Skip to content

Can an employer prohibit the use of AI?

Legal Framework, Risks, and Protection for Your Business

Mgr. Jan Pavlík
Published:Updated:

An employer can restrict or prohibit the use of AI within the company and specify which tools employees are allowed to use, as long as these rules comply with Czech labor law. The policy should address approved tools, the input of personal and confidential data, the review of outputs, and liability. This article explains how to set up AI rules, how to protect company data, and why managed use is safer than an uncontrolled ban or unrestricted freedom.

The picture shows an attorney providing advice on the prohibition of AI use in companies.

Key takeaways

You are liable for damages caused by an employee's use of AI. If your employee uses AI and causes a data leak, copyright infringement, or makes erroneous decisions, your company is held responsible, not the employee.
Unregulated use of AI threatens your company's existence. Uncontrolled AI tools can lead to ruinous fines for GDPR violations or the irreversible loss of trade secrets, which constitutes a failure to act with due managerial care.
The Labour Code grants you the authority to govern the use of AI. The Czech Labour Code is a powerful tool for regulating AI within a company, as it allows you to organize, manage, and control your employees' work.
Rely on Section 301(a) of the Labour Code. This provision unequivocally establishes the employer's right to set the rules of the game and require employees to follow instructions, which includes the regulation of AI tools.
ARROWS law firm

Artificial Intelligence at Work: A Silent Partner or a Ticking Time Bomb?

The problem is that while the benefits of AI are immediately apparent, the threats are hidden in legal details, license terms, and the technical functioning of these tools. The issue is not whether to ban or permit AI. The key question for every responsible manager and business owner is different: How do we manage the use of AI in the company to prevent fatal consequences?

The fundamental legal principle is relentless: the employer is liable for damage caused by an employee in the performance of their work. If an employee uses AI as a work tool and causes damage—whether through a data leak, copyright infringement, or a poor decision based on AI output—the company bears the responsibility. Given the enormous scale of potential damages, from crippling fines for GDPR violations to the irreversible loss of trade secrets, regulating AI is becoming not an option, but a direct obligation.

Ignoring this issue is not a strategic decision, but a failure in the basic duty of due managerial care. Inaction in this area exposes your company to risks that can threaten its stability, reputation, and very existence. The goal is not to stifle innovation, but to manage it so that it serves the company, rather than endangering it.

Your Key Tool: Support in the Labour Code

Many employers feel helpless in the face of the uncontrolled spread of AI tools among employees. However, the Czech Labour Code gives you strong and clear tools to manage this situation. The key is to understand your rights and apply them correctly in practice. It is you who sets the rules of the game, not your employees or AI providers.

How does the Labour Code give you the right to manage employees' work?

The cornerstone of the employment relationship is its nature—it is a relationship of the employer's superiority and the employee's subordination. This principle gives you the right to organize, direct, and control work. The employee is obliged to follow these instructions.

Legal support can be found in Section 301(a) of the Labour Code, which clearly states that employees are obliged to "follow the instructions of superiors issued in accordance with legal regulations." This instruction can take the form of a direct order, but also a more general rule set out in an internal directive. An instruction prohibiting the use of specific software tools (including public AI models) or, conversely, mandating the use of only an approved company tool is entirely legitimate. The employee is not entitled to judge its business logic or meaningfulness; if the instruction complies with the law, they must follow it.

Can you monitor and prohibit the private use of company resources?

Yes, and unequivocally so. A company computer, software, internet connection, and other work equipment are the property of the employer. Their use for private purposes is possible only with your express consent.

This authority is enshrined in Section 316(1) of the Labour Code, which states that employees "may not use the employer's production and work equipment, including computer technology, for their personal needs without the employer's consent." The law also gives you the right to "monitor compliance with this prohibition in a reasonable manner." This provision is directly applicable to a situation where an employee uses freely available versions of AI tools on a company computer, whether for work or private purposes.

How is asset protection related to the use of AI?

The concept of "assets" in the 21st century extends far beyond physical items. The greatest wealth of a modern company is its data, know-how, client databases, and trade secrets. It is precisely these intangible assets that are most at risk from the uncontrolled use of AI.

Here too, the Labour Code provides you with protection. According to Section 301(d) of the Labour Code, an employee is obliged to "guard and protect the employer's property from damage, loss, destruction, and misuse." Inserting sensitive company data into public AI platforms is a direct breach of this duty. Your right to monitor for the purpose of protecting property is further confirmed by Section 248(2) of the Labour Code. Regulating the use of AI is therefore not merely an exercise of your authority, but the fulfillment of your duty to protect company assets.

The team of lawyers at ARROWS helps clients daily, including more than 150 joint-stock companies and 250 limited liability companies, to correctly formulate these powers in employment contracts and internal regulations to make them legally watertight.

Specific Risks of Uncontrolled AI: What Are the Real Threats?

Understanding the theoretical rights is the first step. The second, and crucial for business, is to be aware of the specific, tangible risks that arise from the uncontrolled use of AI. These are not abstract threats, but real scenarios that can cost your company millions, damage its reputation, and destroy its competitive advantage.

Leakage of Trade Secrets and Sensitive Data

This is the biggest and most serious risk. In an effort to save time, an employee copies an internal document into the window of a publicly available AI chat—a financial plan, a strategy for the next quarter, a list of key clients, software source code, or a draft of a new marketing campaign. At that moment, you lose all control over this data.

Providers of free AI tools often reserve the right in their terms and conditions to use the data you input to "train" their models. Your trade secret can thus become part of a database from which your competitors also draw.

This leads to the irreversible devaluation of your most valuable know-how and a breach of all non-disclosure agreements (NDAs) you have signed with clients and partners. ARROWS can help set up technical and legal measures, including the preparation of robust non-disclosure agreements (NDAs) and internal policies that minimize this risk.

GDPR Violations and the Threat of Crippling Fines

Any data that can identify a natural person (name, email, phone number, but also a job title in combination with other information) is personal data protected by the GDPR. Employees work with this data daily. Using AI to process it is a ticking time bomb.

Imagine an HR manager inputs applicants' CVs into an AI tool to help evaluate them. Or a salesperson uploads meeting minutes containing clients' names and opinions to an AI to have a summary created. In both cases, personal data is being processed and transferred to a third party (the AI provider). If this provider is not contractually bound as a data processor in accordance with GDPR, this constitutes unlawful processing.

You face a fine of up to 4% of your company's total worldwide annual turnover. A legal consultation with ARROWS will help you identify processes where there is a risk of GDPR violation and prepare the necessary documentation, such as a Data Protection Impact Assessment (DPIA).

Loss of Control Over Intellectual Property

Your company invests considerable resources in creating content—marketing texts, graphics, logos, software code. If an employee uses AI to create them, a fundamental legal problem arises. Under Czech copyright law, only a natural person can be an author; the work must be the unique result of a person's creative activity.

Output generated by artificial intelligence without significant creative human intervention does not meet these conditions. The result is that your company does not own the copyright to the content it paid for. You cannot effectively protect it against copying by competitors, and you cannot grant licenses to it. Moreover, there is a second risk: the AI was trained on a huge amount of data from the internet, much of which was protected by copyright. The output you generate may thus be an unintentional plagiarism or a derivative work, exposing you to lawsuits from the original authors.

Our intellectual property specialists at ARROWS will help you analyze the terms of use of AI tools and set up processes to minimize the risk of infringing others' rights and to protect your investments.

Who Bears Responsibility for Damages Caused by an AI Error?

AI tools, especially language models, are prone to so-called "hallucinations"—generating factually incorrect, misleading, or completely fabricated information. What happens when your employee relies on such faulty output?

Imagine a financial analyst uses AI for a market analysis that turns out to be wrong, and the company makes a loss-making investment based on it. Or a legal assistant has an AI prepare a draft contract that contains a critical error damaging your company. Who is responsible for this? The answer is clear: you, as the employer.

From a legal perspective, AI is merely a tool, similar to a calculator or a text editor. The employee is fully responsible for its correct use and for checking its outputs, and by extension, the employer. ARROWS can represent you in potential disputes and help set up contractual relationships with AI suppliers to transfer part of the liability to them.

Risks and Penalties

How ARROWS Helps

Disclosure of trade secrets: Inputting internal strategies or client data into a public AI leads to loss of competitive advantage, breach of NDAs, and lawsuits.

We will prepare internal policies prohibiting the input of sensitive data and train employees on the risks.

GDPR violation: Processing personal data (e.g., CVs) in a non-compliant AI tool. Risk of fines up to 4% of turnover and reputational damage.

We will draft a legal opinion on GDPR, prepare an impact assessment (DPIA), and review contracts with AI suppliers.

Inability to claim copyright protection: Creating logos and texts with AI that cannot be legally protected. Risk of uncontrolled copying and loss of investment.

We will assess the license terms of AI tools and prepare contracts with creators to reliably secure rights.

Liability for faulty AI output: A flawed financial or other analysis from AI leading to a loss-making investment, damages, and third-party claims.

We will review supplier contracts for clear allocation of liability and represent you in disputes over damages.

Phishing and cyberattacks: Misuse of AI to create sophisticated phishing that deceives employees and causes data leaks or ransomware.

We will conduct expert training for employees on cybersecurity and threat recognition (with certification).

Discrimination in recruitment (AI Act): Disadvantaging applicants through HR tools using AI. Risk of discrimination lawsuits and fines under the AI Act.

We will conduct a legal audit of HR processes according to the AI Act and draft policies for non-discriminatory use of AI.

Infringement of third-party rights: AI generates output that is a derivative of a protected work. Risk of lawsuits for copyright infringement and content takedowns.

We will provide a risk analysis of generative content and represent you in any intellectual property disputes.

ARROWS law firm

A Solution Exists: How to Set Clear and Legally Enforceable Rules

In the face of the risks described above, it is clear that a "do nothing" strategy is unsustainable. The only way forward is proactive regulation. You don't have to ban AI across the board, but you must establish clear rules for its use. The basic and absolutely essential tool for every company is the introduction of an internal policy.

Why is an internal policy a necessity, not an option?

Imagine that an employee, despite your verbal warnings, causes damage through a data leak via AI. You want to terminate their employment for breach of work duties. However, you will run into trouble in court. If you do not have a clear, written, and demonstrably established rule that the employee violated, your chances of success in an employment dispute are minimal.

A well-drafted internal policy is not just a set of rules; it is your legal shield. It serves as key evidence that you, as the employer, have fulfilled your duty of prevention. It proves that you have properly instructed employees about the risks and established binding procedures. In the event of a dispute with a regulator (e.g., the Office for Personal Data Protection) or during court proceedings, the existence and enforcement of such a policy is a crucial factor that can significantly reduce the amount of any penalties and protect management from personal liability.

Our lawyers at ARROWS specialize in drafting internal policies that are not only practical but, above all, legally enforceable and serve as an effective shield against liability.

Our specialists will help you

Mgr. Jakub Oliva, LL.M., MSc.

Mgr. Jakub Oliva, LL.M., MSc.

advokát, partner

oliva@arws.cz
ARROWS law firm

What Must an Effective AI Use Policy Contain?

For a policy to be effective, it must be comprehensive, understandable, and specific. A general statement like "use AI responsibly" is not enough. An effective policy must contain at least the following points:

  • Purpose and Scope: A clear definition of who and what activities the policy applies to.

  • List of Approved and Prohibited Tools: Explicitly state which AI tools (e.g., a paid corporate version) are permitted and which (e.g., all publicly available free versions) are strictly prohibited.

  • Rules for Data Input: A crucial section. It must include a strict prohibition on inputting any personal data, trade secrets, and confidential information into unapproved AI tools.

  • Duty of Human Review: Establish an obligation for every employee to critically verify
    and check any output generated by AI before its further use. AI is a tool, not an authority.

  • Copyright and Ownership of Outputs: Explain the legal status of AI outputs to employees and define how to handle them.

  • Liability and Sanctions: Clearly define what is considered a breach of the policy and what consequences (from a reprimand to termination of employment) result from it.

ARROWS offers not just templates, but the complete preparation of a policy tailored to your company, including checklists for implementing new tools that will ensure compliance with legal regulations and minimize your risks.

Frequently Asked Questions on the Practical Management of AI and the Labour Code

1. Can an employer completely ban the use of free public AI tools on company devices?

  • Yes. According to Sections 301 and 316 of the Czech Labour Code, the employer has the full right to organize work, determine permitted work equipment, and prohibit the use of computer technology for unapproved or personal purposes.

2. How can an employee who violates the ban and inputs sensitive data into a public AI be disciplined?

  • If the company has a written and demonstrably communicated internal policy, it is a breach of work duties. The employer can issue a written warning, demand compensation for damages under the Labour Code, or, in serious cases, terminate the employment relationship.

3. What key elements must a corporate AI policy contain to be legally enforceable?

  1. The policy must include a precise list of approved and prohibited tools, an explicit ban on inputting personal data and trade secrets, a duty of human review for all generated outputs, and clearly defined sanctions for its violation.

ARROWS law firm

Are You Ready for the AI Act? New Obligations for Companies in the EU

The regulation of AI is rapidly moving from recommendations to hard law. The key regulation is the EU Artificial Intelligence Act (AI Act), which introduces new, EU-wide obligations for companies using AI.

The AI Act classifies AI systems according to their level of risk. Crucially for companies, the use of AI in human resources (HR)—for example, for recruitment, selection, performance evaluation, or decisions on promotion or termination of employment—is explicitly classified as a high-risk system. For you as an employer, this means new obligations, including:

  • Conducting impact and risk assessments before deploying the system.

  • Ensuring high-quality human oversight of the AI's operation and decision-making.

  • Maintaining detailed technical documentation and records of the system's activity.

  • Ensuring so-called "AI literacy" for all employees who work with or oversee these systems.

The AI Act is not a distant prospect; parts of it are already coming into force. You need to prepare for it now. Thanks to our international network, ARROWS International, we monitor the development of EU legislation in real time and are ready to help you implement the requirements of the AI Act, so you can avoid penalties and stay one step ahead of the competition.

Protect Your Company with Experts Who Understand Your Business and the International Environment

Regulating the use of artificial intelligence in a company is not about stifling innovation. It is about professionally managing fundamental legal and financial risks that can threaten the stability and future of your business. As this article has shown, inaction is the most expensive and riskiest option.

The ARROWS law firm provides comprehensive legal services to guide your company safely through the era of artificial intelligence. Our services include everything from an initial legal consultation and detailed risk analysis, through the preparation of all necessary documentation (internal policies, employment contracts, addendums, non-disclosure agreements, legal opinions), to expert training for your employees and management to familiarize them with the risks and rules. If a problem has already arisen, we are prepared to represent you effectively in courts and before administrative authorities.

Our experience is backed by long-term cooperation with a client portfolio that includes more than 150 joint-stock companies and 250 limited liability companies. We pride ourselves on speed, high quality, and a deep understanding of our clients' business needs.

Thanks to the international network ARROWS International, built over ten years, we handle cases with an international element daily and bring our clients global know-how and a perspective that is absolutely key in a field as dynamic as AI. We are also happy to connect our clients if we see interesting business or investment synergies, and we are always keen to hear interesting business ideas ourselves.

Don't wait for a risk to turn into a real problem. Contact us today and secure your legal certainty in the age of artificial intelligence. The ARROWS team is ready to protect your interests in the Czech Republic and abroad.

Frequently Asked Questions on Legal Risks, GDPR, and the European AI Act

1. Who is legally liable for damages if an AI tool generates a faulty output and the company acts on it?

  • The employer is fully liable. From a legal perspective, artificial intelligence is merely a work tool (like a calculator or software). The company is responsible for checking the outputs and for any damage caused to third parties.

2. Is text or graphics generated purely by AI protected by copyright?

  • No. Under Czech copyright law, only a natural person can be an author. Pure output from an AI without significant creative human intervention cannot be protected by copyright, and there is also a risk that the AI has unintentionally generated plagiarism.

3. What fines does a company face for a GDPR violation by using an unapproved AI?

  • For unlawfully inputting personal data (e.g., applicant CVs or client databases) into an AI tool without a data processing agreement, there is a risk of administrative fines from the Office for Personal Data Protection of up to 20 million EUR or 4% of the company's total worldwide annual turnover.

4. Why does the European AI Act also affect regular companies that use AI in HR and recruitment?

  • The AI Act classifies systems used for recruitment, evaluation, or decision-making about employees as high-risk. It therefore requires human rights impact assessments, a duty of human oversight, technical documentation, and ensuring AI literacy among workers.

5. Can the provider of a free AI tool keep the company data that is input?

  • Yes. Most operators of free AI platforms reserve the right in their license terms to use the input data for training their models. Inputting data thus leads to a permanent loss of control over trade secrets.

6. What is the best way to prepare a company for the regulatory requirements associated with artificial intelligence?

The foundation is to conduct a legal and process audit of the tools used, adopt a binding internal AI policy, review supplier contracts and license terms, and regularly train employees on cybersecurity and the AI Act.

DO YOU HAVE MORE QUESTIONS? GET IN TOUCH

ARROWS law firm

About the author

Mgr. Jan Pavlík
Mgr. Jan Pavlík

Associate

Jan Pavlík is an experienced attorney who focuses on resolving complex situations in corporate life. At Arrows Law Firm, he primarily deals with corporate law, labor law, commercial disputes, and contractual matters.

Disclaimer:

The information contained in this article is for general informational purposes only and serves as a basic guide to the issue as of 2026. Although we strive for maximum accuracy, laws and their interpretation evolve over time. We are ARROWS Law Firm, a member of the Czech Bar Association (our supervisory authority), and for the maximum security of our clients, we are insured for professional liability with a limit of CZK 350,000,000. To verify the current wording of the regulations and their application to your specific situation, it is necessary to contact ARROWS Law Firm directly (consultation@arws.cz). We are not liable for any damages arising from the independent use of the information in this article without prior individual legal consultation.