Skip to content

Zaměstnanci a AI nástroje

Na obrázku vidíte specialistu na právní aspekty využívání AI nástrojů v zaměstnání.

Key takeaways

AI literacy training is mandatory for employers. When designing it, you must consider the specific job positions, the technical knowledge of your employees, and the context in which AI tools are used within your company.
Unmonitored use of AI tools by employees poses a serious risk of data leakage. Up to 89% of interactions with generative AI occur without IT oversight, and 72% of employees use private accounts, leading to the uncontrolled sharing of sensitive company information.
You lose control over data entered into public AI tools. Once sensitive company data, such as financial plans or customer information, is submitted, it becomes part of the training datasets and may be made accessible to other users.
Employees violate the Labour Code by sharing company data with AI. Entering sensitive information into AI tools constitutes a breach of the duty to protect the employer's property under Section 301(d) of the Labour Code. Furthermore, the employer has the right to prohibit the use of AI tools under Section 316(1) of the Labour Code.
ARROWS law firm

Why You Can No Longer Ignore AI in Your Company

The obligation to provide training is not just a formality. The law requires that when determining the scope of education, you consider specific job positions, the technical knowledge of employees, and the context in which they use AI tools. For the lawyers at ARROWS, preparing training and educational materials on AI literacy is a regular part of their work – if you need help setting up a training program.

What Legal Risks Does Uncontrolled Use of AI Bring?

The phenomenon of so-called Shadow AI represents one of the biggest threats to corporate security. According to surveys, up to 89% of employee interactions with generative AI occur without the oversight of the IT department, and 72% of workers use AI tools from private accounts. Half of all content entered into these systems contains sensitive company data, including financial plans, customer data, or source code.

A practical example shows how quickly a problem can arise: in 2023, three employees of an unnamed technology company entered sensitive corporate data into a generative AI tool over just a few weeks, including internal documents and confidential information about product development. The company subsequently had to implement strict measures restricting the use of generative AI throughout the organization.

Once you enter information into a public AI tool, you lose control over it. The data becomes part of the training datasets and can potentially be made available to other users. This constitutes a direct breach of the employee's duty to guard and protect the employer's property under Section 301(d) of the Labour Code.

Related questions on protecting company data

1. Can an employer prohibit the use of AI tools?

Yes, Section 316(1) of the Labour Code gives the employer the right to determine which tools employees may use at work, including prohibiting specific AI applications. 

2. What are the consequences for an employee who discloses a trade secret via AI?

The employee is liable for damages caused by a culpable breach of duties, and compensation can reach up to 4.5 times their average earnings.

ARROWS law firm

Internal Policy: The Foundation of Legal Protection for the Employer

A well-drafted internal policy for the use of AI is not just a set of rules – it serves as key evidence that the employer has fulfilled its preventive duty and properly informed employees about the risks. The policy should cover several fundamental areas.

Defining permitted and prohibited AI tools is the first step. Create a list of approved applications and clearly state which tools are banned for company use. For each permitted tool, specify its purpose and conditions of use.

Rules for handling data must unequivocally define what information employees are not allowed to enter into AI systems. Prohibited categories typically include personal data, trade secrets, source codes, financial data, client information, and internal strategies. Entering the personal data of third parties into public AI platforms is a direct violation of GDPR.

An approval process for new tools ensures that every new AI system undergoes a security and legal assessment before deployment. This will prevent the uncontrolled spread of Shadow AI within the company.

The ARROWS law firm prepares internal policies for AI use tailored to the specific needs of the client. Thanks to our experience with over 150 joint-stock companies and 250 limited liability companies in our portfolio, we can set rules that are practically enforceable while meeting all regulatory requirements. Contact us and get a tailor-made legal solution.

Liability for Damage Caused by Artificial Intelligence

Current Czech legislation does not grant legal personality to artificial intelligence. The person or entity using the tool is always responsible for all decisions and outputs of AI systems. If an employee uses AI as a work tool and causes damage – whether through a data leak, copyright infringement, or a faulty decision – the employer bears the liability.

From a civil law perspective, Section 2910 of the Civil Code on liability for damage caused by a breach of a statutory duty applies. Section 2936 of the Civil Code then stipulates that whoever is obliged to perform something for someone and uses a defective item in the process is liable for the damage caused by the defect of that item – which can also be applied to the implementation of a faulty AI system.

Our specialists will help you

JUDr. Jakub Dohnal, Ph.D., LL.M.

JUDr. Jakub Dohnal, Ph.D., LL.M.

advokát, řídící partner

dohnal@arws.cz
Mgr. Jan Pavlík

Mgr. Jan Pavlík

advokát

jan.pavlik@arws.cz
ARROWS law firm

In employment relationships, the employer is liable for damage caused to an employee in connection with the performance of work tasks. This liability is conceived in the Labour Code as strict liability, i.e., regardless of fault. The employer cannot be exonerated by claiming that the error was on the part of the AI.

Potential Problems

How ARROWS Helps (consultation@arws.cz)

Leak of trade secrets via an AI tool – breach of NDA, loss of competitive advantage, litigation

Preparation of internal policies and employee training

GDPR breach by entering personal data into AI – fine of up to 4% of global turnover

Legal audit of processes and preparation of a DPIA

Faulty AI output leading to financial loss – employer's liability for damages

Review of contracts and setting up liability mechanisms

Discrimination in recruitment caused by an AI algorithm – employee lawsuits, reputational damage

Representation in labour law disputes and preparation of non-discriminatory processes

ARROWS law firm

What Requirements Must High-Risk AI Systems in HR Meet?

The AI Act classifies all artificial intelligence systems used in the field of human resources as high-risk. This category includes tools for analysing CVs, evaluating candidates, monitoring employee performance, making decisions about promotions, or assigning tasks based on personality traits.

As of 2 August 2026, strict obligations for the operators of these systems will come into force. Employers will have to ensure human oversight of AI by competent persons, continuously monitor the system's operation, and keep automatically generated logs for a minimum of six months. There is also an obligation to inform employee representatives and the affected workers that they are subject to an AI system before it is deployed.

Violation of the rules for high-risk systems can lead to fines of up to EUR 15 million or 3% of the total worldwide annual turnover. The deployment of prohibited AI practices carries penalties of up to EUR 35 million or 7% of turnover.

In practice, this issue is significantly more complex than it may seem at first glance. The classification of a specific AI tool requires a detailed legal analysis that considers not only the functionality of the system itself but also the context of its use and its connections to other regulations.

The ARROWS law firm handles this agenda daily and can significantly shorten the time required for a client to achieve regulatory compliance. Moreover, we are insured for damages up to CZK 500,000,000, making it safer for the client to entrust the matter to professionals.

How to Handle GDPR When Using AI Tools?

The processing of personal data through AI systems is fully subject to the requirements of the GDPR. A key provision is Article 22, which gives data subjects the right not to be subject to a decision based solely on automated processing if it produces legal effects concerning them or similarly significantly affects them.

In practice, this means for employers that an AI system can only issue recommendations – the final decision on hiring a candidate, termination, or the amount of remuneration must be made by a human. A violation of this rule carries the risk of a penalty of up to EUR 20 million or 4% of the total worldwide turnover.

Before deploying an AI tool that processes employees' personal data, it is in many cases necessary to conduct a Data Protection Impact Assessment (DPIA). This obligation arises in particular for systematic evaluation of personal aspects, large-scale processing of sensitive data, or the use of innovative technologies.

A DPIA for AI systems must include the identification and assessment of risks to the data subjects, an analysis of the proportionality and necessity of the processing, an assessment of measures to minimise risks, and mechanisms for exercising the rights of data subjects. The French supervisory authority CNIL also recommends conducting a DPIA for the development of all foundation models and general-purpose AI systems if they involve the processing of personal data.

Related questions on GDPR and AI

1. Do I have to inform employees about the use of AI for monitoring?

Yes, Section 316 of the Labour Code requires prior notification to employees if there is a serious reason for monitoring. At the same time, the information obligations under Articles 13-15 of the GDPR apply.

2. Can AI be used for psychological profiling of job applicants?

Section 30(2) of the Labour Code limits the collection of data before the start of an employment relationship to only information directly related to the conclusion of the contract. Psychological profiling typically exceeds these limits.
ARROWS law firm

Copyright and AI: Who Owns the Generated Content?

The question of copyright for content created by artificial intelligence remains unclear in many respects, but the basic principles are already established. Under the Czech Copyright Act, only a natural person can be an author, and the work must be the unique result of a human's creative activity. Czech courts have already confirmed that content generated purely by artificial intelligence does not meet the conceptual characteristics of a copyrighted work.

In the European Union, the general approach is that copyright is not granted to AI creations if the work completely lacks human contribution. The U.S. Copyright Office has taken a similar stance – a work created exclusively by AI is not eligible for copyright registration.

This has practical implications for employers. If an employee creates content using AI as an auxiliary tool but actively intervenes in the creation – editing, modifying, combining outputs, and introducing their own creative elements – the result may be protected by copyright. To preserve protection, it is advisable to document the creative process and the degree of human contribution.

We recommend explicitly regulating the ownership of AI tool outputs and the rules for their use in the employment contract or internal policy. In the EU, an employer owns a work created by an employee only if the employment contract explicitly states so.

How to Implement Safe Use of AI in Your Company Step by Step?

Implementing AI governance requires a systematic approach. The first step is to map the current situation – find out what AI tools are already being used in the company, who works with them, and what data is being entered into them. Be aware that some usage occurs outside official channels.

The second step is to categorise use cases by risk level. Distinguish between prohibited use (sensitive data, regulatory documents), restricted use (internal documents with supervisor approval), and free use (brainstorming, formatting public data).

The third step is the preparation of documentation – internal policies, addendums to employment contracts, informational materials for employees. The fourth step is training, which must be tailored to different roles and levels of technical knowledge.

The fifth step is the implementation of technical measures – monitoring the use of AI tools, DLP (Data Loss Prevention) solutions, central access management. The sixth step is to establish an ongoing audit and update the rules according to the development of technology and regulation.

The entire process has many hidden pitfalls and connections to other regulations that a layperson often does not see. We commonly partner with corporate lawyers to resolve special issues in the area of AI compliance – if you do not want to risk mistakes or fines, contact us at consultation@arws.cz.

Potential Problems

How ARROWS Helps (consultation@arws.cz)

Deployment of a high-risk AI system without meeting requirements – fine of up to EUR 15 million

Legal audit of AI systems and preparation of compliance documentation

Automated decision-making without human oversight – violation of Article 22 of the GDPR

Setting up processes with mandatory human review

Lack of transparency towards employees – violation of the Labour Code and GDPR

Preparation of information documents and updating of employment documentation

Use of prohibited AI practices – fine of up to EUR 35 million or 7% of turnover

Legal assessment of AI systems and identification of prohibited practices

ARROWS law firm

International Aspects: When Do You Need a Global Perspective?

If your company operates in multiple countries or employs workers from different jurisdictions, the situation becomes more complicated. AI regulation varies significantly from country to country – while the EU has adopted the comprehensive AI Act, the USA does not yet have federal legislation, but individual states are adopting their own rules. New York City, for example, has required independent audits of AI algorithms used in recruitment since 2023.

The ARROWS law firm provides legal services in the field of AI compliance outside the Czech Republic as well, thanks to the ARROWS International network, which we have been building for ten years. We handle cases with an international element on a daily basis and can coordinate legal advice across jurisdictions. If you are looking for a partner to handle AI governance at an international level, contact our firm.

Should you find an interesting investment or business opportunity in the field of AI technologies, we will be happy to connect you with relevant partners from our portfolio. Likewise, we are always keen to hear about interesting business ideas in this dynamically developing area.

Timeline: What to Expect and When

The implementation of the AI Act is taking place gradually according to a precisely defined schedule:

2 February 2025 – The obligation for AI literacy and the bans on dangerous AI practices will come into force.

2 August 2025 – The rules for providers of general-purpose AI (GPAI) models will apply, and member states must designate the relevant supervisory authorities.

2 August 2026 – Most of the AI Act's rules will become effective, including the requirements for high-risk systems, and enforcement by supervisory authorities will begin.

2 August 2027 – Full effectiveness of the rules for high-risk AI systems embedded in regulated products.

Waiting until the last minute is a risky strategy. Preparing compliance documentation, training employees, and making technical process adjustments take time. Starting preparations well in advance also allows for any complications to be resolved without time pressure.

Conclusion: Safe Use of AI Requires Legal Preparation

Using artificial intelligence in the workplace brings undeniable benefits in the form of increased productivity and efficiency. At the same time, however, it creates complex legal risks that require a systematic approach. From sensitive data leaks and GDPR violations to penalties under the AI Act – each of these risks can cause significant financial and reputational damage.

The ARROWS law firm has a specialised team that has been focusing on AI compliance for a long time. We prepare internal policies, provide employee training with a certificate of AI literacy, conduct legal audits of AI systems, and represent clients in proceedings with supervisory authorities. Thanks to our liability insurance of up to CZK 500,000,000, you can entrust the entire matter to professionals with the assurance that any potential errors are covered.

If you do not want to risk fines, damages, or legal disputes associated with the incorrect use of AI in your company, contact us. We will handle the entire matter safely for you.

FAQ – Most Common Legal Questions on Using AI in the Workplace

1. Must every company have an internal policy for AI use?

The law does not explicitly require the adoption of a policy, but its existence is key evidence of the employer's fulfillment of its preventive duty. Without clear rules, the employer is exposed to the risk of bearing full liability for any damages caused by the uncontrolled use of AI.

2. What are the penalties for violating the AI Act?

Penalties are graded according to the severity of the violation: for deploying prohibited AI practices, up to EUR 35 million or 7% of turnover; for violating the rules for high-risk systems, up to EUR 15 million or 3% of turnover; for providing false information, up to EUR 7.5 million or 1% of turnover. 

3. Can an employee refuse to use AI tools?

An employee is obliged to follow the employer's instructions regarding the performance of work. If the employer mandates the use of a certain AI tool, the employee generally cannot refuse it without a serious reason. At the same time, however, the employer must provide appropriate training.

4. How often should the AI policy be updated?

Given the rapid development of technology and regulation, we recommend reviewing the policy at least once a year and whenever there are significant changes – the introduction of a new AI tool, organisational changes, or amendments to legal regulations. 

5. Does the AI Act also apply to small companies?

Yes, the AI Act applies to all entities using AI systems, regardless of their size. The AI literacy obligation applies to every employer whose employees work with AI tools. Even small companies can get into trouble – write to consultation@arws.cz for a consultation on your obligations.

6. What should be done if an employee violates the rules for using AI?

A violation of the internal policy can be grounds for disciplinary action, ranging from a warning to termination of employment. At the same time, the employer can claim compensation for damages under Section 250 of the Labour Code, limited to 4.5 times the average earnings. 

DO YOU HAVE MORE QUESTIONS? GET IN TOUCH

ARROWS law firm

About the author

Mgr. Jan Pavlík
Mgr. Jan Pavlík

Associate

Jan Pavlík is an experienced attorney who focuses on resolving complex situations in corporate life. At Arrows Law Firm, he primarily deals with corporate law, labor law, commercial disputes, and contractual matters.

Disclaimer:

The information contained in this article is for general informational purposes only and serves as a basic guide to the issue as of 2025. Although we strive for maximum accuracy, laws and their interpretation evolve over time. We are ARROWS Law Firm, a member of the Czech Bar Association (our supervisory authority), and for the maximum security of our clients, we are insured for professional liability with a limit of CZK 350,000,000. To verify the current wording of the regulations and their application to your specific situation, it is necessary to contact ARROWS Law Firm directly (consultation@arws.cz). We are not liable for any damages arising from the independent use of the information in this article without prior individual legal consultation.