Using ChatGPT at work? This is what you need to know

Using ChatGPT at work? This is what you need to know

Using ChatGPT at work? This is what you need to know

Artificial intelligence has become an everyday business tool within just a few years. An increasing number of employees use ChatGPT and similar AI systems to draft emails, summarise contracts, create marketing materials or even generate code. While generative AI can significantly improve efficiency, its use also raises a number of legal and data protection issues.

For many businesses, the question is no longer whether they use artificial intelligence, but whether they are using it within an appropriate legal framework.

Not All Data Belongs in ChatGPT

One of the most common mistakes is uploading business documents or personal data to AI systems without considering the potential consequences.

Uploading a draft contract, customer list, document containing employee data or an internal business strategy may create significant data protection and business risks. The GDPR (the European Union’s General Data Protection Regulation) is technology-neutral and therefore remains fully applicable when work is supported by artificial intelligence. This includes, in particular, requirements relating to the legal basis for data processing, purpose limitation, and the transfer of personal data to third countries, such as to the servers of an AI service provider.

Businesses should therefore clearly define which types of data may be uploaded to AI applications and which data must not be processed in this way.

AI Does Not Eliminate Legal Liability

It is important to emphasise that the company using AI remains responsible for the content generated by artificial intelligence.

An AI-generated contract, information notice or marketing material may contain inaccuracies, incorrect legal references or even false statements. If a business acts unlawfully on the basis of such content, responsibility cannot simply be shifted to the AI system.

For this reason, documents generated with the assistance of AI should always undergo human review, particularly in legal, financial and HR matters.

Consider Adopting an Internal AI Policy

Many businesses still do not have an internal policy defining the framework for the use of artificial intelligence.

An appropriate AI policy may, among other things, specify:
• which AI tools may be used within the business;
• what types of data may be uploaded to these systems;
• when human review is mandatory;
• who is authorised to use AI tools;
• what documentation requirements apply to the use of AI.

Such a policy not only supports legal compliance, but can also reduce operational and data security risks. Our firm would be pleased to assist businesses in preparing internal AI-use policies and reviewing the related legal and data protection considerations.

The AI Act Introduces New Obligations

The European Union’s Artificial Intelligence Act (AI Act) is entering into application gradually and is becoming increasingly relevant to businesses. Although not every company qualifies as a provider or developer of an AI system, the regulation also imposes certain obligations on entities that use artificial intelligence.

In particular, businesses may need to ensure that employees receive appropriate information and training and that the organisation understands the capabilities and limitations of the AI tools it uses. Article 4 of the AI Act requires providers and deployers to take measures to ensure a sufficient level of AI literacy among their staff and other persons involved in the operation of AI systems; this obligation has been further clarified by the 2026 amendments aimed at simplifying the implementation of the AI Act (the so-called Digital Omnibus on AI).

The use of AI is therefore no longer solely an IT issue, but also an important legal, data protection and compliance matter.

What Should Businesses Do Now?

The use of artificial intelligence is expected to become even more deeply integrated into business operations in the coming years. At the same time, the regulatory environment is becoming increasingly detailed. Businesses should therefore consider establishing internal processes that ensure the lawful and secure use of AI.

Among other things, businesses should consider the following questions:
• Do employees know what data must not be uploaded to AI systems?
• Does the company have an internal AI-use policy?
• Are AI-generated documents subject to human review?
• Does the use of AI comply with applicable data protection requirements?
• Is the company prepared for the AI Act requirements that are gradually coming into effect?

Artificial intelligence can provide a genuine competitive advantage for businesses, but only if it is used consciously and within an appropriate legal and regulatory framework. AI does not replace professional decision-making; it is a tool supporting it. It is therefore in every business’s interest to keep its internal policies and compliance processes up to date alongside technological developments.

Share on XShare via emailShare on LinkedIn

Go to
Offices

Go to Offices