allclouds.pl

AI policy: the employer must provide the tools, not the employee — responsibility

AI policy: the employer must provide the tools, not the employee — responsibility

An employee’s signature on a statement that they use private AI tools “at their own risk” transfers nothing. Providing a safe tool for work is the employer’s obligation — and trying to shed it with a single signature does not work under any of the relevant liability regimes. In an unfavourable scenario, the document itself works against the company.

The problem starts earlier, with the decision itself. If an employer allows private tools specifically to avoid licence costs, it is making an organisational decision within its own economic and technical risk. The employee has no control over which model processes the data, the terms of the consumer account, or whether their prompts are used for training. Shifting the consequences of such a decision to someone who lacked the tools to control it undermines the very structure of the employment relationship.

In our new article, we examine this arrangement in detail

The most expensive item, however, appears in no penalty table. Organisational know-how — proposal pricing methods, contract structures and arguments used in disputes — accumulates in conversation histories on private accounts. It cannot be searched, audited or handed over to a successor, and it disappears permanently when the employee leaves.

It also works in the other direction: a private tool does not know the organisation’s context, so everyone builds their own partial version — and synergy never develops.

Conclusion

A statement makes sense only as part of an internal policy: instructions for use and a list of data that must not be entered.

Meaningful protection requires an architecture:

Rules without technical controls are a declaration, while technical controls without rules lack direction.