Addaly is in open beta. Things will change, and AI answers can be wrong — check anything that matters.

AI at Work

The tasks it genuinely helps with, the ones it quietly ruins, and the line you must never cross.

Lesson 49 of 7310 min

The rules that already apply to you

Most of the law here is not new

There is a widespread belief that AI is unregulated and that anything goes until legislators catch up. It is wrong in the way that matters at work. Nearly every problem you can create with a chatbot is already covered by rules that existed before it.

Data protection. If the text contains information about an identifiable living person, sending it to an outside service is processing personal data. Under the GDPR in Europe and the UK, India's Digital Personal Data Protection Act, Brazil's LGPD, Nigeria's NDPA and comparable laws elsewhere, that requires a lawful basis, a purpose, and — crucially — it does not stop being your organisation's responsibility because a supplier did the computing. The organisation that decides to send the data is the controller. The AI provider is a processor. Controllers carry the duties: lawful basis, transparency to the person, security, retention limits, and the ability to answer a request for access or deletion.

That last one has teeth. If a customer asks what you hold about them, "some of it is in a chat log at a company we do not have an account with" is not an answer anybody wants to give.

Confidentiality and professional duty. Separate from data protection and often stricter. Legal professional privilege, medical confidentiality, banking secrecy, the duty a teacher owes a pupil, an auditor's duty to a client, and any NDA you have signed. These bind you personally, they are not satisfied by a supplier's privacy policy, and they are breached at the moment of disclosure — not when harm results.

Sector rules. Financial services, health, aviation, education and public administration all have record-keeping, supervision and accountability requirements that apply to a decision regardless of what helped you make it. "The tool suggested it" has no standing in any of them.

Employment and equality law. If a tool influences hiring, promotion, discipline or dismissal, discrimination law applies to the outcome. That is the subject of the next lesson, because it is where the most damage is being done.

The AI-specific rules, and how to read them

Newer laws sit on top of the above rather than replacing them. The EU AI Act is the most consequential and the pattern is worth knowing even outside Europe, because it is being copied.

It classifies uses by risk. A small set of practices is prohibited — including, directly relevant to workplaces, emotion recognition of employees. A larger set is designated high risk, and that set explicitly includes AI used in recruitment, in decisions about promotion and termination, and in task allocation and monitoring of workers. High-risk uses carry obligations: risk management, data governance, human oversight, logging, and transparency to the people affected. There is also a general duty of AI literacy — that staff using these systems understand them well enough to use them properly, which is roughly what this course is.

The Act entered into force in August 2024 and its obligations were legislated to phase in over the following two years. The timetable for the high-risk tier has been argued over politically since, and I am not going to tell you what is in force on the day you read this. That is itself the lesson: check the current position for your jurisdiction and your use, from the regulator's own page, on the day it matters. A course that told you it had it settled would be doing exactly what the citation lesson warned about.

Elsewhere: New York City has required annual independent bias audits of automated employment decision tools since July 2023, with notice to candidates. Several US states, Canada, Brazil, Japan, South Korea and India have their own instruments in various stages. Sector regulators frequently move first and bind you before any general law does.

What to actually do

You do not need to become a lawyer. Four habits cover most of it.

  1. Ask whether a person is identifiable in what you are about to send. If yes, data protection is engaged and you need to know your organisation's basis for it.
  2. Ask whether this influences a decision about a person. If yes, treat it as high risk whatever your jurisdiction says, and keep a human decision with reasons.
  3. Keep a record. What tool, what went in, what came out, what you did with it. Every regime above eventually asks this question, and a note written on the day is worth more than a reconstruction a year later.
  4. Read the rule from the body that made it. Not a summary, not a vendor's blog, not this lesson. Regulators publish their own guidance and it is usually clearer than the commentary on it.

The proportionate view

None of this means the answer is no. It means the answer has a shape: know whose data it is, know which tier you are on, keep the decision human where a person is affected, and write down what you did. Organisations that do those four things use these tools heavily and safely. Organisations that do none of them are one incident away from a ban that costs them everything the tools were saving.

The one thing to keep

No new AI law is needed to make most workplace misuse unlawful — data protection, confidentiality and sector regulation already bind you, and the AI-specific rules add duties around transparency and decisions about people.

Before you move on

A manager in Europe says the firm need not worry about data protection because 'the AI provider is the one processing the data'. Where does this go wrong?

Pick the one you would defend. Nobody sees your answer.

No ads. No data sale. No public scores on people. Ever.

© 2026 Addaly