|
The document defines "Generative Artificial Intelligence" ("GenAI") as artificial intelligence systems trained on large-scale datasets that are capable of producing content in various formats - such as text, images, video, audio, or software code - in response to user prompts. These tools may enhance efficiency across a wide range of business processes, including drafting e-mails, summarising texts, supporting research activities, and facilitating idea development. However, the widespread use of these technologies also entails various legal and institutional risks, particularly when deployed through third-party platforms. |
|
A. The Risk of "Shadow Artificial Intelligence" ("Shadow AI") |
|
The Authority defines "Shadow Artificial Intelligence" as the use of generative artificial intelligence tools by employees in business processes without the knowledge, approval, or oversight of the company for which they work. |
|
Shadow AI use typically arises from employees seeking to accelerate their work or reduce routine task burdens. However, the transfer of meeting notes, internal correspondence, or information relating to corporate data to external generative artificial intelligence platforms may give rise to significant risks for companies. |
|
The principal risks highlighted by the Authority are summarised below: |
|
|
|
|
|
|
B. What Actions Can Companies Take? |
|
The Authority notes that a blanket prohibition on the use of GenAI is neither practical nor advisable, as it may in fact encourage Shadow AI use. Companies are therefore recommended to establish a corporate policy grounded in guidance, balance, and awareness, rather than a prohibitive approach. |
|
The principal actions that companies may consider in this regard are as follows: |
|
|
|
|
|
|
C. Conclusion |
|
While generative artificial intelligence tools offer significant efficiency and speed advantages in business processes, the emergence of these technologies - particularly in the form of Shadow AI use - may give rise to serious legal and operational risks for companies in relation to data security, the protection of trade secrets, and the processing of personal data. |
|
It is therefore important for companies to approach the use of generative artificial intelligence not merely as a technological efficiency tool, but also through the lens of corporate risk management and data protection. In this context, it is of considerable importance to establish clear and workable corporate policies, define limits on the sharing of sensitive data, strengthen access and oversight mechanisms, and raise employee awareness. |
|
Preventive and guidance-oriented measures taken in this direction will contribute to the safe utilisation of the opportunities offered by generative artificial intelligence technologies and will significantly reduce the likelihood of companies encountering potential legal and reputational risks. |
The Use Of Generative Artificial Intelligence in the Workplace: Legal Risks and Recommendations for Companies
The Personal Data Protection Authority ("Authority") published an informational document entitled "The Use of Generative Artificial Intelligence Tools in the Workplace" on 5 March 2026. The document draws attention to the risks associated with the use of publicly accessible generative artificial intelligence tools offered by third parties in the workplace and sets out a number of recommendations for companies.