[ Chapter 4 · Recognizing and managing AI risks at work ]
The rules that apply
4 min read
You do not need to be a lawyer to use AI at work, but you should know which rules exist, because they explain most of what your organisation asks of you. Four layers matter in Europe.
1. GDPR: personal data, any tool
The GDPR has applied since 2018 and applies fully to AI. Feeding personal data (customers, employees, candidates) into any tool is processing that needs a legal basis, and handing it to a tool provider requires the right setup: depending on the arrangement, the provider acts as your organisation's processor (which requires a contract) or as a controller with its own obligations. Pasting customer details into an unvetted chatbot will almost never satisfy any of this, which is why it is not a gray area in practice. GDPR also restricts decisions based solely on automated processing that have legal or similarly significant effects on people, with narrow exceptions, which constrains what AI may decide alone.
2. The EU AI Act: rules by risk level
The AI Act entered into force in 2024 and applies in stages. It bans a small set of practices outright (for example certain forms of social scoring, and inferring emotions at work from biometric data outside medical and safety uses), imposes strict duties on high-risk systems (many recruitment and employee-management uses qualify, with exceptions, and with duties phasing in), and contains transparency rules: people should be able to know when they are interacting with a machine, and providers of generative systems must mark synthetic content in machine-readable form, subject to exceptions.
Article 4, as amended by Regulation (EU) 2026/1744, requires providers and deployers to take measures supporting AI literacy among staff who operate or use AI systems, appropriate to their role and context. These obligations fall under national supervision from August 2026. This course exists partly so that organisations have a concrete, documented measure to point to; the obligation itself remains theirs and is contextual.
3. Your contracts
Confidentiality clauses in your employment contract and in customer NDAs apply to AI tools exactly as they apply to email. Sending a client's document to an unapproved AI service can breach the NDA regardless of any data protection law.
4. Sector rules and internal policy
Finance, health, legal, and public-sector organisations carry additional duties (banking secrecy, medical confidentiality, professional privilege). And your organisation's own AI policy is the layer written specifically for you: it names the approved tools and the forbidden data. If you read one document after this course, read that one.