Companies are giving employees claims about AI. The lawyer tells you directly how much they are worth
AI entered Polish companies faster than the procedures that were supposed to control it. Now companies are forcefully pushing statements to employees. Is it real security or worthless paper?
Further regulations related to artificial intelligence mean that companies are taking an increasingly closer look at how their employees use AI. From August 2, the provisions of the AI Act regarding the transparency of artificial intelligence systems came into force in the European Union. In response to these regulations, some companies decided to protect themselves. Employees are therefore provided with statements and internal rules regarding the use of artificial intelligence.
They usually contain similar recommendations: do not paste confidential data into public tools, check information generated by AI, carefully use the effects of algorithms and appropriately label content created using them. The problem is that in many cases the actual activities of the company end with the document itself.
Employees can still use publicly available AI tools, often on private accounts over which the employer has no actual control. Therefore, the company has a signed declaration, but does not always provide tools or procedures that allow the employee to actually perform work in accordance with the imposed rules. The question arises how much such “security” is worth and whether the responsibility for the risk related to AI can be transferred to the employee in this way.
– The declaration signed by the employee does not transfer the employer’s responsibility for the lawful and safe organization of the use of AI. It may be an element of internal policy and proof that the employee has received clear instructions – notes attorney Radosław Rogalski, partner at Czupajło Ciskowski & Partners, in an interview with “Wprost”.
He explains that this is definitely not enough.
– However, if a company stops at prohibitions and at the same time expects or tolerates the use of AI on private accounts in public services, a significant organizational gap arises – says attorney Radosław Rogalski.
The AI Act does not require a model for everyone. However, it requires more than just regulations
New EU regulations do not mean that every company must immediately buy its own artificial intelligence model or an expensive, dedicated platform.
– The AI Act does not require every company to buy a dedicated model. However, it requires suppliers and entities using AI to take actions to support staff competences, appropriate to the tool, method of use and risk – explains the lawyer.
He emphasizes that simply asking to sign a form or read the instructions may not be enough.
This means that companies should first answer a few basic questions: whether employees use AI, what they use it for, what information they enter into the systems and which tools are allowed in the organization. Only then can you effectively build rules.
– There are also obligations under the GDPR, such as risk assessment, data minimization, appropriate security measures and administrator accountability. These duties cannot be “delegated” to an employee with one signature, says attorney Rogalski.
Where does the company’s responsibility end and the employee’s begin?
Of course, this does not mean that an employee using AI has no responsibility.
– An employee may face consequences for culpably violating a clear, lawful order, e.g. consciously pasting a trade secret into a prohibited tool – explains attorney Rogalski.
However, the boundary is clear: the employee should not be left alone with a problem that the company solved only with a signed document. If an organization wants to use AI, it must create conditions in which safe principles can actually be applied.
– However, if AI is to be used at work, the employer should first indicate which tools and applications are allowed, train people, ensure that work can be realistically performed in accordance with the rules, and respond to violations. Otherwise, the statement becomes primarily a paper alibi, and not an effective risk management system – emphasizes attorney Rogalski.
This is where the greatest challenge for entrepreneurs may lie. Artificial intelligence did not wait for companies to create regulations for it. It entered the organization through everyday tasks and employees’ private accounts, often almost unnoticed. Merely adding a few prohibitions to the declaration in order to have security in the form of “paper” may turn out to be insufficient. Companies need to answer a much more difficult question: Do they really manage the use of AI, or do they just have documentation that they have tried to do so?
