RESPONSIBLE ARTIFICIAL INTELLIGENCE (AI) USE POLICY
OPERATIONAL AI GOVERNANCE POLICY FOR: SCEARP ICT (PTY) LTD, ITS SUBSIDIARIES, AND DIVISIONS
- PURPOSE AND POLICY POSITION
1.1 Purpose: Scearp ICT recognises Artificial Intelligence (AI) as a powerful tool for research, development, cybersecurity, productivity, analysis, and problem-solving. The Company uses AI to improve the quality, efficiency, and effectiveness of its work while retaining human responsibility for appropriate decisions, outputs, and services delivered by the Company.
1.2 Assistive Technology: AI is used as an assistive technology and not as a replacement for professional judgement, accountability, competence, or human oversight.
1.3 Scope: This Policy applies to the Company’s use of AI systems and services by its directors, employees, contractors, agents, and authorised representatives in connection with Company operations and client work.
- APPROVED AND PERMITTED AI USE
Scearp ICT may use AI systems and services, including but not limited to ChatGPT, Claude, Gemini, DeepSeek, Qwen, and Google Search AI Mode, for legitimate business purposes including:
- technical research, troubleshooting, analysis, and problem-solving;
- software and website development;
- cybersecurity research, investigation, malware analysis, and threat analysis;
- drafting, editing, and improving business and client communications;
- documentation, summarisation, and knowledge management;
- search, information discovery, and comparative research;
- brainstorming, planning, and development of solutions; and
- other legitimate business and operational purposes.
2.1 Multiple AI Systems: The Company may use multiple AI systems for the same or related tasks where appropriate. Different AI systems may produce different results, and comparison can improve research, validation, and decision-making.
2.2 No Inherent Authority: The Company does not regard the output of any particular AI system as inherently authoritative merely because it is produced by a recognised or widely used AI provider.
- HUMAN VERIFICATION AND ACCOUNTABILITY
3.1 AI Output: AI-generated information, code, recommendations, analysis, and written material may contain errors, omissions, outdated information, fabricated references, security weaknesses, or inappropriate conclusions.
3.2 Verification: Scearp ICT does not automatically accept AI output as accurate or authoritative. Material generated or materially assisted by AI shall be reviewed, tested, validated, or independently verified where appropriate before it is relied upon, deployed, published, or provided to a client.
3.3 Human Responsibility: The person using AI remains responsible for appropriately reviewing and handling the resulting work within their authority and applicable Company procedures.
3.4 No Autonomous Authority: AI does not independently determine Company policy, make contractual commitments, approve client requirements, authorise expenditure, provide final professional advice, or approve material changes to Company or client systems.
- CONFIDENTIALITY, PRIVACY, AND PERSONAL INFORMATION
4.1 Confidential Information: Scearp ICT will not knowingly submit confidential, commercially sensitive, or personal information to an AI service where doing so would be inconsistent with the Company’s contractual, legal, confidentiality, or data-protection obligations.
4.2 Personal Information: Particular care shall be taken with information subject to the Protection of Personal Information Act, 4 of 2013 (POPIA), client confidentiality obligations, credentials, authentication information, financial information, security-sensitive infrastructure information, and proprietary client data.
4.3 Data Minimisation: Where AI is used in connection with client information, the information supplied to the AI system shall be limited to what is reasonably necessary for the task and, where practical, anonymised, minimised, or otherwise sanitised.
4.4 Principle: AI should not receive information merely because it is convenient to provide it.
4.5 Existing Obligations: Nothing in this Policy reduces, replaces, or alters the Company’s existing obligations relating to the protection of Personal Information, confidentiality, or the handling of client information under applicable law or contractual agreements.
- SECURITY AND TECHNICAL USE
5.1 Permitted Security Use: AI may be used to assist with cybersecurity research, malware analysis, code review, system administration, incident investigation, threat intelligence, and related defensive security activities.
5.2 Untrusted Output: AI-generated commands, scripts, code, configurations, or security recommendations shall be treated as untrusted until reviewed and understood by a suitably competent person.
5.3 Production Systems: AI shall not independently make production changes, compromise systems, disclose information, alter security controls, or undertake actions outside the authority of the person operating it.
5.4 Malicious or Unauthorised Activity: AI shall not be used by Scearp ICT to facilitate unlawful access, malicious activity, unauthorised interference, fraud, abuse of third-party systems, or any activity prohibited by the Company’s Terms of Service and Acceptable Use Policy.
5.5 AI-Generated Code: AI-generated code is subject to the same security, licensing, testing, review, and maintenance considerations as code obtained from any other external source.
- INTELLECTUAL PROPERTY, ACCURACY, AND RELIANCE
6.1 Intellectual Property: Scearp ICT remains responsible for ensuring that material it publishes, deploys, or delivers is appropriate for its intended purpose and does not knowingly infringe applicable intellectual-property rights.
6.2 Assisted Material: AI-generated content shall be treated as draft or assisted material unless independently reviewed and approved.
6.3 Authoritative Sources: Where factual accuracy, legal interpretation, technical specifications, security decisions, or other material consequences are involved, appropriate authoritative or primary sources take precedence over AI-generated answers.
6.4 No Blind Reliance: The Company shall not rely solely upon an AI-generated answer where an error could reasonably result in material financial, legal, operational, security, or client consequences.
- CLIENT WORK AND CONTRACTUAL OBLIGATIONS
7.1 Client Projects: AI may assist with client projects where its use is appropriate and consistent with the client’s instructions, contractual obligations, confidentiality requirements, and applicable law.
7.2 Client Requirements: AI does not independently determine client requirements, make contractual commitments, provide final professional advice, or approve changes to client systems.
7.3 Client Restrictions: Where a client expressly requires AI to be excluded from a particular project or information set, Scearp ICT shall respect that requirement, subject to the terms of the applicable agreement.
7.4 Existing Contracts: The Company’s use of AI does not alter the contractual allocation of responsibility, risk, liability, warranties, exclusions, indemnities, limitations, or obligations applicable to any client or service.
- RELATIONSHIP TO EXISTING TERMS AND AGREEMENTS
8.1 Internal Governance: This Policy governs Scearp ICT’s internal use and governance of Artificial Intelligence. It does not amend, replace, override, expand, or limit the Company’s Terms of Service & Acceptable Use Policy, Master Service Agreement, applicable service agreements, quotations, statements of work, Data Processing Agreements, or any other contractual terms applicable to a client or service.
8.2 No Additional Liability: Nothing in this Policy creates any additional warranty, representation, guarantee, service level, duty of care, or liability beyond those expressly undertaken by Scearp ICT under the applicable contractual terms and applicable law.
8.3 Contractual Precedence: In the event of any inconsistency between this Policy and a binding contractual agreement, the applicable contractual agreement and its established order of precedence shall govern.
8.4 Existing Risk Allocation: This Policy does not alter the Company’s existing provisions relating to limitation of liability, indemnification, backups and data responsibility, service availability, security, suspension or termination, acceptable use, data protection, intellectual property, or any other contractual allocation of rights, responsibilities, or risk.
8.5 No Implied Undertaking: No statement contained in this Policy shall be interpreted as an undertaking by Scearp ICT to provide continuous AI monitoring, continuous AI verification, guaranteed AI accuracy, AI certification, or any service or standard not expressly contained in the applicable contractual agreement.
- AI SYSTEMS, RESEARCH, AND GOVERNANCE
9.1 Evolving Technology: AI services may change their models, capabilities, terms, retention practices, privacy controls, security characteristics, or other operational characteristics over time.
9.2 Service Selection: Scearp ICT retains the right to change, restrict, suspend, or discontinue the use of any AI service where its use is considered unsuitable, insecure, unreliable, commercially inappropriate, or inconsistent with the Company’s obligations.
9.3 Ongoing Assessment: The Company may periodically assess the AI services it uses, including their capabilities, limitations, security considerations, privacy practices, and suitability for particular tasks.
9.4 Competency: The Company recognises that responsible AI use requires continuing development of internal knowledge and competencies. AI tools shall therefore be treated as evolving technologies requiring continuing assessment rather than as fixed or infallible sources of information.
- AI AUDIT, TRANSPARENCY, AND CONTINUOUS IMPROVEMENT
10.1 Voluntary External Audits: Scearp ICT may, from time to time and on a voluntary basis, submit aspects of its AI practices to independent audits or assessments conducted by external third parties that the Company reasonably considers to be credible, competent, and appropriately qualified AI audit or assurance providers.
10.2 Purpose of Audits: The purpose of such audits is not simply to demonstrate compliance. Audits are intended to strengthen our internal competencies, identify weaknesses or areas for improvement, and hold us accountable to the principles and controls established by this Policy.
10.3 Scope: An audit may examine the Company’s use of AI, human oversight, data protection, confidentiality, security, verification practices, transparency, governance, and other matters relevant to responsible AI use.
10.4 Improvement: The findings of an audit may result in changes to the Company’s processes, controls, practices, training, or this Policy. Scearp ICT considers such changes to be a positive outcome of responsible governance.
10.5 Evolution: AI is evolving rapidly, and our understanding, capabilities, and governance must evolve with it.
10.6 Transparency: Where appropriate, Scearp ICT may communicate material findings or outcomes of an audit, subject to legitimate confidentiality, security, legal, contractual, and commercial considerations.
10.7 No Implied Certification: A voluntary audit or assessment does not constitute certification, accreditation, endorsement, or compliance assurance unless the relevant auditor expressly provides such certification, accreditation, endorsement, or assurance.
- OUR POSITION
Scearp ICT believes responsible AI use means **using the technology where it creates genuine value, while remaining accountable for what we trust it to do.**
We do not believe that responsible AI is achieved by simply declaring that AI is being used responsibly. It requires appropriate controls, human oversight, verification, transparency, and a willingness to have those practices independently examined.
AI may accelerate our work. **It does not assume our responsibility.**
Every decision remains ours.
Every client deliverable remains ours.
Every system we deploy remains our responsibility.
Version Control
Version: AI 1.0
Effective Date: 01 September 2026
Legal Pages Archive: https://scearpcommunications.co.za/legal-pages-archive/

