Curriculum / Module 07
professional2 hours4 lessonsTimed assessment

GenAI Without Leaks

Data governance, personal information and POPIA

This module covers how to use generative AI productively without disclosing the personal information that regulation protects. It sets out the four routes by which information escapes: prompts, outputs, memorisation and training reuse. It then covers the controls that address each route, namely the difference between consumer and enterprise tools, safe prompting and redaction discipline, and the POPIA mapping across security safeguards, the operator relationship, automated decisions and cross-border transfers. The practical result is a workflow that allows an adviser to use AI on a client report lawfully.

Create an accountBack to curriculum

By the end of this module, you can
  • Explain the mechanisms by which personal information leaks into and out of generative-AI systems.
  • Choose and configure tools, and write prompts, so that client and personal data is not exposed or transferred unlawfully.
  • Apply POPIA sections 19, 71 and 72 and the operator concept to a real generative-AI workflow, including cross-border processing.
Skills taught
  • Data-leakage threat modelling
  • Consumer-versus-enterprise tool evaluation
  • Safe prompting and redaction discipline
  • POPIA operator and transborder analysis

Lessons in this module

L1
How information actually leaks: four routes out
Explain the four leakage mechanisms, namely prompt disclosure, output disclosure, memorisation and training reuse, and cite the research that established each of them.
30 min
L2
Consumer versus enterprise: the tool decision and what turns on it
Evaluate a generative-AI tool for institutional use against the questions that decide the outcome, namely retention, training, processing location, contract and controls, and explain why the difference between consumer and enterprise tools is a legal boundary rather than a pricing tier.
30 min
L3
Safe prompting and redaction: the adviser's client-report workflow
Apply minimisation, redaction and structure disciplines to prompts so that generative tools remain fully productive on client work without exposing personal information, and carry out the module's main workflow, the AI-assisted client report.
30 min
L4
The POPIA map: sections 19, 20 to 22, 71 and 72 over one workflow
Apply POPIA's security-safeguard, operator, breach-notification, automated-decision and transborder provisions to a generative-AI workflow, and produce the compliance record that evidences it.
30 min
Case 07.1
Case file: The report that wrote itself
An applied fact pattern worked against a model resolution, followed by the timed assessment (30 minutes, pass mark 70 percent).
20 min

How it lands across the four desks

Wealth & Advisory

Client financial data is precisely the kind of information that a careless prompt exposes, so this desk carries a high level of risk. The module gives you a workflow for producing a client report at the speed AI assistance allows, without disclosing personal information that the task never required.

Compliance & Risk

You set the policy: the tool approval criteria, the operator-contract checklist, the transborder analysis, and the response when a disclosure happens anyway. The module supplies a usable version of each of those documents.

Fraud & AML

Case data is among the most sensitive information the institution holds, including alert narratives, suspicion assessments and subject identities. You learn which of it may never leave the approved environment, and the legal reasons why.

Credit & Underwriting

Application files contain a large volume of personal information. You learn safe-use patterns for AI-assisted underwriting work, and the leakage routes by which a drafting shortcut can become a security compromise that the institution must assess for notification.

Key literature · 7 sources

Every module rests on a verified scholarly and institutional evidence base. The full core and further reading lists open with the module.

  • Carlini, N. et al. (2021) 'Extracting Training Data from Large Language Models.' USENIX Security 2021: verbatim training-data extraction demonstrated.
  • Carlini, N. et al. (2019) 'The Secret Sharer: Evaluating and Testing Unintended Memorization in Neural Networks.' USENIX Security 2019: memorisation of rare secrets established.
  • Shokri, R. et al. (2017) 'Membership Inference Attacks Against Machine Learning Models.' IEEE S&P 2017: presence-in-training-data as leakable information.
  • OWASP GenAI Security Project (2025) 'OWASP Top 10 for LLM Applications': the sensitive-information-disclosure and related risk catalogue.
  • NIST (2024) 'AI RMF: Generative AI Profile' (AI 600-1): data privacy as a cross-cutting generative-AI risk, with control framing.
  • Protection of Personal Information Act 4 of 2013, ss 19, 20:22, 71, 72: read in full against this module's workflow mapping.
Create an account