What must employees not enter into ChatGPT, who is liable for incorrect AI output, and what should an employer’s internal AI policy contain?
1. ABSTRACT
Generative artificial intelligence began to be used in many companies before internal rules governing it were introduced. Within seconds, an employee can paste a draft contract, a customer list, a job applicant’s CV or financial results into a publicly available tool and ask it to process the information. An act that appears to be simple copying may, however, constitute the processing of personal data, disclosure of confidential information to an external provider or a threat to trade secrets.
The Artificial Intelligence Act does not impose a general ban on the use of tools such as ChatGPT, Microsoft Copilot, Google Gemini or Claude. It does, however, introduce new obligations for companies and, together with existing data protection, employment and copyright rules, creates a framework that cannot be replaced by the simple instruction “use AI with care”.
This article focuses primarily on (A) when a company is a deployer of an AI system, (B) what information employees should not enter into unapproved tools, (C) who is liable for an incorrect AI output, (D) under what conditions an employer may monitor employees’ use of AI and (E) what an internal AI policy should contain.
2. RELEVANT LEGISLATION
The use of generative AI in the workplace is governed in particular by:
(A) Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (the “AI Act”), as amended by Regulation (EU) 2026/1744 of the European Parliament and of the Council (the “Digital Omnibus on AI”), which simplified and amended certain rules of the AI Act and postponed the application of some obligations for high-risk systems,
(B) Regulation (EU) 2016/679 of the European Parliament and of the Council (the “GDPR”),
(C) Slovak Act No. 18/2018 Coll. on Personal Data Protection,
(D) Slovak Act No. 311/2001 Coll., the Labour Code (the “Labour Code”),
(E) Slovak Act No. 513/1991 Coll., the Commercial Code (the “Commercial Code”), and
(F) Slovak Act No. 185/2015 Coll., the Copyright Act (the “Copyright Act”).
The specific legal regime may also depend on sectoral regulation, statutory confidentiality duties or the company’s contractual obligations. Stricter requirements may apply, for example, to banks, insurers, healthcare providers, lawyers, tax advisers or operators of essential services.
3. THE COMPANY AS A DEPLOYER OF AN AI SYSTEM
The AI Act distinguishes between several categories of operators. For an ordinary company, the term “deployer of an AI system” is particularly important. It means a natural or legal person, public authority, agency or other body using an AI system under its authority, except where the system is used in the course of a personal, non-professional activity.
A company therefore does not need to develop or sell an AI system for the AI Act to apply to it. It is sufficient for the company to use the system in its business or employment activities. Typical examples include the use of AI to draft business correspondence, summarise documents, provide customer support, pre-screen job applicants or evaluate employee performance.
Not every use of ChatGPT constitutes high-risk use within the meaning of the AI Act. The intended purpose of the system and the specific manner in which it is deployed are decisive. Using AI to improve the style of a generic email has a different legal profile from using a system to rank CVs, recommend an employee’s dismissal or allocate tasks on the basis of workers’ behaviour and personal characteristics.
AI LITERACY
The Digital Omnibus on AI replaced the original wording of Article 4 of the AI Act. Providers and deployers of AI systems must take measures to promote the development of AI literacy among their employees and other persons operating or using AI systems on their behalf. The measures must take account of the workers’ technical knowledge, experience, education and training, the context in which the AI systems are to be used and the persons in relation to whom they are used.
The new wording expressly states that a company is not required to guarantee any specific level of AI literacy for each individual. The obligation cannot, however, be satisfied merely by circulating a generic email. The scope of training and internal rules should correspond to the risk. An employee who uses AI to proofread an anonymous text requires different guidance from an HR professional using AI to select candidates or an employee processing health or financial data.
Suitable measures may include, in particular, (A) an internal policy, (B) regular training, (C) a list of approved tools and purposes, (D) rules for reviewing outputs and (E) a simple incident-reporting procedure.
PROHIBITED PRACTICES
The AI Act prohibits certain practices irrespective of the size of the company. In the workplace, the prohibition on using AI to infer a natural person’s emotions is particularly important, except where the use is intended for medical or safety reasons. Manipulative techniques or social scoring may also be prohibited where the statutory conditions are met.
Companies should therefore also examine features of tools marketed merely as productivity solutions. Voice analysis during a job interview, automated interpretation of facial expressions in a video call or an estimate of an employee’s “engagement” may be subject to a considerably stricter regime than ordinary text assistance.
4. WHAT AN EMPLOYEE MUST NOT ENTER INTO AI WITHOUT PRIOR APPROVAL
There is no single universal list of data applicable to every company and every tool. As a practical rule, however, an employee should not enter the following into an unapproved external AI system:
(A) personal data of clients, customers, employees or job applicants,
(B) special categories of personal data, such as health data, biometric data, political opinions or trade union membership,
(C) national identification numbers, identity document numbers, login details, passwords, payment information or authentication codes,
(D) contracts, legal analyses, internal correspondence and documents protected by a duty of confidentiality,
(E) business plans, pricing information, source code, technical documentation, customer databases and other trade secrets,
(F) copyright-protected works or databases for whose use the company does not have the necessary authorisation, and
(G) information whose disclosure to an external provider is prohibited by a contract with a client or business partner.
The prohibition need not be absolute. Processing may be permissible in a tool that the company has properly assessed, contractually secured and technically configured for the relevant purpose. An employee should not, however, decide independently that a consumer account or free version of a service provides a sufficient level of protection.
PERSONAL DATA IN A PROMPT
Entering personal data into an AI system constitutes processing of personal data. The controller must have a legal basis and a specified purpose for the processing, comply with the data-minimisation principle, determine the role of the supplier, enter into the necessary data-processing agreement, assess any transfers to third countries and implement appropriate security measures.
The fact that the data is used only to create a summary or a draft response does not remove these obligations. Nor is it sufficient merely to remove a person’s name if that person can still be identified from the remaining information. Pseudonymised data remains personal data where it can be attributed to a particular person by using additional information.
When special categories of personal data are processed, one of the conditions under Article 9 GDPR must be met in addition to a legal basis under Article 6 GDPR. Where processing is extensive, systematic or otherwise likely to result in a high risk, a data protection impact assessment under Article 35 GDPR may be required.
The employer should distinguish between an employee’s personal account, a company user account and an enterprise solution or application programming interface. Contractual terms, use of content to improve models, retention periods, administrative controls and the location of processing may differ depending on the service and configuration. The mere designation of a product as “business” therefore does not replace a legal and security assessment of its specific configuration.
TRADE SECRETS AND CONFIDENTIALITY
Pursuant to Section 17(1) of the Slovak Commercial Code, a trade secret consists of facts of a commercial, manufacturing or technical nature connected with an enterprise that have actual or potential value, are not normally available in the relevant business circles, are intended to be kept confidential and whose owner adequately safeguards their confidentiality.
Uncontrolled entry of sensitive information into external AI tools may not only breach confidentiality but also weaken the argument that the company adequately protected its trade secrets. An internal policy, access management, information classification and documented employee training are therefore also measures for the protection of trade secrets.
Under Section 81(e) and (f) of the Slovak Labour Code, an employee must protect the employer’s property, refrain from acting contrary to the employer’s legitimate interests and maintain confidentiality concerning facts that may not be disclosed to other persons in the employer’s interests. Depending on the circumstances, unauthorised entry of confidential data into an external system may constitute a breach of work discipline and may also give rise to liability for damage. The consequences must nevertheless be assessed individually, particularly in view of the nature of the data, fault, the existence of clear rules and the seriousness of the risk or damage.
5. WHO IS LIABLE FOR AN INCORRECT AI OUTPUT
An AI system is not a person to whom liability for a business decision can be transferred. If an employee sends a client incorrect legal information, uses a non-existent technical standard in an offer or makes a decision based on an incorrect calculation generated by AI, the statement that “ChatGPT made the mistake” will generally not relieve the company of liability.
Generative AI produces outputs through probabilistic processing. Even a confidently worded answer may contain a non-existent court decision, an incorrect figure, outdated information or a distorted summary of the source document. The risk increases where the user requests an answer outside the available sources or lacks the expertise needed to review it.
Internal rules should therefore identify cases in which human review is mandatory. Without qualified verification, an AI output should not be used in particular as a final professional opinion, a contractual clause, a calculation affecting pay or price, a decision concerning an employee or information on which a client is expected to rely.
Human review must not be merely formal. The reviewer must have sufficient knowledge, access to the underlying materials and genuine authority to reject or amend the output.
6. COPYRIGHT IN INPUTS AND OUTPUTS
A user may enter into an AI system text, a photograph, source code or other creative material that the company is not entitled to use in this manner. In a particular case, this may constitute reproduction or another use of a work requiring the rights holder’s consent, unless a statutory exception applies.
Nor can it be automatically assumed that every AI output is free of third-party rights or that the company has acquired exclusive copyright in it. Under Section 3(1) of the Slovak Copyright Act, a work is a unique result of the author’s creative intellectual activity. A purely automatically generated output without sufficient creative input from a natural person may therefore not meet the requirements for copyright protection. Conversely, in AI-assisted creation, the result of human creative choices may be protected.
Before commercially using a significant output, it is advisable to examine (A) the tool’s licensing terms, (B) the origin of the source materials, (C) similarity to existing works, trademarks or designs and (D) the extent and documentation of human creative input.
7. MAY AN EMPLOYER MONITOR THE USE OF AI?
An employer may determine which work tools may be used, block unapproved services on the corporate network and require compliance with security rules. Monitoring an employee’s specific activity must, however, respect the employee’s privacy, data protection rights and Section 13(4) of the Slovak Labour Code.
Without serious reasons arising from the particular nature of its activities, an employer may not interfere with an employee’s privacy by monitoring the employee or checking work email without prior notice. When introducing a monitoring mechanism, the employer must discuss its scope, method and duration with employee representatives and inform employees accordingly.
It follows that even the legitimate objective of preventing a data leak does not automatically entitle an employer to read all employee prompts and conversations. Monitoring must be necessary, proportionate and transparent. Before monitoring content, the employer should consider less intrusive measures, such as restricting access to unapproved domains, displaying a technical warning before sensitive data is entered, detecting categories of data without reading the entire content or reviewing anonymised operational logs.
8. AI IN RECRUITMENT AND EMPLOYEE MANAGEMENT
Particular attention must be paid to AI systems used for recruitment, selection of applicants, decisions affecting employment conditions, promotion or termination, allocation of tasks based on individual behaviour or personal characteristics, and monitoring or evaluation of workers. Subject to the statutory conditions, the AI Act classifies such systems as high-risk.
The Digital Omnibus on AI postponed the application of the relevant requirements and obligations for high-risk systems listed in Annex III to the AI Act until 2 December 2027. The postponement does not create a legal vacuum. The GDPR, anti-discrimination law, the Slovak Labour Code and the prohibition of selected practices under the AI Act already apply.
Where a system processes personal data and makes a decision based solely on automated processing that produces legal effects concerning a person or similarly significantly affects that person, Article 22 GDPR must also be respected. Formal confirmation of an AI recommendation by a human may not amount to meaningful human intervention if the reviewer has neither the ability nor the expertise to change the decision.
Before deploying such a system, a company should assess in particular its purpose, the quality and origin of its input data, possible discriminatory effects, explainability of results, human oversight, information obligations and the need for a data protection impact assessment.
9. SEVEN STEPS FOR EMPLOYERS
INVENTORY
The company should establish which AI tools employees actually use, for what purposes, with which inputs and through which personal or corporate accounts. A prohibition without an inventory often merely moves the use of AI into an uncontrolled environment.
RISK CLASSIFICATION
Individual use cases should be classified by risk. Proofreading an anonymous text does not have the same legal profile as processing health data, selecting job applicants or generating a professional opinion for a client.
APPROVED TOOLS AND CONTRACTS
The company should identify permitted tools and assess their contractual terms, data protection, retention of inputs and outputs, subprocessors, security measures and any data transfers. Where personal data is processed, the roles of the parties must be determined and the necessary agreements concluded.
INTERNAL AI POLICY
The policy should clearly define permitted and prohibited uses, categories of data that must not be entered, anonymisation rules, mandatory human review, labelling of AI-generated content, approval of new tools and the consequences of non-compliance.
RISK-BASED TRAINING
Employees need practical examples from their own work. Training should explain not only how to operate the tool but also the limitations of outputs, protection of personal data and trade secrets, copyright and the incident-reporting procedure.
HUMAN REVIEW AND DOCUMENTATION
For significant outputs, the responsible person, scope of verification and method of documentation should be specified. In decisions concerning individuals, human intervention must be genuine, qualified and effective.
INCIDENT REPORTING
Employees must know whom to contact and how to report that they have accidentally entered personal data, a trade secret or an incorrect document into an AI system. Prompt reporting may allow the company to seek deletion, change access credentials, comply with any notification obligations and limit the damage.
10. APPLICATION AND CONCLUSION
The AI Act applies in stages. Its first provisions, including the rules on AI literacy and the prohibition of selected practices, began to apply on 2 February 2025. Most of its remaining provisions began to apply on 2 August 2026. The Digital Omnibus on AI nevertheless amended certain obligations and postponed the high-risk regime for systems listed in Annex III until 2 December 2027 and for selected high-risk systems embedded in regulated products until 2 August 2028.
The greatest legal risk associated with ordinary use of ChatGPT in a company may therefore not currently arise from the AI Act itself. It often arises earlier: when personal data is entered without a legal basis, a trade secret is disclosed to an unapproved supplier, an unverified output is used or an employee is monitored disproportionately.
A company using AI needs more than a ban or a one-off training session. It needs to understand actual use cases, approve appropriate tools, set boundaries for working with data and ensure that an identifiable and qualified human remains responsible for every significant decision.


