Using AI Within the Law
What you paste, publish and switch on is all regulated.
What Is Using AI Within the Law?
Employees meet three bodies of law every time they use AI at work. Data protection decides what may go into a prompt and which tools may receive it. Copyright decides whether AI output copies someone else's work and whether your company owns it. Employment law and the AI Act decide which features that watch or judge staff need workers informed first, and which are banned. In this exercise you work through one day where each applies, and decide what the law allows.
What You'll Learn in Using AI Within the Law
- Choose an approved AI tool with a data processing agreement and share only the personal data a task needs, leaving out health details and third parties
- Recognise AI output that copies protected work, and explain why output with no human creative input may not belong to the company
- Identify AI features that evaluate or rank staff as high-risk, requiring workers' representatives and affected staff to be informed first
- Recognise emotion recognition of employees as a practice the AI Act prohibits at work
Using AI Within the Law — Training Steps
-
Review Week
Quarterly reviews are due on Friday, and you have six people to write feedback for. Kasia Wrobel, who leads the motor claims team, has found a shortcut and wants to share it.
-
The Approved Tool
The idea is not wrong: AI is good at a first draft of feedback. The tool is. Ostbury has its own assistant for exactly this kind of work, covered by a data processing agreement.
-
Before You Send
An approved tool does not mean anything goes. The summary needs the work, not the person's name, their health data or a customer's policy number. Ostbury Assist has found four pieces of personal data in your draft. You decide what happens to each one.
-
Send It
The prompt now carries the work and nothing else.
-
Without the Names
Kasia's shortcut is worth one more look.
-
Lena's Assets
Mid-morning, a second request lands. Legal is away, and you are the named reviewer for the claims FAQ this week.
-
The Review
Four assets, one question each: can this go on a public Ostbury page without taking something that belongs to someone else?
-
Usable Is Not Owned
One asset passed. Before you send the decisions back, two things about this review are worth knowing.
-
The Logo
Lena has one more idea after reading your decisions.
-
Switched On by Default
After lunch, IT writes to every team lead. The contact centre software your team uses all day has updated overnight.
Security Framework Coverage
CIS Controls
- CIS 14.4 Train Workforce on Data Handling Best Practices
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
GDPR
- Art. 5 Principles relating to processing of personal data (data minimisation)
- Art. 9 Processing of special categories of personal data
- Art. 28 Processor
EU AI Act
- Art. 26 Obligations of deployers of high-risk AI systems
- Art. 5 Prohibited AI practices
- Art. 4 AI literacy