Zum Inhalt springen

ChatGPT and similar tools in the workplace: A legally compliant AI policy – the be-all and end-all

4 min.

Artificial intelligence has long since become part of everyday working life. Whether it’s ChatGPT, Microsoft Copilot, Gemini or other AI tools – many employees are already using these applications to draft texts, compose emails, prepare presentations or analyse information more quickly.

This offers significant opportunities for businesses: processes can become more efficient, routine tasks can be automated, and staff can free up time for value-adding activities.

At the same time, however, new legal risks are emerging. This is because AI tools are often used without there being clear guidelines in place within the organisation. This is precisely where an AI policy comes in: it establishes binding rules for the safe and responsible use of artificial intelligence.

Why companies need an AI policy

In many companies, staff are already using AI – often on their own initiative. The problem is that, without clear guidelines, there is a risk that sensitive company data or personal information could be entered into public AI systems.

Furthermore, AI-generated content is not automatically accurate, complete or legally sound. Anyone who uses the results without checking them risks errors, data protection breaches or even copyright issues.

An AI policy therefore not only ensures greater legal certainty, but also provides clarity on which AI applications are actually permitted within the organisation.

Legal pitfalls associated with the use of AI

The use of AI touches on various areas of law simultaneously. Of particular relevance are:

Data Protection and Confidentiality

Anyone who enters personal data or confidential business information into public AI tools may be in breach of the General Data Protection Regulation (GDPR) or existing confidentiality obligations. Customer information, personnel data and internal business documents, for example, are particularly sensitive.

Copyright and rights of use

Not all AI-generated content may be used or published without further ado. Depending on the tool used, different terms of use may apply. Companies should therefore check what rights they actually hold over the content generated.

Incorrect or misleading results

AI can provide convincing answers – but it can also be wrong. Results that are factually incorrect or incomplete can have significant consequences, particularly in legal, financial or technical fields. For this reason, AI should never replace an independent expert review.

What should a legally compliant AI policy include?

A good AI policy is not simply a general ban or permission to use AI. It should contain specific and practical rules for day-to-day business operations.

Permitted and prohibited AI tools

Organisations should specify which applications may be used and which are expressly prohibited. This helps to prevent employees from using any AI services without supervision.

Rules for data entry

A key component of any AI policy is the handling of data. Confidential company information, personal data or trade secrets should, as a general rule, not be entered into public AI systems without prior review.

Obligation to verify AI results

AI can provide support – but the responsibility remains with humans. That is why every AI policy should clearly stipulate that AI-generated content must be subject to expert review before it is used.

Transparency in the use of AI

In certain situations, it may be advisable or even necessary to indicate that content has been created using AI. This applies, for example, to internal processes, certain communication initiatives or documentation.

Rights of use and exploitation

Companies should also establish guidelines on how to handle AI-generated content. This includes, in particular, the question of whether, and to what extent, such content may be used for business purposes, modified or published.

Further sensible regulations

Depending on the company, the following points, amongst others, may also be worth considering:

  • Handling confidential company information
  • Documentation of the use of AI in sensitive processes
  • Responsibilities within the company
  • Approval processes for AI-generated content
  • Guidelines on the use of AI in customer communications
  • Compliance with the provisions of the EU AI Act, insofar as these are already applicable.

Practical tip: Combine AI policy with training

In practice, an AI policy on its own is rarely enough. Even the best policies are of little use if staff do not know how to use AI safely and responsibly.

Companies should therefore offer regular training and raise staff awareness of issues such as data protection, confidentiality, copyright and the critical evaluation of AI outputs.

Particularly in light of the EU AI Act, internal processes and training programmes are becoming increasingly important. Companies should therefore address the issue of responsible AI governance at an early stage.

Conclusion

ChatGPT and other AI tools are set to bring about lasting changes to the day-to-day workings of many organisations. However, anyone wishing to manage their use effectively should not rely on the individual decisions of individual staff members.

A legally sound AI policy establishes clear rules, protects sensitive company data and reduces legal risks. At the same time, it ensures that the benefits of artificial intelligence can be utilised responsibly and efficiently.

It is important to note that an AI policy is only the first step. It is only when combined with clear processes, regular training and a mindful approach to AI that a sustainable and legally compliant AI strategy for the company can be established.


If you have any questions on this or other topics, please contact us - we will be happy to advise you.

to the contact form