Championing
Wellbeing

AI Policies at Work: Why Your Company Needs One, and Why This Summer Changes Everything

Data and Commercial

Your employees are already using AI. The question is not whether it is happening, but whether you have any say in how. 

From drafting emails to summarising meetings, AI tools have become part of the everyday working day. Most employees are using them without formal guidance, and most employers have no policy in place. For HR professionals, that gap is a legal, reputational, and cultural risk sitting in plain sight, and with key EU AI Act transparency obligations taking effect on 2 August 2026, the urgency for employers to act has never been greater. 

Here is what you need to know. 

The EU AI Act: What You Need to Know Now 

The EU AI Act is the world’s first comprehensive legal framework regulating artificial intelligence, and while the UK is no longer in the EU, the Act’s reach still matters to UK employers and signals the direction of travel, 

If your organisation operates in the EU, serves EU customers, or works with EU-based partners, obligations under the Act may apply to you.  

While the direction of UK regulation remains to be seen, the UK government’s current approach is a lighter touch than the EU model, and UK employers with EU connections should not assume equivalence. 

The following obligations apply from 2 August 2026: 

  • Transparency obligations: employees must be informed when they are interacting with AI systems 
  • Prohibited practices: certain AI applications are banned outright, including systems that manipulate behaviour or exploit vulnerabilities 

It is also worth noting that Article 4 of the EU AI Act, which has applied since 2 February 2025, already requires providers and deployers of AI systems to take reasonable steps to ensure their staff have sufficient AI literacy – meaning a working understanding of what AI is, how it works, and how to use it appropriately. For organisations within scope, training employees on AI is not just good practice; it is already a legal obligation. 

The high-risk AI obligations most directly relevant to HR, covering recruitment, performance management, and people processes, are coming, but on a later timeline. Following the Digital Omnibus agreement reached at EU level earlier this year, these provisions have been deferred, with the new deadline expected in December 2027. The framework itself remains intact and the direction of travel is set. For employers, the deferral is not a reason to wait: it is a window to get ahead. 

The Data Protection Problem 

When an employee pastes client information or personal data into a public AI platform, that data leaves your organisation’s control. Under UK GDPR, your organisation is responsible for how personal data is processed, including via a tool your employee downloaded themselves. 

An AI policy sets out: 

  • Which tools are approved for use 
  • What data must never be inputted to an AI tool 
  • Who is responsible for reviewing AI use in sensitive contexts 

There is a further point that is easy to overlook. Where an AI tool processes personal data on your organisation’s behalf, a Data Processing Agreement should be in place with that provider. Without one, the organisation may be in breach of UK GDPR regardless of how carefully employees are using the tool. Many employers are unaware of this requirement, and checking whether appropriate DPAs are in place is an important early step. 

Without it, you are relying on individuals to make data protection decisions that they may not be equipped to make. Read here for more information on navigating AI and GDPR compliance. 

The Accuracy Risk 

AI does not fact-check. It generates plausible-sounding content and can be wrong with complete confidence. In the workplace, this means contracts drafted with inaccurate clauses, HR correspondence that misstates employee rights, and client-facing materials containing errors that damage credibility. 

Clear guidance on when AI output must be reviewed by a human before use protects both the organisation and the employee. 

The Equality Risk Nobody Is Talking About 

Used carelessly in HR processes, AI can create discrimination risks. AI systems can reflect the biases in their training data, producing outcomes that disadvantage candidates or employees from protected groups. 

Under the Equality Act 2010, it does not matter whether discrimination was intentional. If an AI-assisted process produces discriminatory outcomes, the employer may be liable. This risk is now compounded by the EU AI Act, which specifically identifies AI used in recruitment and people management as high-risk – precisely because of its potential to produce biased outcomes at scale. 

An AI policy should define where AI can and cannot support HR decisions, and how those decisions will be reviewed by a human before action is taken. 

The Disciplinary Grey Zone 

Without a policy, disciplining an employee for AI misuse is legally complicated. If there are no rules, employees can reasonably argue they did not know the behaviour was prohibited. 

A clear AI policy gives HR the foundation to act fairly and consistently, providing employees with the transparent expectations they deserve. 

What a Good AI Policy Covers 

An effective policy is not a blanket ban. It should cover: 

  • Approved tools: which platforms are sanctioned and in what contexts 
  • Data handling: what must never be entered into AI systems 
  • Accuracy: when output must be verified before use 
  • Intellectual property: ownership and disclosure obligations 
  • HR processes: where AI may and may not support decisions 
  • Regulatory compliance: how the policy addresses EU AI Act obligations where relevant 
  • Disciplinary framework: what constitutes misuse 
  • Training: how employees will be supported to use AI responsibly, and for organisations within scope of the EU AI Act, how the Article 4 AI literacy obligation will be met 

Review it regularly, and i and when any regulatory changes are incoming, like now. If you do not currently have an AI policy, now is the time to act. An AI policy is a data protection necessity, an equality safeguard, and increasingly a regulatory requirement. Getting one in place which is properly drafted, clearly communicated, and up to date is one of the most important steps HR professionals can take right now. 

We Are Here to Help 

At Thrive Law, we help organisations draft AI policies that are legally sound and people-first. Get in touch at enquiries@thrivelaw.co.uk, call 0113 869 8101, or explore our blog here for more HR and employment law guidance. 

Contact Us

Contact Form (Generic)
Thrive Law is committed to protecting and respecting your privacy, and we’ll only use your personal information to administer your account and to provide the products and services you requested from us. From time to time, we would like to contact you about our products and services, as well as other content that may be of interest to you. If you consent to us contacting you for this purpose, please tick below to say how you would like us to contact you:
To respond to your enquiry, we need to collect and use your personal data. Please confirm that you have read and understood our Privacy Policy by ticking the box below.

Book a Free Consultation

Our Awards and Recognition

Verified by MonsterInsights