AI policy: the employer must provide the tools, not the employee — responsibility
An employee’s signature on a statement that they use private AI tools “at their own risk” transfers nothing. Providing a safe tool for work is the employer’s obligation — and trying to shed it with a single signature does not work under any of the relevant liability regimes. In an unfavourable scenario, the document itself works against the company.
The scenario is familiar: a company does not buy licences, allows employees to use private chatbots and collects their signatures. The document goes into personnel files and everyone feels safe — until the first incident at the provider
The problem starts earlier, with the decision itself. If an employer permits private tools specifically to avoid licence costs, it makes an organisational decision within its own business and technical risk. Employees cannot control which model processes the data, the terms of a consumer account or whether their prompts are used for training. Passing the consequences of that decision to someone without the means to control it undermines the very structure of the employment relationship
In our new post, we examine this structure in detail
- Labour Code: Only the employer is liable to third parties for damage (Article 120 § 1 of the Polish Labour Code), while recourse for unintentional fault is capped at three months' pay. A clause extending an employee's liability is void under Article 18 § 2
- Criminal law: Liability is personal and cannot be transferred. The statement merely shows that the risk was foreseeable; for management, it may be read as evidence of a failure to act
- AI Act: The deployer is the employer, regardless of whose name the account is registered in or who pays the subscription. The “sign that it is at your own risk” approach cannot be reconciled with the duty to ensure staff AI literacy — so the document may itself constitute evidence of a breach
- GDPR: An employee's signature does not change the allocation of controller and processor roles
- ISO/IEC 27001 and ISO/IEC 42001: Allowing an external tool may be an organisational decision, but it must be recorded in the management system and an approved risk treatment plan. An employee's signature is neither a safeguard nor acceptance of residual risk — only the organisation's risk owner can accept it
Yet no penalty table captures the most expensive item. Organisational know-how — pricing methods, contract structures and arguments in disputes — accumulates in chat histories on private accounts. It cannot be searched, audited or handed over to a successor, and disappears for good when the employee leaves
This also works the other way: a private tool does not know the organisation's context, so everyone builds a separate, incomplete version — and synergy never emerges
Conclusion
A statement makes sense only as part of an internal policy — instructions for use and a list of data that must not be entered
Real protection comes from architecture
- Company tools instead of private ones
- A layer deciding which data can reach which models
- Operation logging
- Trained staff
A policy without technical control is a declaration; technical control without a policy is blind
The full analysis with its legal basis is on our blog