Their staff are already using generative AI. The question is: what rules apply?
In most companies, artificial intelligence did not come in as a result of a management decision, but rather through the back door: one person started using it to draft an email, another to summarise a report, and a third to prepare a proposal. By the time management considers the matter, its use is already widespread and unregulated.
The problem is not the tool itself. The problem is that, without guidelines, each person decides for themselves what information to input into it.
What is at stake for the company
- Data protection. Entering personal data relating to customers, patients, candidates or employees into a third-party tool constitutes a data transfer. This requires a legal basis, a data processing agreement, an assessment of international transfers and an update to the record of processing activities. Doing so without any of these constitutes a breach of the GDPR.
- Trade secrets. Law 1/2019 protects business information provided that reasonable measures have been taken to keep it secret. If staff upload quotes, client lists or contractual terms to open-source tools, the company itself is undermining the requirement that would allow it to defend that secrecy against a third party.
- Contractual confidentiality. Many client contracts contain clauses prohibiting the disclosure of client information to third parties without authorisation. Careless use of AI may constitute a breach of contract, leading to claims for damages.
- Intellectual property and erroneous content. Generated content may reproduce third-party works or contain errors presented with complete apparent certainty. Liability towards the client remains with the person who signs off on the work, not with the tool.
- Decisions concerning individuals. Using AI to screen CVs, assess performance or make decisions about employees enters particularly sensitive territory, involving obligations to inform employees’ legal representatives and, in future, compliance with the ‘high-risk’ regime set out in the European Regulation.
What should never be included
Personally identifiable data, and even more so health data, biometric data or data relating to minors.
Client documentation subject to confidentiality or professional secrecy.
Proprietary source code, formulas, processes or any asset constituting a trade secret.
Documentation relating to non-public transactions, ongoing negotiations or sensitive financial information.
What an internal usage policy should contain
There is no need for a lengthy document. What is needed is a clear one:
- Which tools are authorised and which are not, distinguishing between corporate licences and free versions for personal use.
- Which categories of information may and may not be entered, with specific examples from the sector.
- The requirement for human review before using any results, and for the verification of data, quotations and references.
- Rules for identifying AI-generated content where required by regulation.
- A channel for raising queries and clearly communicated consequences of non-compliance.
- A record of the tools used, which will also serve as the inventory required by the European Regulation.
Added to this is staff training, which from February 2025 will no longer be merely good practice but a legal obligation under the European Artificial Intelligence Regulation.
Our recommended approach
Banning the use of AI does not work: it is used anyway, but without oversight and without anyone keeping track of it. It is more effective to authorise specific tools, set clear boundaries and train those who will be using them.
The company gains in productivity and retains control over its data.





