed through the AI feature.

5

Acceptable use of AI features

Prohibit uses that create legal or safety risk — feeding in unlawful, infringing, or special-category personal information; attempting to reverse-engineer or extract the model; generating unlawful, defamatory, or harmful content; or using outputs to make prohibited solely-automated decisions about people. Reserve the right to suspend AI features for breach, and pass through the use restrictions imposed by any underlying foundation-model provider.

6

Third-party foundation-model flow-through

Where the product relies on an external model provider, flow that provider’s terms, acceptable-use policy, and restrictions through to the customer, and disclaim liability for changes, outages, or output of the third-party model. This puts the customer on notice that part of the service is supplied by a sub-processor whose terms they must also observe, and aligns the addendum with the chain of upstream contracts.

7

Confidentiality of prompts and inputs

Treat the customer’s prompts, inputs, and the resulting outputs as the customer’s confidential information, and commit not to disclose them or use them beyond providing the service (and any permitted, de-identified training use). This reassures customers that sensitive material entered into AI features is protected, and dovetails with both the confidentiality terms of the main agreement and POPIA’s security-safeguards duty.

8

Liability for AI errors and infringing output

Allocate the risk of AI being wrong and of an output that infringes a third party’s intellectual property. Typically the provider’s liability for AI output is limited or excluded (consistent with the accuracy disclaimer), the customer takes responsibility for how it uses outputs, and any IP-infringement indemnity for outputs is carefully scoped — bearing in mind that a blanket exclusion can be tested against public policy and the Consumer Protection Act where it applies.

9

Suspension, changes, and survival

Reserve the right to change, throttle, or withdraw AI features (which often depend on volatile third-party models), and set out what happens to inputs and outputs on termination. Make the ownership, confidentiality, POPIA, and liability provisions survive termination, so the protections do not evaporate the moment the underlying SaaS subscription ends.

AI features addendum vs cloud/SaaS agreement vs data protection addendum

FeatureAI features addendumCloud / SaaS agreementData protection addendum
Main jobGoverns the AI/ML features — inputs, outputs, training, accuracy, AI liabilityGoverns the overall software service, fees, uptime, supportGoverns how personal information is processed under POPIA
Ownership focusInputs vs outputs vs the modelsThe software and customer data generallyNot about ownership — about lawful processing
Key SA lawCopyright Act (computer-generated works) + POPIA s71Common law of contract + ECTA + CPAPOPIA (responsible party / operator duties)
Training / de-identificationCentral — opt-out and de-identification for model trainingUsually silentSets the rules for processing and de-identification
When you add itWhen the product ships AI featuresThe base contract for any cloud productWhenever personal information is processed

Common South African pitfalls

  • Saying nothing about inputs vs outputs: relying on the Copyright Act to sort out who owns AI-generated output is a mistake, because the Act’s treatment of computer-generated works does not clearly resolve AI ownership. If the addendum is silent, the customer and provider can each end up claiming the same output — fix ownership and licences expressly.
  • Quietly training on customer data: using customer prompts or documents to train or improve models without a clear basis breaches POPIA where personal information is involved — sections 11 and 13 require a lawful justification and a defined purpose. Hiding training use in dense terms, with no opt-out and no de-identification, is both a compliance and a trust failure.
  • Letting AI make solely-automated decisions about people: where an AI feature scores, screens, or ranks individuals and that decision has legal or similarly significant effects, POPIA section 71 restricts decisions based solely on automated processing. An addendum that enables such decisions without an exception, human review, and the right to make representations is non-compliant.
  • A weak or missing accuracy disclaimer: AI outputs can be confidently wrong. Without a clear disclaimer that outputs are not professional advice, may be inaccurate, and require human verification and oversight, the provider invites reliance-based claims when the AI gets it wrong — and the customer is left over-trusting the tool.
  • Ignoring the foundation-model terms upstream: if the product runs on a third-party model, the provider is bound by that model’s usage terms and restrictions. Failing to flow those through to customers can put the provider in breach upstream while leaving customers unaware of restrictions that bind them.
  • A blanket liability exclusion that may not hold: excluding all liability for AI errors and infringing outputs can be tested against public policy, and against the Consumer Protection Act where the customer is a consumer. An exclusion that is unreasonable or unfair in the circumstances may be read down, so liability must be allocated thoughtfully rather than simply switched off.

Frequently asked questions

What is an AI features addendum?

It is a contractual add-on to a SaaS or cloud agreement that governs the AI and machine-learning features in the product. It sets out who owns inputs and outputs, whether customer data may be used to train models, how accurate outputs are warranted to be, acceptable use of the AI, and who bears liability when the AI is wrong or produces infringing content. In South Africa it does this contractually, within POPIA and the Copyright Act.

Who owns the output an AI feature generates in South Africa?

Ownership is best settled by contract, because the Copyright Act 98 of 1978 is uncertain on AI-generated material. The Act recognises a “computer-generated work” and attributes authorship to whoever made the arrangements necessary for its creation, but whether a given AI output is protected at all, and who owns it, is unsettled. A good addendum therefore assigns or licenses outputs expressly rather than relying on the Act.

Can a provider use my data to train its AI models?

Only on a lawful basis. Where the data includes personal information, POPIA sections 11 and 13 require a lawful justification (such as consent) and a specific, defined purpose before that data may be used to train or run AI. A well-drafted addendum makes training use transparent, offers an opt-out, and ties any reuse to de-identification or aggregation — usually cross-referenced to an aggregate and anonymised data addendum.

Does POPIA restrict AI features that make decisions about people?

Yes. POPIA section 71 gives a person the right not to be subject to a decision that has legal or similarly significant effects and is based solely on the automated processing of their personal information, including profiling — subject to defined exceptions and safeguards. So an AI feature that scores, screens, or ranks individuals with significant consequences needs an exception, human involvement, and the ability for the person to make representations.

Are AI accuracy disclaimers enforceable in South Africa?

A clear accuracy disclaimer is generally enforceable as a contractual term, which is why the addendum should warrant AI features “as is”, state the output is not professional advice, and require human oversight. But disclaimers are not unlimited: a term that is contrary to public policy, or unfair under the Consumer Protection Act where it applies, can be read down. Precise, reasonable disclaimers tied to genuine AI limitations hold up best.

How does an AI features addendum handle third-party foundation models?

It flows the model provider’s terms through to your customers. Where your product calls an external model (for example a large language model via an API), the addendum binds your customer to the upstream provider’s acceptable-use policy and restrictions, and disclaims liability for changes, downtime, or output of that third-party model. This keeps your contract consistent with the terms you are bound by upstream.

Are prompts and inputs kept confidential?

They should be. A well-drafted addendum treats the customer’s prompts, inputs, and outputs as the customer’s confidential information, and commits the provider not to disclose them or use them beyond delivering the service and any permitted, de-identified training. This dovetails with the confidentiality terms of the main agreement and with POPIA’s duty to secure personal information against unauthorised access or use.

Do I need an AI features addendum, or can I just update my main terms?

You can put the AI terms inside your main agreement, but a separate addendum is usually cleaner: it isolates the AI-specific issues — inputs versus outputs, training, accuracy, automated decisions, and foundation-model flow-through — so they can be updated as the technology and the law evolve without reopening the whole contract. Either way, the substance must cover ownership, training, accuracy, POPIA, and liability.

Sources & authority

This guide is general information, not legal advice. It reflects the law as at June 2026.

Get your AI Features Addendum reviewed or drafted

Upload an existing document for a fixed-fee review, or have a bespoke AI Features Addendum drafted for your business — personally, by a senior corporate and commercial attorney. No obligation to proceed.

Review: Fixed fee from R8 325 (excl. VAT) · 48-hour turnaroundDraft: Fixed fee from R8 175 (excl. VAT)

For the businesses we act for

The Keystone Workspace

The attorney-designed platform the businesses we act for use to run their contracts, e-signatures and company secretarial work in one place.

Why you can trust this: Martin Kotze has been an admitted Attorney of the High Court of South Africa, registered Conveyancer, and Notary Public since 2014, practising from Pretoria. The firm is regulated by the Legal Practice Council under firm registration 17444.

This guide is general information, not legal advice for your specific matter.