AI in Corporate HR Policies
AI is no longer just a futuristic tool, but a daily reality that helps companies automate processes and improve decision-making. However, integrating it into business processes also brings hidden legal risks that can cost a company not only money but also its reputation. Legal frameworks, such as GDPR or the new AI Act, were not designed for this new technology, and a lack of awareness can lead to serious problems. With the expert legal advice provided by the specialists at ARROWS, your company can navigate this complex landscape and gain a strategic advantage.

A New Era in HR: How Artificial Intelligence is Changing the Game
The AI Toolkit for Modern HR
Recruitment and onboarding: AI tools now automate resume screening, candidate assessment and ranking, interview scheduling, and even initial interviews conducted by chatbots. They can generate job descriptions and onboarding documents, saving HR professionals countless hours of administrative work.
Performance management and engagement: AI-powered platforms analyze employee feedback, track performance goal attainment, and can even predict the risk of turnover, allowing management to intervene proactively. They can personalize engagement programs and suggest individual training and development plans.
Compliance and administration: AI systems can monitor regulatory compliance in real-time, automate payroll processing, manage employee benefits, and streamline a whole range of administrative processes.
The Promise of Objectivity Versus the Reality of Risk
The main selling point of many AI-powered HR tools is the elimination of human bias and subjectivity from decision-making processes. This promise is alluring—the idea of fair and purely data-driven selection or evaluation is the ideal of every modern HR department.
However, this brings us to the central paradox that this report explores in detail: these same tools, if not properly managed and monitored, can not only replicate but even amplify and systematize biases on an unprecedented scale. A machine that learns from historical data reflecting past societal inequalities becomes not a tool of objectivity, but a highly effective tool for perpetuating discrimination.
This paradox creates an entirely new category of risks that are not obvious at first glance. The speed and scale at which AI can make decisions mean that a single error in an algorithm or a bias in the training data can manifest in thousands of incorrect decisions before anyone even notices the problem.
The Czech Context
It is crucial to realize that this is not a distant problem concerning only the tech giants of Silicon Valley. With the National Artificial Intelligence Strategy and active support for AI development from the Czech government, the pressure and opportunity for local firms to adopt these technologies and maintain competitiveness are growing. The question is therefore no longer,
whether companies will use AI in HR, but how they will manage the associated risks. The legal team at ARROWS is actively monitoring these developments at both the national and European levels to provide clients with the most current and strategically valuable advice.
The rapid pace of AI adoption in HR creates what can be called an "inevitability trap." Companies feel pressured to implement these tools as quickly as possible to keep up with the efficiency of their competitors. However, this pressure often leads to rushed procurement and implementation, bypassing thorough legal and ethical vetting. Company leadership, driven by the fear of "being left behind," perceives due diligence as a bureaucratic obstacle that slows down "innovation."
This very competitive pressure driving adoption thus becomes the primary cause of unmanaged risk, which firms like ARROWS must help their clients navigate. It is a self-perpetuating cycle of risk where the pursuit of profitability paradoxically generates potentially catastrophic liabilities.
Hidden Pitfalls: Legal Risks You Need to Know About
This section is the core of the entire report. Its goal is to create a sense of informed urgency in the reader and to show that ignoring these risks is not a sustainable strategy.
Under Brussels' Scrutiny: Why Your HR Software is Now "High-Risk" Under the AI Act
The EU's Artificial Intelligence Regulation (AI Act) is the world's first comprehensive law on AI. It introduces a risk-based approach and, crucially for the HR sector, explicitly classifies AI systems used for the recruitment, selection, promotion, and termination of employees as "high-risk."
This classification is not just a label. It triggers a cascade of strict legal obligations that must be met even before the tool is put into operation. These obligations include:
Mandatory conformity assessment before being placed on the market.
Implementation of robust risk management systems.
Ensuring high quality and governance of the data used for training.
Maintaining detailed technical documentation.
Guaranteeing effective human oversight of the system's operation.
Mandatory registration of the system in an EU database.
Failure to comply with these rules can have catastrophic financial consequences for a company. The AI Act introduces fines of up to 35 million euros or 7% of the total worldwide annual turnover for the most serious violations, such as using prohibited AI practices. Even non-compliance with obligations for high-risk systems can lead to fines of up to 15 million euros or 3% of annual turnover. This is a financial risk that the board of directors of every company must address. The lawyers at
ARROWS have been analyzing the AI Act since its initial drafts and are uniquely positioned to guide companies through the complex process of conformity assessment and documentation preparation required for these high-risk systems.
Ghost in the Machine: Algorithmic Discrimination and the Threat of Lawsuits
The core of the problem lies in how AI learns. It learns from data. If historical recruitment data reflects past societal or organizational biases (e.g., fewer women in leadership positions, a preference for graduates from certain universities), the AI will learn these biases, replicate them, and amplify them in its automated decision-making.
It can even create new, unintended forms of discrimination by finding spurious correlations in data that have no connection to job performance (e.g., a correlation between commute distance and job success).
These risks are not theoretical. They are illustrated by real-world cases that serve as a warning:
Amazon's recruitment tool: A well-known case is when Amazon had to abandon its recruitment tool because it learned to penalize resumes containing the word "women's" (e.g., "captain of the women's chess club"). The reason was that its training data came predominantly from male applicants from the past.
Lawsuit against Workday: A significant class-action lawsuit is currently pending against the tech giant Workday, which provides HR software. The lawsuit alleges that its AI-based tools discriminate against applicants based on race, age, and disability. This case is groundbreaking because it shows that even if a company does not intend to discriminate, it can be held fully liable for indirect discrimination (disparate impact) caused by the third-party tools it uses.
The problem is further complicated by the so-called "black box." Many advanced AI models are so complex that even their creators cannot fully explain why a particular decision was made. This makes it impossible to defend against an accusation of discrimination, as the company cannot present a legitimate, non-discriminatory reason to the court for a decision made by the algorithm. Litigating a case of indirect discrimination is a complex legal challenge.
ARROWS helps clients conduct algorithmic bias audits and develop defense strategies, but more importantly, it helps them implement governance frameworks that prevent such lawsuits from arising in the first place.
GDPR on Steroids: Data Protection in the Era of Intelligent Systems
The implementation of AI in HR creates new and amplified challenges for compliance with the General Data Protection Regulation (GDPR).
An inherent conflict: Artificial intelligence is data-hungry, but GDPR mandates the principle of data minimization—processing only the data that is strictly necessary for a given purpose. AI often requires huge datasets for training, creating a fundamental tension with this principle.
Legal basis and consent: On what legal basis are you processing an employee's personal data to train an AI model? Relying on "legitimate interest" requires conducting a complex balancing test that may not hold up. Employee "consent" is problematic in an employment relationship due to the power imbalance—it is highly likely that such consent will not be considered freely given and will therefore be invalid.
Security and data breach risks: Using AI tools, especially cloud-based or free versions, can lead to unintentional data leaks. Sensitive employee data or confidential company information entered into a prompt can be used to train the provider's public model, which is essentially equivalent to publishing it. Such an incident constitutes a massive personal data breach with all the ensuing legal consequences.
DPIA obligation: The use of new technologies like AI for large-scale processing of personal data, especially in the sensitive HR context, almost certainly requires conducting a Data Protection Impact Assessment (DPIA) under GDPR. This is a formal process of identifying and mitigating risks that requires expert legal knowledge. The team at
ARROWS includes GDPR specialists who routinely conduct DPIAs and advise clients on the lawful processing of employee data, ensuring that AI implementation does not violate existing data protection laws.
"AI Generated It" – Why This Excuse Won't Hold Up, or: Liability and Penalties
One of the most dangerous myths is the idea that the manufacturer of the AI is responsible for its errors.
Shifting liability: AI tool providers are masters at limiting their own liability. Their terms and conditions almost universally transfer all responsibility for the AI's outputs to the user. The argument "the artificial intelligence did it" is not and will not be a valid legal defense.
The user is the operator: From a legal perspective, the company that deploys an AI tool is its operator and, in the case of personal data, the "data controller." You are fully responsible for its decisions, its biases, and its mistakes.
The price of non-compliance: The risk is not just one fine from one regulator. It's a combination of:
Huge fines under the AI Act (up to 7% of total worldwide annual turnover).
Huge fines under GDPR (up to 4% of total worldwide annual turnover).
Civil lawsuits from rejected applicants or disadvantaged employees.
Interventions and fines from the State Labour Inspection Office, which has the authority to check compliance with internal regulations.
Serious reputational damage and loss of market trust.
The legal risks associated with AI in HR are not isolated. They represent a dangerous convergence of three distinct legal areas: labor law, data protection law, and technology regulation. A single flawed AI decision in recruitment can simultaneously violate the AI Act (improper use of a high-risk system), GDPR (unlawful data processing), and the Labour Code (discrimination). This creates a "triple jeopardy" scenario for the company, where it faces penalties from three different directions.
Managing such complex risk requires a multidisciplinary legal team like the one available at ARROWS, which understands the interconnections between these fields. ARROWS specializes in information technology law and helps clients negotiate contracts with AI providers to mitigate risks and appropriately allocate liability, instead of blindly accepting one-sided terms and conditions.
Example of Violation | Affected Regulations and Violations | Maximum Potential Penalty |
Using an unvetted AI resume screening tool that demonstrably disadvantages older applicants. | AI Act: Non-compliance with obligations for a high-risk system. Labour Code: Age discrimination. GDPR: Unfair processing of personal data. | Up to €15 million or 3% of turnover (AI Act) + damages in a civil lawsuit. |
Deploying AI for employee performance monitoring without conducting a Data Protection Impact Assessment (DPIA). | GDPR: Violation of Art. 35 (DPIA obligation). Labour Code: Unreasonable intrusion into employee privacy (§ 316). | Up to €10 million or 2% of turnover (GDPR) + fine from the Labour Inspectorate. |
Using an AI tool for emotion recognition of candidates during an online interview. | AI Act: Use of a prohibited AI practice. | Up to €35 million or 7% of turnover (AI Act). |
Entering internal salary tables into a publicly available version of a generative AI for analysis purposes. | GDPR: Personal data breach. Civil Code: Violation of trade secrets. | Up to €20 million or 4% of turnover (GDPR) + damages. |
Internal Policies as Your Shield: Building Resilience from Within
Having identified the complex threats, we now turn to the primary solution: creating a robust internal governance framework. Well-drafted internal regulations are the cornerstone of defense against the legal and financial risks associated with AI.
Why Your Old Work Regulations Are No Longer Enough
The Czech Labour Code defines two basic types of internal norms: an internal regulation (Section 305 of the Labour Code), which establishes employee rights more favorably than the law, and work regulations (Section 306 of the Labour Code), which further elaborate on the duties of employees and the employer. These documents are usually issued unilaterally by the employer and form the basis of employment relationships within the company.
The problem is that these traditional documents were designed for a world where decisions were made by people. They contain no provisions that address the specific challenges of AI:
Rules for managing data used to train AI.
Policies for employee interaction with generative AI.
Protocols for mandatory human oversight of algorithmic decisions.
The duty of transparency towards employees regarding the use of AI.
Incident response plans for when AI fails or generates discriminatory results.
Relying on existing work regulations to govern AI is like using a 19th-century map to navigate a modern highway network. It's not just outdated; it's dangerously misleading.
Creating a Robust AI Policy for HR: Key Components
Creating a comprehensive AI Governance Policy is a task that requires not only technical but, above all, legal expertise. ARROWS specializes in drafting these new types of documents, which must contain the following key components to be effective and legally sound:
Purpose and Scope: The policy must clearly define which AI tools are approved for use in the company, in which specific HR processes (recruitment, performance evaluation, etc.), and for what specific purpose (e.g., accelerating recruitment, reducing administrative burden).
Data Handling and Privacy: It must contain strict rules on what data (especially personal or confidential) can and cannot be entered into AI tools. It is necessary to mandate data anonymization or pseudonymization wherever possible to minimize risk under GDPR.
Human Oversight Protocol: The policy must define a "human-in-the-loop" process. It must specify at what stage a human must review and approve AI recommendations. A key provision is that the final decision with legal consequences (e.g., hiring, dismissal) is always made by a responsible and trained person, not a machine.
Transparency and Information Duty: The policy must enshrine the commitment to inform applicants and employees if an AI system is used to make decisions that affect them. This is a direct requirement of the AI Act.
Audit and Bias Monitoring: It must include an obligation for regular testing and monitoring of AI outputs to detect and mitigate any systematic bias.
Incident Response: Clear procedures must be defined in case an AI system fails, generates discriminatory results, or causes a data breach. It must be clear who has the authority to suspend the system, who must be informed (legal department, data protection officer, IT security), and how to carry out remediation.
Accountability: The policy must clearly state that its violation is considered a serious breach of work duties, which may lead to disciplinary action, including possible termination of employment. This firmly anchors the new rules within the existing labor law framework.
How to Do It in Practice: Integrating AI Rules into the Existing Policy Framework
A practical question arises: should the AI policy be a standalone document, or should it be integrated into existing regulations, such as the work regulations or the data protection policy?
The recommended approach, which we at ARROWS advocate, is a hybrid model. This approach combines clarity and legal force:
Create a central, overarching AI Governance Policy. This document will regulate all the above-mentioned aspects in detail and serve as the main source of rules for the entire company.
Integrate references and key provisions into existing documents. This ensures that the new rules are legally enforceable and consistent with the entire internal legal framework of the company.
The work regulations will be amended to include a provision that "a violation of the AI Governance Policy constitutes a serious breach of employee duties."
The data protection (GDPR) policy will be updated with chapters on data processing for AI purposes, with a reference to the main AI policy for detailed rules.
Onboarding documents and employment contracts must now include information for employees about the use of AI in HR processes, as required by both the Labour Code and GDPR.
This integrated approach ensures consistency, clarity, and legal enforceability. The team at ARROWS has the expertise not only to draft the key AI policy but also to carry out the necessary review and amendment of all related company documents, thereby creating a seamless and legally sound governance framework.
A Strategic Approach to AI Implementation: From Audit to Deployment
This final section provides company leadership with a clear and practical plan for how to approach the safe and effective implementation of artificial intelligence.
First Step: A Comprehensive Legal and Technical Audit
Before you can effectively govern AI, you need to know what AI you are even using in your company. The first step is therefore a comprehensive audit of all existing software tools and processes to identify any built-in or standalone AI tools. Special attention must be paid to so-called "shadow IT"—tools that employees use without official approval.
ARROWS offers an AI Regulatory Compliance Audit as a key service. This audit includes:
Inventory: Identification of all AI systems the company uses, whether knowingly or unknowingly.
Risk Classification: Determining which of these systems fall into the "high-risk" category under the AI Act.
Gap Analysis: Comparing existing practices with the requirements of the AI Act and GDPR to identify specific compliance gaps.
Remediation Plan: Providing a concrete, prioritized list of steps to be taken to close the identified gaps and achieve full compliance.
Vetting Suppliers: Questions You Must Ask Your AI Provider
Companies often accept suppliers' claims and their standardized contracts without deeper scrutiny. In the age of AI, this approach is unacceptable and dangerous. Thorough due diligence is absolutely essential, and the technology procurement process must now always involve the legal department or external legal counsel.
The following table serves as a practical checklist for company management. It contains key questions to ask every AI tool supplier. The ARROWS team helps clients not only with formulating these questionnaires but, more importantly, with negotiating contracts to include key clauses on data processing, liability, indemnification, and the right to audit.
Category | Key Questions for the AI Supplier |
Compliance and Certification | Can you provide documentation of conformity assessment with the AI Act for this high-risk system? How do you ensure compliance with GDPR? |
Data and Privacy | Where is our data physically stored? Is our data used to train your public models? What data anonymization and encryption techniques do you use? |
Bias and Fairness | How was the model trained and what data was used? Can you provide the results of independent audits focused on algorithmic bias? What mechanisms do you have for mitigating identified biases? |
Transparency and Explainability | Can you explain how the model arrives at its recommendations? What level of human oversight do you recommend or require for this tool? |
Liability and Contract | What are your liability limits in the event of a data breach or a discriminatory outcome caused by your tool? Will you indemnify us in the event of third-party lawsuits arising from the use of your product? |
The Human Factor: The Key Role of Employee Training and AI Literacy
AI implementation is not just about technology and rules; it is primarily about people. The human factor is key both for successful utilization and for risk management.
A Legal Requirement: The AI Act explicitly requires that personnel overseeing high-risk AI systems have the necessary competence, training, and authority. It also mandates a general level of "AI literacy" for employees who work with these systems. Training is therefore no longer optional but a legal obligation.
More Than Just Compliance: Training is also a critical risk mitigation tool. Employees must understand the company's AI policy, comprehend the risks of data leakage, and know how to use AI tools responsibly and ethically. They must be able to recognize when an AI output seems suspicious and know who to turn to in such a case.
The Role of Legal Counsel in Training: Although ARROWS is not a training agency, it provides the key legal component of these training sessions. Our lawyers can clearly explain to employees the "why" behind the rules—that is, the real legal and financial consequences of non-compliance. This increases the impact and effectiveness of the entire training program, as employees understand the gravity of the situation.
The Future of Work is Here. Are You Ready?
The integration of artificial intelligence into HR processes represents a fundamental paradigm shift. It offers enormous opportunities for increasing efficiency and decision-making quality, but at the same time, it brings risks that can threaten the very existence of a company. The old ways of managing legal and operational risks are obsolete and insufficient in this new era.
As this report has shown, the threats are complex and interconnected. They involve a convergence of draconian fines under the AI Act, high penalties under GDPR, costly civil lawsuits, and irreparable reputational damage. Relying on the hope that these problems do not concern you, or that the technology provider bears the responsibility, is a strategy doomed to fail.
However, a proactive legal strategy should not be seen merely as a defensive measure. On the contrary, it is a source of competitive advantage. Companies that master AI governance will be able to use these powerful tools safely and effectively, while their unprepared competitors will struggle with legal battles, regulatory interventions, and a loss of trust.
The future of HR is intelligent, but intelligence without wisdom is dangerous. Let the expert legal team at ARROWS provide you with the strategic wisdom your business needs to thrive in the age of artificial intelligence. Contact us today for a confidential consultation and an assessment of your company's readiness for the challenges that AI brings.
About the author
Disclaimer:
The information contained in this article is for general informational purposes only and serves as a basic guide to the issue as of 2026. Although we strive for maximum accuracy, laws and their interpretation evolve over time. We are ARROWS Law Firm, a member of the Czech Bar Association (our supervisory authority), and for the maximum security of our clients, we are insured for professional liability with a limit of CZK 350,000,000. To verify the current wording of the regulations and their application to your specific situation, it is necessary to contact ARROWS Law Firm directly (consultation@arws.cz). We are not liable for any damages arising from the independent use of the information in this article without prior individual legal consultation.

