Zaměstnanci a AI nástroje

Key takeaways
Why You Can No Longer Ignore AI in Your Company
The obligation to provide training is not just a formality. The law requires that when determining the scope of education, you consider specific job positions, the technical knowledge of employees, and the context in which they use AI tools. For the lawyers at ARROWS, preparing training and educational materials on AI literacy is a regular part of their work – if you need help setting up a training program.
What Legal Risks Does Uncontrolled Use of AI Bring?
The phenomenon of so-called Shadow AI represents one of the biggest threats to corporate security. According to surveys, up to 89% of employee interactions with generative AI occur without the oversight of the IT department, and 72% of workers use AI tools from private accounts. Half of all content entered into these systems contains sensitive company data, including financial plans, customer data, or source code.
A practical example shows how quickly a problem can arise: in 2023, three employees of an unnamed technology company entered sensitive corporate data into a generative AI tool over just a few weeks, including internal documents and confidential information about product development. The company subsequently had to implement strict measures restricting the use of generative AI throughout the organization.
Once you enter information into a public AI tool, you lose control over it. The data becomes part of the training datasets and can potentially be made available to other users. This constitutes a direct breach of the employee's duty to guard and protect the employer's property under Section 301(d) of the Labour Code.
Internal Policy: The Foundation of Legal Protection for the Employer
A well-drafted internal policy for the use of AI is not just a set of rules – it serves as key evidence that the employer has fulfilled its preventive duty and properly informed employees about the risks. The policy should cover several fundamental areas.
Defining permitted and prohibited AI tools is the first step. Create a list of approved applications and clearly state which tools are banned for company use. For each permitted tool, specify its purpose and conditions of use.
Rules for handling data must unequivocally define what information employees are not allowed to enter into AI systems. Prohibited categories typically include personal data, trade secrets, source codes, financial data, client information, and internal strategies. Entering the personal data of third parties into public AI platforms is a direct violation of GDPR.
An approval process for new tools ensures that every new AI system undergoes a security and legal assessment before deployment. This will prevent the uncontrolled spread of Shadow AI within the company.
The ARROWS law firm prepares internal policies for AI use tailored to the specific needs of the client. Thanks to our experience with over 150 joint-stock companies and 250 limited liability companies in our portfolio, we can set rules that are practically enforceable while meeting all regulatory requirements. Contact us and get a tailor-made legal solution.
Liability for Damage Caused by Artificial Intelligence
Current Czech legislation does not grant legal personality to artificial intelligence. The person or entity using the tool is always responsible for all decisions and outputs of AI systems. If an employee uses AI as a work tool and causes damage – whether through a data leak, copyright infringement, or a faulty decision – the employer bears the liability.
From a civil law perspective, Section 2910 of the Civil Code on liability for damage caused by a breach of a statutory duty applies. Section 2936 of the Civil Code then stipulates that whoever is obliged to perform something for someone and uses a defective item in the process is liable for the damage caused by the defect of that item – which can also be applied to the implementation of a faulty AI system.
In employment relationships, the employer is liable for damage caused to an employee in connection with the performance of work tasks. This liability is conceived in the Labour Code as strict liability, i.e., regardless of fault. The employer cannot be exonerated by claiming that the error was on the part of the AI.
Potential Problems | How ARROWS Helps (consultation@arws.cz) |
Leak of trade secrets via an AI tool – breach of NDA, loss of competitive advantage, litigation | Preparation of internal policies and employee training |
GDPR breach by entering personal data into AI – fine of up to 4% of global turnover | Legal audit of processes and preparation of a DPIA |
Faulty AI output leading to financial loss – employer's liability for damages | Review of contracts and setting up liability mechanisms |
Discrimination in recruitment caused by an AI algorithm – employee lawsuits, reputational damage | Representation in labour law disputes and preparation of non-discriminatory processes |
What Requirements Must High-Risk AI Systems in HR Meet?
The AI Act classifies all artificial intelligence systems used in the field of human resources as high-risk. This category includes tools for analysing CVs, evaluating candidates, monitoring employee performance, making decisions about promotions, or assigning tasks based on personality traits.
As of 2 August 2026, strict obligations for the operators of these systems will come into force. Employers will have to ensure human oversight of AI by competent persons, continuously monitor the system's operation, and keep automatically generated logs for a minimum of six months. There is also an obligation to inform employee representatives and the affected workers that they are subject to an AI system before it is deployed.
Violation of the rules for high-risk systems can lead to fines of up to EUR 15 million or 3% of the total worldwide annual turnover. The deployment of prohibited AI practices carries penalties of up to EUR 35 million or 7% of turnover.
In practice, this issue is significantly more complex than it may seem at first glance. The classification of a specific AI tool requires a detailed legal analysis that considers not only the functionality of the system itself but also the context of its use and its connections to other regulations.
The ARROWS law firm handles this agenda daily and can significantly shorten the time required for a client to achieve regulatory compliance. Moreover, we are insured for damages up to CZK 500,000,000, making it safer for the client to entrust the matter to professionals.
How to Handle GDPR When Using AI Tools?
The processing of personal data through AI systems is fully subject to the requirements of the GDPR. A key provision is Article 22, which gives data subjects the right not to be subject to a decision based solely on automated processing if it produces legal effects concerning them or similarly significantly affects them.
In practice, this means for employers that an AI system can only issue recommendations – the final decision on hiring a candidate, termination, or the amount of remuneration must be made by a human. A violation of this rule carries the risk of a penalty of up to EUR 20 million or 4% of the total worldwide turnover.
Before deploying an AI tool that processes employees' personal data, it is in many cases necessary to conduct a Data Protection Impact Assessment (DPIA). This obligation arises in particular for systematic evaluation of personal aspects, large-scale processing of sensitive data, or the use of innovative technologies.
A DPIA for AI systems must include the identification and assessment of risks to the data subjects, an analysis of the proportionality and necessity of the processing, an assessment of measures to minimise risks, and mechanisms for exercising the rights of data subjects. The French supervisory authority CNIL also recommends conducting a DPIA for the development of all foundation models and general-purpose AI systems if they involve the processing of personal data.
Copyright and AI: Who Owns the Generated Content?
The question of copyright for content created by artificial intelligence remains unclear in many respects, but the basic principles are already established. Under the Czech Copyright Act, only a natural person can be an author, and the work must be the unique result of a human's creative activity. Czech courts have already confirmed that content generated purely by artificial intelligence does not meet the conceptual characteristics of a copyrighted work.
In the European Union, the general approach is that copyright is not granted to AI creations if the work completely lacks human contribution. The U.S. Copyright Office has taken a similar stance – a work created exclusively by AI is not eligible for copyright registration.
This has practical implications for employers. If an employee creates content using AI as an auxiliary tool but actively intervenes in the creation – editing, modifying, combining outputs, and introducing their own creative elements – the result may be protected by copyright. To preserve protection, it is advisable to document the creative process and the degree of human contribution.
We recommend explicitly regulating the ownership of AI tool outputs and the rules for their use in the employment contract or internal policy. In the EU, an employer owns a work created by an employee only if the employment contract explicitly states so.
How to Implement Safe Use of AI in Your Company Step by Step?
Implementing AI governance requires a systematic approach. The first step is to map the current situation – find out what AI tools are already being used in the company, who works with them, and what data is being entered into them. Be aware that some usage occurs outside official channels.
The second step is to categorise use cases by risk level. Distinguish between prohibited use (sensitive data, regulatory documents), restricted use (internal documents with supervisor approval), and free use (brainstorming, formatting public data).
The third step is the preparation of documentation – internal policies, addendums to employment contracts, informational materials for employees. The fourth step is training, which must be tailored to different roles and levels of technical knowledge.
The fifth step is the implementation of technical measures – monitoring the use of AI tools, DLP (Data Loss Prevention) solutions, central access management. The sixth step is to establish an ongoing audit and update the rules according to the development of technology and regulation.
The entire process has many hidden pitfalls and connections to other regulations that a layperson often does not see. We commonly partner with corporate lawyers to resolve special issues in the area of AI compliance – if you do not want to risk mistakes or fines, contact us at consultation@arws.cz.
Potential Problems | How ARROWS Helps (consultation@arws.cz) |
Deployment of a high-risk AI system without meeting requirements – fine of up to EUR 15 million | Legal audit of AI systems and preparation of compliance documentation |
Automated decision-making without human oversight – violation of Article 22 of the GDPR | Setting up processes with mandatory human review |
Lack of transparency towards employees – violation of the Labour Code and GDPR | Preparation of information documents and updating of employment documentation |
Use of prohibited AI practices – fine of up to EUR 35 million or 7% of turnover | Legal assessment of AI systems and identification of prohibited practices |
International Aspects: When Do You Need a Global Perspective?
If your company operates in multiple countries or employs workers from different jurisdictions, the situation becomes more complicated. AI regulation varies significantly from country to country – while the EU has adopted the comprehensive AI Act, the USA does not yet have federal legislation, but individual states are adopting their own rules. New York City, for example, has required independent audits of AI algorithms used in recruitment since 2023.
The ARROWS law firm provides legal services in the field of AI compliance outside the Czech Republic as well, thanks to the ARROWS International network, which we have been building for ten years. We handle cases with an international element on a daily basis and can coordinate legal advice across jurisdictions. If you are looking for a partner to handle AI governance at an international level, contact our firm.
Should you find an interesting investment or business opportunity in the field of AI technologies, we will be happy to connect you with relevant partners from our portfolio. Likewise, we are always keen to hear about interesting business ideas in this dynamically developing area.
Timeline: What to Expect and When
The implementation of the AI Act is taking place gradually according to a precisely defined schedule:
2 February 2025 – The obligation for AI literacy and the bans on dangerous AI practices will come into force.
2 August 2025 – The rules for providers of general-purpose AI (GPAI) models will apply, and member states must designate the relevant supervisory authorities.
2 August 2026 – Most of the AI Act's rules will become effective, including the requirements for high-risk systems, and enforcement by supervisory authorities will begin.
2 August 2027 – Full effectiveness of the rules for high-risk AI systems embedded in regulated products.
Waiting until the last minute is a risky strategy. Preparing compliance documentation, training employees, and making technical process adjustments take time. Starting preparations well in advance also allows for any complications to be resolved without time pressure.
Conclusion: Safe Use of AI Requires Legal Preparation
Using artificial intelligence in the workplace brings undeniable benefits in the form of increased productivity and efficiency. At the same time, however, it creates complex legal risks that require a systematic approach. From sensitive data leaks and GDPR violations to penalties under the AI Act – each of these risks can cause significant financial and reputational damage.
The ARROWS law firm has a specialised team that has been focusing on AI compliance for a long time. We prepare internal policies, provide employee training with a certificate of AI literacy, conduct legal audits of AI systems, and represent clients in proceedings with supervisory authorities. Thanks to our liability insurance of up to CZK 500,000,000, you can entrust the entire matter to professionals with the assurance that any potential errors are covered.
If you do not want to risk fines, damages, or legal disputes associated with the incorrect use of AI in your company, contact us. We will handle the entire matter safely for you.
About the author
Disclaimer:
The information contained in this article is for general informational purposes only and serves as a basic guide to the issue as of 2025. Although we strive for maximum accuracy, laws and their interpretation evolve over time. We are ARROWS Law Firm, a member of the Czech Bar Association (our supervisory authority), and for the maximum security of our clients, we are insured for professional liability with a limit of CZK 350,000,000. To verify the current wording of the regulations and their application to your specific situation, it is necessary to contact ARROWS Law Firm directly (consultation@arws.cz). We are not liable for any damages arising from the independent use of the information in this article without prior individual legal consultation.

