Your Staff Are Using AI at Work. Do You Have a Policy?
Right now, someone in your business is probably pasting client information into ChatGPT.
If that information includes anything personal or commercially sensitive, you could be looking at a UK GDPR breach. And the ICO will not accept that you did not know it was happening.
Most employees are already using AI tools regularly. ChatGPT, Copilot, Gemini, Grammarly, coding assistants. They use them because they are genuinely useful, and because nobody has told them not to. Or told them how.
That gap between everyone using it and nobody having any rules around it is where your risk sits.
The data protection problem
When an employee enters client information or personal details into a third party AI tool, that data may be stored externally.
Some tools use inputs to train their models, meaning confidential business information can end up embedded in a system you can't control or retrieve from.
Under UK GDPR, you are the data controller. You are responsible for how personal data is processed, even when it is your employee doing the processing, through a tool you never authorised.
The quality and reputation risk
AI is confident. It is also frequently wrong.
If someone on your team is using AI to draft client emails or reports without properly reviewing the output, those errors go out under your name.
The client does not know AI wrote it. They just know your business sent them something inaccurate.
The ownership question
If an employee uses AI to produce a piece of work, who owns it?
Your employment contracts almost certainly do not address this. That is fine right up until there is a dispute, at which point it is not fine at all.
The disciplinary gap
If an employee uses AI to write something and passes it off as entirely their own work, what is your position on that?
If you have no policy, you probably have no position. And without a position, taking disciplinary action that would hold up at a tribunal becomes very difficult.
What a proportionate AI policy looks like
You do not need a thirty page document. A clear one-page policy is enough to start with.
It should cover:
- Which AI tools are permitted, and for what types of work
- What data must never be entered into AI tools, including client data, personal data, financial information and anything commercially sensitive
- How AI-generated output should be reviewed before it goes anywhere
- When and how AI use should be disclosed, particularly in client-facing work
- What happens if someone misuses AI or breaches the policy
It is also worth considering how your suppliers and vendors are using AI. Without asking, you could be exposed through your supply chain without ever knowing about it.
This is not about banning AI
A blanket ban is unenforceable. People will use these tools regardless, and pretending otherwise simply pushes the behaviour out of sight where you cannot manage it.
The point is proportionate boundaries. Your team should be able to use AI where it genuinely helps, without putting the business at risk.
How we can help
We can draft a proportionate AI use policy tailored to your business, covering your data protection obligations and giving your team clear, practical guidance on what is acceptable.
If you do not have one yet, now is the time.
๏ปฟ
Get in touch and we will help you put one in place quickly.
๐ 0161 757 7576
๐ง
info@hrtoolbox.co.uk
๐
www.hrtoolbox.co.uk











