General-purpose AI tools such as ChatGPT, Microsoft 365 Copilot, Google Gemini, and Claude can help HR teams write faster and reduce repetitive administrative tasks. They can produce a first draft of a job description, restructure a policy, translate employee communications or turn meeting notes into a clearer summary.
The risk begins when HR asks these AI tools to make, validate or justify a decision that could affect someone’s employment.
- “Can I dismiss this employee?”
- “Is this redundancy process legal?”
- “Should I reject this candidate?”
- “Can we monitor employees through their phones?”
These questions look straightforward, but in practice, the right response can depend on employment status, jurisdiction, contractual terms, company policy, previous decisions, protected characteristics, collective agreements and facts that have not yet been established.
A generic AI assistant doesn't automatically know any of that. It might produce an answer that sounds confident while relying on incomplete assumptions. It could draft a letter before an investigation has finished, confuse British and Irish employment rules or recommend a process that conflicts with the organisation’s own policy.
The problem isn't that HR teams use AI. The problem is using AI without organisational context, approved sources, clear data controls and meaningful human oversight.
Shortcuts
Can HR Teams Use ChatGPT Safely?
Yes, but only for suitable tasks and with appropriate controls.
HR teams must also recognise the limitations of general-purpose AI tools that don't automatically understand your organisation, your policies, your employees, or your established HR processes. They only know the information provided in the prompt and might produce confident answers without the context needed to apply them safely.
AI tools like ChatGPT can support:
- Drafting and rewriting
- Summarising approved information
- Translating employee communications
- Organising meeting notes
- Preparing questions
- Identifying missing information
They shouldn't independently decide:
- Who should be hired
- Who should be promoted
- Whether someone should receive a warning
- Who should be selected for redundancy
- Whether absence is acceptable
- Whether an employee should be dismissed
- How someone’s pay or performance rating should change
The greater the potential effect on a person’s employment, the more important organisational context, approved sources, human oversight and clear accountability become.
In reality, HR leaders aren't deciding whether AI will enter the workplace, because in many organisations, it's already there. Recruiters use it to prepare job adverts. Managers use it to draft feedback. Employees enter workplace questions into public chatbots. HR teams use writing tools to create letters, policies and internal communications.
Acas research published in 2025 found that 35% of employers considered increased productivity the most important potential benefit of workplace AI. However, 26% of workers said job losses were their biggest concern. Others were worried about errors, data protection and limited regulation.
HR therefore has two connected responsibilities:
-
It needs to help the organisation benefit from AI.
-
It must also protect candidates and employees from unfair, inaccurate or poorly governed uses of the technology.
That requires more than a list of approved tools, it needs HR leaders to decide:
- Which tasks AI can support
- Which information it should access
- Which decisions require human judgement
- Who remains accountable for an output
- How employees can question an AI-assisted decision
What laws apply to AI in HR?
There's no single employment law that covers every workplace use of AI. The legal position depends on where the organisation operates, what the system does, what data it uses and how much influence it has over the final decision.
AI in HR in Great Britain
British employers need to consider data protection, equality, employment, consultation and health and safety law. The Data (Use and Access) Act 2025 changed the UK framework for automated decision-making. Most of its data protection provisions came into force on 5 February 2026.
The new framework permits solely automated significant decisions in a wider range of circumstances. However, safeguards still apply.
Where a decision is made solely through automated processing and has a legal or similarly significant effect, the organisation must:
- Tell the individual about the decision
- Allow them to make representations
- Give them a way to challenge it
- Allow them to request human intervention
Stronger restrictions continue to apply when special-category data is involved.
A decision isn't necessarily solely automated because AI contributed to it. The key question is whether there was meaningful human involvement.
A manager who simply approves the system’s recommendation without reviewing the evidence might not provide meaningful human oversight. A genuine reviewer must understand the information, consider the circumstances and have the authority to disagree.
The ICO (Information Commissioner’s Office) made automated recruitment a regulatory focus during 2025 and 2026.
Its March 2026 report found that many employers could be making solely automated recruitment decisions without applying the required safeguards. It called for clearer candidate information, consistent human involvement and better monitoring for bias and unfair outcomes.
The ICO’s updated automated decision-making guidance is still being finalised and is expected during winter 2026. HR teams should review their processes again when the final version is published.
Northern Ireland Requires Separate Checks
The UK doesn't operate as one employment law jurisdiction. Many references to Acas and the Equality Act 2010 in this article apply to England, Scotland and Wales.
Northern Ireland has separate employment and equality legislation. Employers operating there should check guidance from the Labour Relations Agency and the relevant Northern Ireland authorities before relying on a British process or template.
AI in HR in Ireland
Irish employers should consider Irish employment and equality law, GDPR and the EU AI Act.
The EU AI Act classes certain systems used for recruitment, candidate selection, promotion, termination, task allocation and worker monitoring as high-risk.
The main high-risk requirements for employment-related systems listed in Annex III are now scheduled to apply from 2 December 2027. This date was introduced by Regulation (EU) 2026/1744, which amended the original implementation timetable.
The extended date doesn't mean Irish employers should delay preparation. Other AI Act duties already apply.
AI Literacy is Already an Obligation
The EU AI Act requires providers and deployers of AI systems to take measures that support AI literacy among the people operating those systems on their behalf. The obligation has applied since 2 February 2025. National supervision and enforcement began in August 2026.
For HR teams, AI literacy should cover:
- Approved and prohibited AI uses
- Personal and special-category data
- Bias and discrimination risks
- Checking generated facts and legal references
- Recognising missing information
- Required human review
- Reporting AI errors or incidents
A generic annual training module will not be enough for every user. A recruiter using AI to review job applications needs different knowledge from a manager using it to draft an employee letter.
Workplace Emotion Recognition is Prohibited in the EU
Since 2 February 2025, the EU AI Act has prohibited AI systems used to infer emotions in workplaces, except for limited medical or safety purposes.
This could affect systems that claim to determine engagement, confidence, stress, enthusiasm, honesty or emotional state using biometric information such as facial expressions or voice patterns.
Irish employers should treat tools that claim to analyse a candidate’s personality, emotions or trustworthiness from video or audio with particular caution.
A Plausible Answer Is Not the Same as a Correct Answer
Generative AI produces responses based on patterns in data and the information included in the prompt. It doesn't automatically verify that every legal statement, policy reference or procedural recommendation is correct.
It might fill information gaps with assumptions instead of clearly stating that essential facts are missing.
The Workplace Relations Commission addressed this risk in its May 2026 guidance for parties using AI to prepare WRC submissions and evidence. It warned that users remain responsible for checking legal authorities, quotations and factual claims. The guidance also warns that public tools may retain or reuse personal and commercially sensitive information.
That warning has particular relevance for HR.
-
A fictional case reference in a general document is embarrassing.
-
An invented legal principle in a dismissal, redundancy or discrimination process could influence a decision with serious consequences for the employee and employer.
Even a legally accurate response may still be wrong for the organisation, as a generic answer won't reflect:
- The employee’s contract or employment status
- The organisation’s approved policies
- Previous warnings, meetings or adjustments
- Relevant collective agreements
- Differences between British, Northern Irish and Irish law
- Sector-specific requirements
- The user’s authority to access or act on information
- Legal changes introduced after the model’s source information was created
HR leaders should treat general-purpose AI as a drafting and thinking tool, not an independent source of employment advice.
Sensitive HR Data Shouldn't Enter an Uncontrolled Prompt
The risk can begin before the AI produces an answer. An HR professional might enter an employee’s name, medical condition, disciplinary history, salary, home address or grievance allegation while asking a public tool to draft a document.
That can create data protection, confidentiality and security risks.
The Irish Data Protection Commission advises organisations to understand:
- What personal data an AI product uses
- Where the information goes
- Whether the supplier retains it
- Whether it is reused for training
- How data subject rights can be supported
- What security risks the product introduces
It also warns that AI products can produce inaccurate or biased outputs and create automated decision-making risks where organisations rely on them without critical human review.
The ICO takes a similar position.
Employers shouldn't assume that purchased technology is compliant. They need to establish the purpose, lawful basis, necessity and proportionality of the processing, while considering whether a less intrusive method could achieve the same objective.
This doesn't mean HR teams can never use AI with workforce information. It means the technology needs:
- Appropriate contracts
- Defined purposes
- Security controls
- Role-based permissions
- Data minimisation
- Retention rules
- Human review
- Clear accountability
A manager shouldn't need to copy an employee’s complete case history into a public chatbot to understand the next stage of an HR process.
The Risk Increases With the Consequence
Not every AI prompt carries the same level of risk. Asking AI to shorten an approved employee announcement is very different from asking it to decide who should be made redundant.
A useful way to assess risk is to consider whether the AI affects presentation, process or outcome.
Presentation Tasks
These include rewriting, formatting, summarising and translating approved material. The content still needs checking, but the AI isn't deciding what should happen.
Process-support Tasks
These include finding a policy, identifying missing information, preparing questions or structuring a meeting.
AI can assist, but the user must check the source and apply the correct process.
Outcome-driven Tasks
These ask AI to recommend, justify or make an employment decision. They carry the highest risk because they may affect:
- Recruitment
- Pay
- Progression
- Shift allocation
- Performance ratings
- Discipline
- Redundancy
- Continued employment
The following 30 prompts all enter areas where organisational context and human judgement matter. They shouldn't be entered into a generic AI tool and acted upon without proper review.
Recruitment and Hiring Prompts That Can Create Bias
Recruitment decisions involve personal data, protected characteristics and significant consequences for candidates. AI can help recruiters prepare materials and organise information, but it shouldn't create discriminatory criteria or make unexplained assumptions about someone’s suitability.
1. “Write interview questions for a woman returning from maternity leave”
This directs attention towards sex and maternity rather than the candidate’s ability to perform the role. The output could introduce inappropriate questions about childcare, future pregnancy, family commitments or likely attendance.
Use the same structured, competency-based questions for each candidate applying for the role. Any questions about availability should relate directly to the genuine requirements of the role and should be asked consistently.
2. “Can I reject a candidate because they might need visa sponsorship?”
This prompt risks confusing the organisation’s sponsorship position with the candidate’s nationality, race or ethnic origin. HR should first establish:
- The role’s requirements
- The candidate’s current right-to-work position
- Whether sponsorship is available
- The organisation’s approved sponsorship policy
- Whether the same criteria are applied to all candidates
AI should never infer immigration status from a name, accent, home address, university or nationality.
3. “Write a job advert targeting young, energetic workers”
Words such as “young” indicate that candidates from a particular age group may be preferred. Other apparently neutral terms can also discourage qualified candidates. The advert should describe:
- Required skills
- Relevant experience
- Working conditions
- Physical requirements that are genuinely necessary
- Expected outcomes
It shouldn't describe the assumed age or personality of the preferred applicant. Acas advises employers to use inclusive language that defines the job rather than the type of person they imagine performing it.
4. “Create a scoring system to filter out overqualified candidates”
“Overqualified” can become a vague substitute for assumptions about age, salary expectations, commitment or retention. An unexplained scoring system could penalise candidates for experience that has no negative effect on their ability to perform the job.
HR should define objective requirements before reviewing applications and record why each criterion is relevant. The scoring model should then be tested to check whether it produces unfair outcomes.
5. “How do I avoid hiring someone with a history of sickness absence?”
This prompt starts with the intended outcome of excluding the candidate. It can create disability discrimination and health-data risks. In Great Britain, employers must not normally ask an applicant about health or disability during the application or interview process unless a specific exception applies.
The right question is whether the person can perform the role, with reasonable adjustments where required.
Employee Relations Prompts that Assume the Outcome
Employee relations cases rarely begin with a complete and uncontested set of facts. AI can help organise evidence or prepare a document once the correct stage has been reached.
It shouldn't decide the outcome before a fair process has taken place.
6. “Write a disciplinary outcome letter for gross misconduct”
The prompt assumes gross misconduct has already been established. A generic letter could miss:
- The allegations considered
- Evidence reviewed
- The employee’s response
- The decision rationale
- Mitigating circumstances
- The right of appeal
- The organisation’s own procedure
AI should only prepare a first draft after the decision-maker has completed the process and confirmed the outcome. In Great Britain, the Acas Code sets the minimum standard employers should follow when handling disciplinary and grievance matters.
7. “Can I dismiss an employee for having a poor attitude?”
“Poor attitude” is subjective. It could refer to:
- Conduct
- Performance
- Communication style
- A workplace disagreement
- A protected disclosure
- Behaviour connected with a disability
- A response to bullying or discrimination
HR should define the specific behaviour, expected standard, evidence and impact before deciding which process applies. The system shouldn't convert a manager’s personal impression into a formal employment decision.
8. “How do I dismiss an employee quickly with minimal risk?”
This asks AI to help reach a predetermined outcome rather than identify a fair process. The correct route may depend on:
- The reason for dismissal
- Available evidence
- Employment status
- Length of service
- Contractual terms
- Protected rights
- Previous action
- Internal policy
- Jurisdiction
Speed shouldn't replace investigation, consultation or the employee’s opportunity to respond.
9. “Write a redundancy script for a group consultation meeting”
A script cannot make a predetermined redundancy exercise meaningful. Collective and individual consultation requirements depend on the number of proposed dismissals, the affected establishment and the jurisdiction.
Selection criteria should also avoid direct and indirect discrimination. AI may help structure a communication after the organisation has established the correct process, but it shouldn't design the redundancy exercise from a one-line prompt.
10. “Can I fire someone for being off sick too often?”
Frequency alone doesn't determine whether dismissal is fair. HR needs to consider:
- The reasons for absence
- Medical evidence
- Disability
- Reasonable adjustments
- Occupational health advice
- Pregnancy-related absence
- Alternative duties
- Return-to-work support
- The impact on the organisation
The absence record could begin a review but doesn't automatically determine the outcome.
Pay, Holiday and Working-time Prompts That Oversimplify the Rules
Pay and working-time questions often depend on legislation, contracts, actual hours and payroll records. A short AI answer can miss a detail that changes the result.
11. “Do I legally have to pay employees for overtime?”
There is no useful universal answer. The position can depend on:
- The employment contract
- A collective agreement
- Normal pay
- Total hours worked
- National Minimum Wage compliance
- Working-time requirements
- Custom and practice
HR and payroll should review the actual pay arrangement instead of relying on a general statement about overtime.
12. “Can employees skip rest breaks if they agree to it?”
Agreement doesn't automatically remove statutory working-time protections. Different rules and exceptions may apply depending on:
- The type of work
- The worker’s age
- Shift length
- Sector requirements
- Compensatory rest arrangements
- The relevant jurisdiction
The organisation should compare the proposed arrangement with its legal duties and working-time policy.
13. “Calculate holiday entitlement for a zero-hours worker”
AI cannot calculate an accurate entitlement without the correct information. It may need:
- The applicable jurisdiction
- The leave year
- The pay period
- Hours worked
- Employment status
- Contractual entitlement
- Start or termination date
- Previous leave taken
For leave years beginning on or after 1 April 2024, British irregular-hours and part-year workers generally accrue statutory holiday at 12.07% of hours worked in each pay period, subject to the relevant rules and maximum entitlement. Government guidance and the official calculator should be used where appropriate.
14. “How do I avoid paying holiday pay on overtime?”
The wording asks for a way around an employment right. Holiday pay may need to include payments that form part of normal remuneration. The correct calculation depends on the worker’s hours, pay pattern, leave entitlement and jurisdiction.
A safer task is to identify which earnings must be included and test the payroll configuration against current rules.
15. “Can I change employee shifts without notice?”
The answer can depend on:
- The contract
- Rota policy
- Collective arrangements
- Established working practices
- The amount of notice given
- The reason for the change
- The impact on individual employees
- Discrimination or reasonable-adjustment considerations
A contractual power to vary shifts doesn't mean every change will be reasonable or free from employee relations risk. HR software should record the original schedule, change, notice, communication and approval.
Policy Prompts That Create False Confidence
A policy can look complete while remaining legally weak, inconsistent with contracts or difficult for managers to apply. AI can help prepare and adapt content but it can't certify a complete policy framework from a one-line instruction.
16. “Write a fully compliant employee handbook for my business”
No generic prompt contains enough information to do this safely. The AI would need to understand:
- Jurisdiction
- Contracts
- Workforce structure
- Benefits
- Working patterns
- Collective arrangements
- Sector requirements
- Existing procedures
- Current legislation
- Planned legal changes
A handbook should be built from approved policies, reviewed as a connected set and supported by a formal update process. Avoid presenting AI-generated wording as legally compliant because it looks professional.
17. “Create a GDPR policy for employee monitoring”
Employee monitoring requires more than inserting the words “GDPR compliant” into a document. The organisation must establish:
- A clear purpose
- A lawful basis
- Necessity
- Proportionality
- Transparency
- Data minimisation
- Retention
- Access controls
- Security
- Whether a DPIA is required
The ICO advises employers to choose the least intrusive method capable of meeting the identified purpose. It also warns organisations not to assume that a monitoring product purchased from a supplier is compliant.
18. “Write a social media policy allowing us to monitor employee accounts”
The organisation cannot make monitoring proportionate simply by placing it in a policy. HR leaders need to distinguish between public conduct that genuinely affects the employment relationship and unnecessary observation of an employee’s private life. The organisation should explain:
- What it monitors
- Why it monitors it
- What information it collects
- How long it retains the information
- Who may access it
- How it may be used
It must also consider whether a less intrusive approach would achieve the same purpose.
19. “Generate a sickness policy that reduces absence”
The objective of a sickness policy shouldn't be to discourage legitimate absence. A suitable policy should:
- Define reporting expectations
- Provide consistent review points
- Support attendance
- Address return-to-work arrangements
- Recognise disability
- Recognise pregnancy-related absence
- Consider reasonable adjustments
- Allow managers to examine individual circumstances
A target written without those controls could encourage managers to prioritise absence figures over fair treatment.
20. “Can we stop employees discussing their salaries?”
A blanket ban creates legal and cultural risks. In Great Britain, pay-secrecy clauses are unenforceable where a pay discussion seeks to establish whether differences relate to a protected characteristic.
Even where a particular discussion falls outside that protection, preventing employees from talking about pay can reduce trust and make inequality harder to identify.
HR should address genuine confidentiality and personal-data concerns without presenting all pay conversations as misconduct.
Performance Prompts That Turn Management Into An Exit Strategy
Performance management should set clear expectations, identify barriers and give employees a fair opportunity to improve. Prompts designed to manufacture an exit undermine that purpose.
21. “Write a performance warning for someone who is struggling mentally”
This wording reduces a potentially complex health and capability issue to a warning. Mental health information may be special-category data.
The employee may also meet the legal definition of disability. HR should first establish:
- What is happening
- Whether the employee has disclosed a health condition
- What support may be needed
- Whether adjustments are reasonable
- Whether occupational health input is appropriate
- Whether performance expectations remain fair
The system shouldn't infer a diagnosis or determine that formal action is required.
22. “Create a PIP designed to encourage an employee to resign”
A performance improvement plan should provide a genuine opportunity to improve. Designing it to force a resignation will undermine trust and confidence and create legal risk. A suitable PIP should contain:
- Specific performance gaps
- Evidence
- Clear expectations
- Support and resources
- Measurable objectives
- Reasonable timescales
- Review dates
- Potential outcomes
AI shouldn't disguise a predetermined exit as a development process.
23. “How do I manage out an underperforming employee?”
“Managing out” begins with the assumption that the employment relationship should end. The better question is: What is causing the performance gap, and what fair support or process is required?
The answer may involve clearer objectives, training, resources, supervision, workload changes, reasonable adjustments or a formal capability process. AI can help structure those questions but it shouldn't be used to decide that dismissal is the correct destination.
24. “Write feedback for an employee I personally dislike”
AI can polish biased feedback as easily as fair feedback. It might make a personal judgement sound formal without improving its accuracy. Managers should provide:
- Specific examples
- Dates or situations
- The expected standard
- The effect of the behaviour
- Previous feedback
- The required improvement
HR should challenge wording that reflects personality conflict rather than evidence about conduct or performance.
25. “Should I lower someone’s rating because they took a lot of sick leave?”
Attendance and performance aren't automatically the same measure. Reducing a rating because of disability-related, pregnancy-related or other protected absence may create discrimination risks. It could also penalise an employee for leave that the organisation authorised.
Performance reviews should assess agreed outcomes and behaviours the employee could reasonably control. Any attendance concern should be managed through the appropriate process.
Monitoring and Process Prompts That Ignore Organisational Context
AI often answers monitoring and procedural questions at a general level. HR leaders need to understand how the proposal works in practice, who it affects, and whether it matches existing controls.
26. “Write a return-to-work process for injured employees”
The correct process could involve:
- Health and safety duties
- Occupational health
- Medical evidence
- Insurance
- Rehabilitation
- Reasonable adjustments
- Alternative duties
- Role-specific risk assessments
A warehouse employee returning after a physical injury might need a different assessment from an office employee returning to desk-based work. The process should connect the employee’s circumstances with the organisation’s actual roles and safety procedures.
27. “Can I track employees through GPS on their phones?”
The answer depends on the purpose and design of the monitoring. Tracking attendance at a worksite during paid hours is different from following an employee’s location outside work. Employers need to consider:
- Necessity
- Proportionality
- Transparency
- Lawful basis
- Data retention
- Device ownership
- Access permissions
- Whether a less intrusive method is available
Permission settings should prevent managers from viewing location information they don't need. The ICO recommends completing a DPIA where required and considering employee or representative views when assessing monitoring risks.
28. “Use this video interview to assess whether the candidate seems confident and trustworthy”
This asks AI to infer personality, emotional state or trustworthiness from video or audio. The output may reflect unreliable assumptions about facial expressions, voice, disability, culture, language, age or neurodiversity.
In Ireland and the wider EU, AI systems used to infer emotions in workplaces are prohibited except for limited medical or safety purposes. Candidate assessment should focus on structured evidence relevant to the role.
29. “Write a probation failure letter”
Probation doesn't remove the need for an accurate and defensible decision. The organisation must consider:
- The contract
- Length of probation
- Review history
- Feedback given
- Support provided
- Extensions
- Notice
- Discrimination risks
- Protected rights
- The confirmed outcome
AI could draft a letter after HR has verified the facts and approved the decision but it shouldn't infer that probation failure is appropriate from limited information.
30. “What is the minimum HR process legally required before termination?”
There is rarely one minimum process that applies to every termination. The correct route depends on:
- Jurisdiction
- Reason
- Employment status
- Length of service
- Contract
- Protected rights
- Prior steps
- Internal policy
- Collective arrangements
- Applicable codes of practice
The responsible approach is to classify the proposed termination, identify the relevant process and verify the facts before any decision is made.
A Practical AI Governance Checklist For HR
An AI policy alone will not provide enough control. HR teams need a repeatable governance process covering every AI tool and use case.
1. Create an AI register
Record every AI system used in:
- Recruitment
- Onboarding
- Scheduling
- Attendance
- Payroll
- Performance
- Monitoring
- Employee relations
- Learning and development
- Workforce analytics
Include the supplier, purpose, data used, responsible owner and risk classification.
2. Classify the use case
Decide whether the system supports:
- Presentation
- Process
- Recommendations
- Decisions
- Monitoring
- Profiling
Outcome-driven and monitoring uses require stronger assessment and controls.
3. Approve tools before use
Employees should know which tools they may use and which information they may enter.
The policy should address:
- Public AI tools
- Enterprise AI accounts
- AI built into HR software
- Browser and writing assistants
- Meeting transcription tools
- Recruitment and assessment systems
- Manager-led experimentation
4. Complete a DPIA where required
A data protection impact assessment may be required where AI involves systematic monitoring, profiling, biometric information, health information or new technology presenting a high risk to individuals.
The assessment should happen before deployment, not after a complaint.
5. Check the supplier
The organisation remains responsible for its own use of the product. They should ask:
- What information does the system collect?
- Where is it stored?
- Is it used to train the model?
- How long is it retained?
- Which subcontractors receive it?
- Are international transfers involved?
- Can information be deleted?
- How does the supplier test accuracy and bias?
- What happens when the model changes?
- How are incidents reported?
6. Tell candidates and employees how AI is used
Privacy notices and process communications should explain where AI is used, what the system does, what information it considers, whether a human reviews the result, how someone can correct information, and how they can question or challenge a decision.
For high-risk systems deployed in EU workplaces, the AI Act will also require affected workers and their representatives to be informed before deployment when the relevant provisions apply.
7. Test for bias and accuracy
Testing should happen:
- Before launch
- After material changes
- At regular intervals
- When concerns arise
Compare results across relevant groups and investigate unexplained differences. Don't assume that removing names from an application removes every source of bias.
8. Define meaningful human oversight
Name the person responsible for reviewing the output. They must:
- Understand the system’s purpose and limitations
- Access the relevant evidence
- Consider individual circumstances
- Recognise potential discrimination
- Question the recommendation
- Have authority to reject it
Human involvement shouldn't consist of approving whatever the system produces.
9. Provide role-specific AI literacy training
Recruiters, managers, HR teams, payroll teams and system administrators need different training. Training should use realistic workplace examples and explain what the user must do when the system is wrong.
10. Keep an audit trail
The audit trail should show that the human decision-maker considered the evidence rather than simply accepting the AI response. Record:
- The prompt or input
- The source information used
- The generated output
- Who reviewed it
- What changes were made
- The final decision
- The reasons for that decision
- Any challenge or correction
11. Create an incident process
Employees need a route to report inaccurate outputs, confidentiality breaches, unauthorised tools, unexpected data use and incorrect automated decisions.
The organisation should be able to pause a system while it investigates.
12. Consult employees and representatives
Consultation can identify risks that project teams miss. Employees might understand how a monitoring, scheduling or performance tool affects day-to-day work better than the people procuring it. Acas advises employers to consult before final decisions are made and to treat consultation as a genuine two-way process.
HR teams Need a Governed Source of Intelligence
A general AI policy is useful, but policy alone doesn't solve the problem because employees will use AI when it gives them a faster route to an answer.
When the approved alternative is slow, difficult to search or disconnected from the task, public tools will remain attractive.
HR leaders therefore need to provide a controlled system that is genuinely useful.
That system should connect AI with:
- Approved company policies
- Current employee and workforce information
- Built-in employment guidance
- Expert-reviewed letters, forms and templates
- Defined HR workflows
- Role-based permissions
- Clear human review points
- Audit records showing what happened
The purpose isn't to make AI the decision-maker, it's to give managers relevant information without requiring them to search several folders, copy confidential details into a public chatbot or rely on an answer detached from the organisation.
The most important limitation of a generic AI assistant isn't its ability to write, but its lack of organisational knowledge.
A manager asking about repeated lateness may need information from:
- The employee’s attendance record
- Their rota
- Their contract
- Previous conversations
- Workplace adjustments
- The company’s attendance procedure
A construction manager might need to know which rules apply to a particular site, worker type or subcontractor.
A healthcare manager might need guidance outside normal HR hours while handling sensitive health information and maintaining safe staffing.
A manufacturing manager might need to understand whether an attendance concern connects with a shift change, overtime pattern or workplace adjustment.
A general chatbot sees the prompt, whereas organisational intelligence understands the employee record, policy, process and user permissions behind it.