AI in the workplace isn’t something that’s coming in the future.
It’s already here.
Employees are using tools like ChatGPT and other generative AI platforms to draft emails, summarise documents, brainstorm ideas, create reports, prepare meeting notes and generally make their working lives a little easier.
And, used well, AI can be incredibly helpful.
But there’s a question I think more employers need to be asking:
Do your employees actually know what they are – and aren’t – allowed to put into it?
Because there’s quite a difference between asking AI:
“Can you make this email sound friendlier?”
and:
“Can you write a response to Sarah Jones, who’s currently off sick with anxiety, following her grievance against her manager?”
😬
And that’s where things start getting a little more complicated.
The problem isn’t necessarily employees using AI
For most businesses, banning AI altogether probably isn’t the answer.
Employees are already finding ways to use it to save time and make everyday tasks easier. It can help someone get started on a blank page, turn a rambling paragraph into something clearer or provide ideas they might not have thought of.
The issue is when employees are using it without any guidance about what’s appropriate.
If your business hasn’t said anything about AI, an employee might reasonably think:
“Well, everyone uses ChatGPT now, so this must be fine.”
But they may not have thought about what happens to the information they’re putting into the tool.
And that’s particularly important when that information relates to your employees, customers, clients or business.
So, what shouldn’t employees be putting into AI?
This will depend on the AI tool being used, its settings and the safeguards your organisation has in place.
But as a starting point, employees should not simply be copying sensitive or confidential information into an external AI tool without considering whether they’re authorised to do so.
That might include:
- employee personal information;
- sickness or medical information;
- disciplinary or grievance details;
- salary and payroll information;
- customer or client information;
- commercially sensitive information;
- passwords or security information;
- confidential contracts or documents; and
- information your organisation has a contractual obligation to protect.
And don’t forget that personal data doesn’t just mean someone’s name and address.
Even if you remove someone’s name, the information you’re entering could still identify them. So, simply removing names from a prompt doesn’t automatically mean there’s no data protection issue.
“But we’re only using it to help write something…”
This is where it can be easy to underestimate what’s happening.
Imagine a manager has received a lengthy grievance from an employee.
They think:
“I’ll put this into AI and ask it to summarise the key points for me.”
Sounds efficient.
But that grievance might contain names, allegations about colleagues, health information and other sensitive personal information.
By copying it into an AI system, the organisation may be carrying out further processing of that personal data.
The ICO’s position is clear that data protection law applies where AI systems process personal data. Organisations need to think about why that information is being processed, whether they have an appropriate lawful basis and how people’s information is being protected.
That’s why “I was only asking it to summarise it” isn’t really the end of the conversation.
AI can be wrong, too
There’s another important issue.
AI can produce an answer that sounds very convincing.
That doesn’t necessarily make it correct.
If an employee uses AI to research legislation, draft advice, analyse data or produce information for a client, somebody still needs to check the output.
That becomes even more important when the output could influence a decision about another person.
Think recruitment, performance management, disciplinary decisions or redundancy selection.
AI can assist a human.
It shouldn’t become:
“Well, ChatGPT said…”
as the justification for an important workplace decision.
Where AI is used with personal data or to make predictions or recommendations about people, fairness and human oversight become particularly important. The ICO highlights the risk of discriminatory outcomes and the need for safeguards around significant automated decisions.
What about recruitment?
This deserves particular attention.
AI tools can make recruitment quicker. Employers might use them to help write job adverts, develop interview questions or organise information.
But there’s a significant difference between using AI to help you draft six interview questions and asking an AI system:
“Here are 50 CVs. Tell me which five people I should interview.”
If AI is being used to assess candidates or influence employment decisions, employers need to understand how it’s being used, what data is being processed and whether the outcome is fair.
Simply adding a human at the end of a process doesn’t automatically make every AI-assisted decision risk-free.
“We don’t have an AI policy…”
You’re definitely not alone.
For many smaller businesses, AI has arrived much faster than their policies have.
You don’t necessarily need a 25-page Artificial Intelligence Governance Framework before anybody is allowed near ChatGPT.
But you do need some sensible ground rules.
At the very least, employees should understand:
What AI tools can be used?
Can employees use any public AI platform they choose, or only approved systems?
What information can be entered
Be clear about personal, confidential and commercially sensitive information.
What AI can be used for
Drafting? Brainstorming? Research? Recruitment? Employee decisions? Different uses carry very different levels of risk.
That outputs must be checked
AI-generated information shouldn’t automatically be treated as accurate simply because it sounds authoritative.
That humans remain responsible
An employee can’t outsource their judgement or professional responsibilities to AI.
What to do if they’re unsure
Employees need somewhere to ask before putting information into a tool and hoping for the best.
Don’t forget your existing policies
You may not need to start completely from scratch.
AI use can overlap with policies and procedures you already have covering:
- data protection;
- confidentiality;
- information security;
- acceptable IT use;
- recruitment;
- disciplinary and grievance processes; and
- equality and diversity.
So your first step might simply be reviewing what you’ve already got and identifying the gaps.
If your organisation is processing personal data through AI, the ICO expects data protection to be considered from the outset rather than bolted on afterwards.
And managers need to understand the rules too
An AI policy isn’t much use if it’s uploaded to the HR system, everyone clicks “I’ve read this” and nobody ever thinks about it again.
Talk to your employees.
Give them examples.
Fine:
“Give me five ideas for an agenda for a team-building day.”
Potential problem:
“Here’s an employee’s occupational health report. Tell me whether we should dismiss them.”
Those examples make the issue much easier to understand than simply telling people to “use AI responsibly”.
And managers in particular need to know when they should stop and ask for advice. Clear communication with managers about what’s expected is just as important as having the policy itself.
AI in the workplace isn’t the enemy
I use AI. Plenty of businesses do.
And used appropriately, it can be a fantastic tool.
The aim shouldn’t be to frighten employees into never touching it.
It’s about making sure that the enthusiasm to save ten minutes doesn’t accidentally create a data protection, confidentiality or employee-relations problem that takes considerably longer to sort out.
So, if AI is already quietly being used across your workplace, perhaps the question isn’t:
“Should we allow employees to use AI?”
It might be:
“Have we actually told them how to use it properly?”
And if the answer is no, now might be a very good time to start.
Need a hand?
If AI has made its way into your workplace but your HR policies haven’t quite caught up yet, virtuHR can help you put practical guidance in place that works for your business and your employees.
Say Goodbye to HR Hassle – Say Hello to life!