Artificial intelligence tools such as ChatGPT and Microsoft Copilot are becoming part of everyday work. Employees may be using them to draft emails, summarise documents, prepare reports, review applications or create marketing content.
These tools can save time, but they also create risks around privacy, confidentiality, accuracy, employment decisions and copyright.
The key point for employers is that using AI does not remove their responsibility for the information entered into a tool, the work it produces or the decisions made with its assistance.
A business does not need to have formally introduced AI for employees to be using it.
Before creating rules, employers should understand:
An open discussion with employees can help identify where AI is already being used and where clearer boundaries may be needed.
One of the biggest risks is employees copying information into an AI tool without considering where it may be stored or how it may be used.
Employees should generally avoid entering:
Employers should check the terms of any approved AI tools, including whether prompts are retained, used for training or transferred overseas.
Removing a person’s name may not always be enough if the remaining details could still identify them.
AI-generated content can sound convincing while still being inaccurate, incomplete or outdated.
This creates particular risk when it is used to prepare:
AI output should be treated as a draft rather than a finished product.
The level of review should match the level of risk. A suggested social media caption may need a light check, while a disciplinary letter or client report requires careful review by someone with the right knowledge and authority.
AI may be used to compare CVs, rank applicants, draft performance feedback or analyse employee information.
However, an employer should not rely on an AI system to make the final decision.
AI tools may reflect bias in their data or place too much weight on irrelevant information. Employers still need to ensure decisions are fair, based on accurate information and free from unlawful discrimination.
Where AI is used in recruitment or employee management, employers should understand:
AI can assist with administrative work, but meaningful human judgement must remain part of the process.
Businesses should not assume that AI-generated writing, images or designs are automatically original or safe to use.
Before publishing or using AI-generated work commercially, consider:
The law in this area is still developing, so caution is sensible where AI-generated material will be widely published or used for commercial purposes.
A workplace AI policy should be clear and practical. It may include:
The policy should be easy to find, understood by employees and reviewed as new tools are introduced.
AI can help employees work more efficiently, but it should not replace judgement, accountability or a fair process.
Employers who set clear expectations now will be better placed to use these tools productively while reducing the risk of privacy breaches, employment disputes and intellectual property issues.
McVeagh Fleming can assist employers with workplace AI policies, privacy obligations, employment processes, confidentiality requirements and intellectual property concerns.
Getting the right framework in place can help employees use AI confidently while making it clear where human review and approval are still required.

Artificial intelligence tools such as ChatGPT and Microsoft Copilot are becoming part of everyday work. Employees may be using them to draft emails, summarise documents, prepare reports, review applications or create marketing content.
These tools can save time, but they also create risks around privacy, confidentiality, accuracy, employment decisions and copyright.
The key point for employers is that using AI does not remove their responsibility for the information entered into a tool, the work it produces or the decisions made with its assistance.
A business does not need to have formally introduced AI for employees to be using it.
Before creating rules, employers should understand:
An open discussion with employees can help identify where AI is already being used and where clearer boundaries may be needed.
One of the biggest risks is employees copying information into an AI tool without considering where it may be stored or how it may be used.
Employees should generally avoid entering:
Employers should check the terms of any approved AI tools, including whether prompts are retained, used for training or transferred overseas.
Removing a person’s name may not always be enough if the remaining details could still identify them.
AI-generated content can sound convincing while still being inaccurate, incomplete or outdated.
This creates particular risk when it is used to prepare:
AI output should be treated as a draft rather than a finished product.
The level of review should match the level of risk. A suggested social media caption may need a light check, while a disciplinary letter or client report requires careful review by someone with the right knowledge and authority.
AI may be used to compare CVs, rank applicants, draft performance feedback or analyse employee information.
However, an employer should not rely on an AI system to make the final decision.
AI tools may reflect bias in their data or place too much weight on irrelevant information. Employers still need to ensure decisions are fair, based on accurate information and free from unlawful discrimination.
Where AI is used in recruitment or employee management, employers should understand:
AI can assist with administrative work, but meaningful human judgement must remain part of the process.
Businesses should not assume that AI-generated writing, images or designs are automatically original or safe to use.
Before publishing or using AI-generated work commercially, consider:
The law in this area is still developing, so caution is sensible where AI-generated material will be widely published or used for commercial purposes.
A workplace AI policy should be clear and practical. It may include:
The policy should be easy to find, understood by employees and reviewed as new tools are introduced.
AI can help employees work more efficiently, but it should not replace judgement, accountability or a fair process.
Employers who set clear expectations now will be better placed to use these tools productively while reducing the risk of privacy breaches, employment disputes and intellectual property issues.
McVeagh Fleming can assist employers with workplace AI policies, privacy obligations, employment processes, confidentiality requirements and intellectual property concerns.
Getting the right framework in place can help employees use AI confidently while making it clear where human review and approval are still required.