Using AI Within the Law

Using AI Within the Law

What you paste, publish and switch on is all regulated.

What Is Using AI Within the Law?

Employees meet three bodies of law every time they use AI at work. Data protection decides what may go into a prompt and which tools may receive it. Copyright decides whether AI output copies someone else's work and whether your company owns it. Employment law and the AI Act decide which features that watch or judge staff need workers informed first, and which are banned. In this exercise you work through one day where each applies, and decide what the law allows.

What You'll Learn in Using AI Within the Law

Using AI Within the Law — Training Steps

  1. Review Week

    Quarterly reviews are due on Friday, and you have six people to write feedback for. Kasia Wrobel, who leads the motor claims team, has found a shortcut and wants to share it.

  2. The Approved Tool

    The idea is not wrong: AI is good at a first draft of feedback. The tool is. Ostbury has its own assistant for exactly this kind of work, covered by a data processing agreement.

  3. Before You Send

    An approved tool does not mean anything goes. The summary needs the work, not the person's name, their health data or a customer's policy number. Ostbury Assist has found four pieces of personal data in your draft. You decide what happens to each one.

  4. Send It

    The prompt now carries the work and nothing else.

  5. Without the Names

    Kasia's shortcut is worth one more look.

  6. Lena's Assets

    Mid-morning, a second request lands. Legal is away, and you are the named reviewer for the claims FAQ this week.

  7. The Review

    Four assets, one question each: can this go on a public Ostbury page without taking something that belongs to someone else?

  8. Usable Is Not Owned

    One asset passed. Before you send the decisions back, two things about this review are worth knowing.

  9. The Logo

    Lena has one more idea after reading your decisions.

  10. Switched On by Default

    After lunch, IT writes to every team lead. The contact centre software your team uses all day has updated overnight.

Security Framework Coverage

CIS Controls

  • CIS 14.4 Train Workforce on Data Handling Best Practices

NIST CSF

  • PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind

GDPR

  • Art. 5 Principles relating to processing of personal data (data minimisation)
  • Art. 9 Processing of special categories of personal data
  • Art. 28 Processor

EU AI Act

  • Art. 26 Obligations of deployers of high-risk AI systems
  • Art. 5 Prohibited AI practices
  • Art. 4 AI literacy