General-purpose AI tools such as ChatGPT, Microsoft 365 Copilot, Google Gemini, and Claude can help HR teams write faster and reduce repetitive administrative tasks. They can produce a first draft of a job description, restructure a policy, translate employee communications or turn meeting notes into a clearer summary.
The risk begins when HR asks these AI tools to make, validate or justify a decision that could affect someone’s employment.
These questions look straightforward, but in practice, the right response can depend on employment status, jurisdiction, contractual terms, company policy, previous decisions, protected characteristics, collective agreements and facts that have not yet been established.
A generic AI assistant doesn't automatically know any of that. It might produce an answer that sounds confident while relying on incomplete assumptions. It could draft a letter before an investigation has finished, confuse British and Irish employment rules or recommend a process that conflicts with the organisation’s own policy.
The problem isn't that HR teams use AI. The problem is using AI without organisational context, approved sources, clear data controls and meaningful human oversight.
Yes, but only for suitable tasks and with appropriate controls.
HR teams must also recognise the limitations of general-purpose AI tools that don't automatically understand your organisation, your policies, your employees, or your established HR processes. They only know the information provided in the prompt and might produce confident answers without the context needed to apply them safely.
AI tools like ChatGPT can support:
They shouldn't independently decide:
The greater the potential effect on a person’s employment, the more important organisational context, approved sources, human oversight and clear accountability become.
In reality, HR leaders aren't deciding whether AI will enter the workplace, because in many organisations, it's already there. Recruiters use it to prepare job adverts. Managers use it to draft feedback. Employees enter workplace questions into public chatbots. HR teams use writing tools to create letters, policies and internal communications.
Acas research published in 2025 found that 35% of employers considered increased productivity the most important potential benefit of workplace AI. However, 26% of workers said job losses were their biggest concern. Others were worried about errors, data protection and limited regulation.
HR therefore has two connected responsibilities:
It needs to help the organisation benefit from AI.
It must also protect candidates and employees from unfair, inaccurate or poorly governed uses of the technology.
That requires more than a list of approved tools, it needs HR leaders to decide:
There's no single employment law that covers every workplace use of AI. The legal position depends on where the organisation operates, what the system does, what data it uses and how much influence it has over the final decision.
British employers need to consider data protection, equality, employment, consultation and health and safety law. The Data (Use and Access) Act 2025 changed the UK framework for automated decision-making. Most of its data protection provisions came into force on 5 February 2026.
The new framework permits solely automated significant decisions in a wider range of circumstances. However, safeguards still apply.
Where a decision is made solely through automated processing and has a legal or similarly significant effect, the organisation must:
Stronger restrictions continue to apply when special-category data is involved.
A decision isn't necessarily solely automated because AI contributed to it. The key question is whether there was meaningful human involvement.
A manager who simply approves the system’s recommendation without reviewing the evidence might not provide meaningful human oversight. A genuine reviewer must understand the information, consider the circumstances and have the authority to disagree.
The ICO (Information Commissioner’s Office) made automated recruitment a regulatory focus during 2025 and 2026.
Its March 2026 report found that many employers could be making solely automated recruitment decisions without applying the required safeguards. It called for clearer candidate information, consistent human involvement and better monitoring for bias and unfair outcomes.
The ICO’s updated automated decision-making guidance is still being finalised and is expected during winter 2026. HR teams should review their processes again when the final version is published.
The UK doesn't operate as one employment law jurisdiction. Many references to Acas and the Equality Act 2010 in this article apply to England, Scotland and Wales.
Northern Ireland has separate employment and equality legislation. Employers operating there should check guidance from the Labour Relations Agency and the relevant Northern Ireland authorities before relying on a British process or template.
Irish employers should consider Irish employment and equality law, GDPR and the EU AI Act.
The EU AI Act classes certain systems used for recruitment, candidate selection, promotion, termination, task allocation and worker monitoring as high-risk.
The main high-risk requirements for employment-related systems listed in Annex III are now scheduled to apply from 2 December 2027. This date was introduced by Regulation (EU) 2026/1744, which amended the original implementation timetable.
The extended date doesn't mean Irish employers should delay preparation. Other AI Act duties already apply.
The EU AI Act requires providers and deployers of AI systems to take measures that support AI literacy among the people operating those systems on their behalf. The obligation has applied since 2 February 2025. National supervision and enforcement began in August 2026.
For HR teams, AI literacy should cover:
A generic annual training module will not be enough for every user. A recruiter using AI to review job applications needs different knowledge from a manager using it to draft an employee letter.
Since 2 February 2025, the EU AI Act has prohibited AI systems used to infer emotions in workplaces, except for limited medical or safety purposes.
This could affect systems that claim to determine engagement, confidence, stress, enthusiasm, honesty or emotional state using biometric information such as facial expressions or voice patterns.
Irish employers should treat tools that claim to analyse a candidate’s personality, emotions or trustworthiness from video or audio with particular caution.
Generative AI produces responses based on patterns in data and the information included in the prompt. It doesn't automatically verify that every legal statement, policy reference or procedural recommendation is correct.
It might fill information gaps with assumptions instead of clearly stating that essential facts are missing.
The Workplace Relations Commission addressed this risk in its May 2026 guidance for parties using AI to prepare WRC submissions and evidence. It warned that users remain responsible for checking legal authorities, quotations and factual claims. The guidance also warns that public tools may retain or reuse personal and commercially sensitive information.
That warning has particular relevance for HR.
A fictional case reference in a general document is embarrassing.
An invented legal principle in a dismissal, redundancy or discrimination process could influence a decision with serious consequences for the employee and employer.
Even a legally accurate response may still be wrong for the organisation, as a generic answer won't reflect:
HR leaders should treat general-purpose AI as a drafting and thinking tool, not an independent source of employment advice.
The risk can begin before the AI produces an answer. An HR professional might enter an employee’s name, medical condition, disciplinary history, salary, home address or grievance allegation while asking a public tool to draft a document.
That can create data protection, confidentiality and security risks.
The Irish Data Protection Commission advises organisations to understand:
It also warns that AI products can produce inaccurate or biased outputs and create automated decision-making risks where organisations rely on them without critical human review.
The ICO takes a similar position.
Employers shouldn't assume that purchased technology is compliant. They need to establish the purpose, lawful basis, necessity and proportionality of the processing, while considering whether a less intrusive method could achieve the same objective.
This doesn't mean HR teams can never use AI with workforce information. It means the technology needs:
A manager shouldn't need to copy an employee’s complete case history into a public chatbot to understand the next stage of an HR process.
Not every AI prompt carries the same level of risk. Asking AI to shorten an approved employee announcement is very different from asking it to decide who should be made redundant.
A useful way to assess risk is to consider whether the AI affects presentation, process or outcome.
These include rewriting, formatting, summarising and translating approved material. The content still needs checking, but the AI isn't deciding what should happen.
These include finding a policy, identifying missing information, preparing questions or structuring a meeting.
AI can assist, but the user must check the source and apply the correct process.
These ask AI to recommend, justify or make an employment decision. They carry the highest risk because they may affect:
The following 30 prompts all enter areas where organisational context and human judgement matter. They shouldn't be entered into a generic AI tool and acted upon without proper review.
Recruitment decisions involve personal data, protected characteristics and significant consequences for candidates. AI can help recruiters prepare materials and organise information, but it shouldn't create discriminatory criteria or make unexplained assumptions about someone’s suitability.
This directs attention towards sex and maternity rather than the candidate’s ability to perform the role. The output could introduce inappropriate questions about childcare, future pregnancy, family commitments or likely attendance.
Use the same structured, competency-based questions for each candidate applying for the role. Any questions about availability should relate directly to the genuine requirements of the role and should be asked consistently.
This prompt risks confusing the organisation’s sponsorship position with the candidate’s nationality, race or ethnic origin. HR should first establish:
AI should never infer immigration status from a name, accent, home address, university or nationality.
Words such as “young” indicate that candidates from a particular age group may be preferred. Other apparently neutral terms can also discourage qualified candidates. The advert should describe:
It shouldn't describe the assumed age or personality of the preferred applicant. Acas advises employers to use inclusive language that defines the job rather than the type of person they imagine performing it.
“Overqualified” can become a vague substitute for assumptions about age, salary expectations, commitment or retention. An unexplained scoring system could penalise candidates for experience that has no negative effect on their ability to perform the job.
HR should define objective requirements before reviewing applications and record why each criterion is relevant. The scoring model should then be tested to check whether it produces unfair outcomes.
This prompt starts with the intended outcome of excluding the candidate. It can create disability discrimination and health-data risks. In Great Britain, employers must not normally ask an applicant about health or disability during the application or interview process unless a specific exception applies.
The right question is whether the person can perform the role, with reasonable adjustments where required.
Employee relations cases rarely begin with a complete and uncontested set of facts. AI can help organise evidence or prepare a document once the correct stage has been reached.
It shouldn't decide the outcome before a fair process has taken place.
The prompt assumes gross misconduct has already been established. A generic letter could miss:
AI should only prepare a first draft after the decision-maker has completed the process and confirmed the outcome. In Great Britain, the Acas Code sets the minimum standard employers should follow when handling disciplinary and grievance matters.
“Poor attitude” is subjective. It could refer to:
HR should define the specific behaviour, expected standard, evidence and impact before deciding which process applies. The system shouldn't convert a manager’s personal impression into a formal employment decision.
This asks AI to help reach a predetermined outcome rather than identify a fair process. The correct route may depend on:
Speed shouldn't replace investigation, consultation or the employee’s opportunity to respond.
A script cannot make a predetermined redundancy exercise meaningful. Collective and individual consultation requirements depend on the number of proposed dismissals, the affected establishment and the jurisdiction.
Selection criteria should also avoid direct and indirect discrimination. AI may help structure a communication after the organisation has established the correct process, but it shouldn't design the redundancy exercise from a one-line prompt.
Frequency alone doesn't determine whether dismissal is fair. HR needs to consider:
The absence record could begin a review but doesn't automatically determine the outcome.
Pay and working-time questions often depend on legislation, contracts, actual hours and payroll records. A short AI answer can miss a detail that changes the result.
There is no useful universal answer. The position can depend on:
HR and payroll should review the actual pay arrangement instead of relying on a general statement about overtime.
Agreement doesn't automatically remove statutory working-time protections. Different rules and exceptions may apply depending on:
The organisation should compare the proposed arrangement with its legal duties and working-time policy.
AI cannot calculate an accurate entitlement without the correct information. It may need:
For leave years beginning on or after 1 April 2024, British irregular-hours and part-year workers generally accrue statutory holiday at 12.07% of hours worked in each pay period, subject to the relevant rules and maximum entitlement. Government guidance and the official calculator should be used where appropriate.
The wording asks for a way around an employment right. Holiday pay may need to include payments that form part of normal remuneration. The correct calculation depends on the worker’s hours, pay pattern, leave entitlement and jurisdiction.
A safer task is to identify which earnings must be included and test the payroll configuration against current rules.
The answer can depend on:
A contractual power to vary shifts doesn't mean every change will be reasonable or free from employee relations risk. HR software should record the original schedule, change, notice, communication and approval.
A policy can look complete while remaining legally weak, inconsistent with contracts or difficult for managers to apply. AI can help prepare and adapt content but it can't certify a complete policy framework from a one-line instruction.
No generic prompt contains enough information to do this safely. The AI would need to understand:
A handbook should be built from approved policies, reviewed as a connected set and supported by a formal update process. Avoid presenting AI-generated wording as legally compliant because it looks professional.
Employee monitoring requires more than inserting the words “GDPR compliant” into a document. The organisation must establish:
The ICO advises employers to choose the least intrusive method capable of meeting the identified purpose. It also warns organisations not to assume that a monitoring product purchased from a supplier is compliant.
The organisation cannot make monitoring proportionate simply by placing it in a policy. HR leaders need to distinguish between public conduct that genuinely affects the employment relationship and unnecessary observation of an employee’s private life. The organisation should explain:
It must also consider whether a less intrusive approach would achieve the same purpose.
The objective of a sickness policy shouldn't be to discourage legitimate absence. A suitable policy should:
A target written without those controls could encourage managers to prioritise absence figures over fair treatment.
A blanket ban creates legal and cultural risks. In Great Britain, pay-secrecy clauses are unenforceable where a pay discussion seeks to establish whether differences relate to a protected characteristic.
Even where a particular discussion falls outside that protection, preventing employees from talking about pay can reduce trust and make inequality harder to identify.
HR should address genuine confidentiality and personal-data concerns without presenting all pay conversations as misconduct.
Performance management should set clear expectations, identify barriers and give employees a fair opportunity to improve. Prompts designed to manufacture an exit undermine that purpose.
This wording reduces a potentially complex health and capability issue to a warning. Mental health information may be special-category data.
The employee may also meet the legal definition of disability. HR should first establish:
The system shouldn't infer a diagnosis or determine that formal action is required.
A performance improvement plan should provide a genuine opportunity to improve. Designing it to force a resignation will undermine trust and confidence and create legal risk. A suitable PIP should contain:
AI shouldn't disguise a predetermined exit as a development process.
“Managing out” begins with the assumption that the employment relationship should end. The better question is: What is causing the performance gap, and what fair support or process is required?
The answer may involve clearer objectives, training, resources, supervision, workload changes, reasonable adjustments or a formal capability process. AI can help structure those questions but it shouldn't be used to decide that dismissal is the correct destination.
AI can polish biased feedback as easily as fair feedback. It might make a personal judgement sound formal without improving its accuracy. Managers should provide:
HR should challenge wording that reflects personality conflict rather than evidence about conduct or performance.
Attendance and performance aren't automatically the same measure. Reducing a rating because of disability-related, pregnancy-related or other protected absence may create discrimination risks. It could also penalise an employee for leave that the organisation authorised.
Performance reviews should assess agreed outcomes and behaviours the employee could reasonably control. Any attendance concern should be managed through the appropriate process.
AI often answers monitoring and procedural questions at a general level. HR leaders need to understand how the proposal works in practice, who it affects, and whether it matches existing controls.
The correct process could involve:
A warehouse employee returning after a physical injury might need a different assessment from an office employee returning to desk-based work. The process should connect the employee’s circumstances with the organisation’s actual roles and safety procedures.
The answer depends on the purpose and design of the monitoring. Tracking attendance at a worksite during paid hours is different from following an employee’s location outside work. Employers need to consider:
Permission settings should prevent managers from viewing location information they don't need. The ICO recommends completing a DPIA where required and considering employee or representative views when assessing monitoring risks.
This asks AI to infer personality, emotional state or trustworthiness from video or audio. The output may reflect unreliable assumptions about facial expressions, voice, disability, culture, language, age or neurodiversity.
In Ireland and the wider EU, AI systems used to infer emotions in workplaces are prohibited except for limited medical or safety purposes. Candidate assessment should focus on structured evidence relevant to the role.
Probation doesn't remove the need for an accurate and defensible decision. The organisation must consider:
AI could draft a letter after HR has verified the facts and approved the decision but it shouldn't infer that probation failure is appropriate from limited information.
There is rarely one minimum process that applies to every termination. The correct route depends on:
The responsible approach is to classify the proposed termination, identify the relevant process and verify the facts before any decision is made.
An AI policy alone will not provide enough control. HR teams need a repeatable governance process covering every AI tool and use case.
Record every AI system used in:
Include the supplier, purpose, data used, responsible owner and risk classification.
Decide whether the system supports:
Outcome-driven and monitoring uses require stronger assessment and controls.
Employees should know which tools they may use and which information they may enter.
The policy should address:
A data protection impact assessment may be required where AI involves systematic monitoring, profiling, biometric information, health information or new technology presenting a high risk to individuals.
The assessment should happen before deployment, not after a complaint.
The organisation remains responsible for its own use of the product. They should ask:
Privacy notices and process communications should explain where AI is used, what the system does, what information it considers, whether a human reviews the result, how someone can correct information, and how they can question or challenge a decision.
For high-risk systems deployed in EU workplaces, the AI Act will also require affected workers and their representatives to be informed before deployment when the relevant provisions apply.
Testing should happen:
Compare results across relevant groups and investigate unexplained differences. Don't assume that removing names from an application removes every source of bias.
Name the person responsible for reviewing the output. They must:
Human involvement shouldn't consist of approving whatever the system produces.
Recruiters, managers, HR teams, payroll teams and system administrators need different training. Training should use realistic workplace examples and explain what the user must do when the system is wrong.
The audit trail should show that the human decision-maker considered the evidence rather than simply accepting the AI response. Record:
Employees need a route to report inaccurate outputs, confidentiality breaches, unauthorised tools, unexpected data use and incorrect automated decisions.
The organisation should be able to pause a system while it investigates.
Consultation can identify risks that project teams miss. Employees might understand how a monitoring, scheduling or performance tool affects day-to-day work better than the people procuring it. Acas advises employers to consult before final decisions are made and to treat consultation as a genuine two-way process.
A general AI policy is useful, but policy alone doesn't solve the problem because employees will use AI when it gives them a faster route to an answer.
When the approved alternative is slow, difficult to search or disconnected from the task, public tools will remain attractive.
HR leaders therefore need to provide a controlled system that is genuinely useful.
That system should connect AI with:
The purpose isn't to make AI the decision-maker, it's to give managers relevant information without requiring them to search several folders, copy confidential details into a public chatbot or rely on an answer detached from the organisation.
The most important limitation of a generic AI assistant isn't its ability to write, but its lack of organisational knowledge.
A manager asking about repeated lateness may need information from:
A construction manager might need to know which rules apply to a particular site, worker type or subcontractor.
A healthcare manager might need guidance outside normal HR hours while handling sensitive health information and maintaining safe staffing.
A manufacturing manager might need to understand whether an attendance concern connects with a shift change, overtime pattern or workplace adjustment.
A general chatbot sees the prompt, whereas organisational intelligence understands the employee record, policy, process and user permissions behind it.