Staff are already using these tools, with or without permission. The exposure for the employer is confidential information leaving the business, unverified output relied on as fact, and decisions about people taken with no meaningful human review. This is what to put in place, and in what order.
The decision an employer faces is not whether to allow generative AI. Staff are already using it, on their own accounts if not on the company's, and an employer with no position has taken one by default: unrestricted use, no record of what has been entered, and no way of knowing what has left the business. The exposure is confidential information disclosed to a third party, unverified output relied on as fact, and decisions about people taken by a system nobody has audited. All three are manageable, and none of them is managed by a paragraph in the staff handbook saying that employees should be careful.
The three risks, in order of how often they materialise
Information leaving the business. Anything an employee types into a public tool has been disclosed to whoever operates it, on that operator's terms. Where the material is a client's confidential information, a counterparty's draft, personal data of staff or customers, or the business's own unpublished work, the disclosure may breach a contract, a duty of confidence or data protection obligations regardless of what the tool subsequently does with it. This is the risk that arrives first and the one that cannot be undone.
Output that is wrong. These systems produce text that predicts what an answer looks like. Confident, fluent and false is their characteristic failure, and it is a failure that survives casual reading. An employee who forwards an unverified output to a client has made a representation on behalf of the business.
Bias. Where output reflects patterns in the material a system was trained on, it can reproduce discriminatory assumptions. This matters most where the output touches people: recruitment, promotion, performance assessment, allocation of work.
A usage policy is a short instruction, and it is cheaper before the first incident than after.
What the policy has to contain
A usable policy is short, specific and enforceable. Ours cover the following, and we would not sign off on one that omits any of them.
An approved tool list. Named products, with named account arrangements. Personal accounts should be prohibited for work purposes, because the employer has no control over, and no record of, what passes through them.
A rule on what may be entered. State the categories that may never be put into a tool: client confidential information, personal data, unpublished financial information, anything received under an obligation of confidence, and credentials. Say it in categories staff recognise from their own work, not in abstractions.
Verification before use. Nothing generated leaves the business, goes to a client, or is relied on in a decision until a named person has checked it against a source. Where the output is a legal, financial or technical proposition, the source has to be the primary material.
Human oversight of decisions about people. No recruitment, disciplinary, performance or dismissal decision should rest on a system's output. A human decision maker must have the underlying material, the authority to depart from the recommendation, and a record of the reasons.
Disclosure. When AI generated material is provided to a client or a counterparty, or used in a public communication, decide in advance whether it will be identified as such. Contracts with clients increasingly require it.
Intellectual property. State who owns what staff produce with these tools, and warn that output may reproduce third party material. Content generated for publication should be checked before it is published, not after a complaint.
Training and a record. The policy has to be issued, acknowledged and trained. An unacknowledged policy is of limited use in defending a claim, and of no use at all in enforcing one.
The claims that follow misuse
Where the policy is absent or ignored, the exposure typically takes one of four forms. Discrimination claims, where a decision affecting an employee or applicant is influenced by output reflecting systemic bias. Unfair dismissal or detrimental treatment claims, where a system contributed to a decision without adequate human oversight and the employer cannot show a reasoned human process. Intellectual property claims, where an employee generated content that infringes a third party's rights. And breach of contract or confidence claims from clients whose information was disclosed to a tool the client never approved.
Note where the liability lands. In each of these cases the employee acted, and the business answers for it. The employer's protection is not the disclaimer in the tool's terms of service, to which the employer is not a party in any useful sense. It is a documented policy, evidence that it was issued and understood, and a record that the human decision was genuinely human.
Disciplinary use and monitoring
Two cautions. First, an employer cannot discipline an employee for breaching a rule that was never communicated, so the policy must be issued before it is enforced. Second, monitoring employees' use of these tools is itself processing of personal data, and where the employee works remotely it engages section 8 of the Regulation of the Framework for the Organisation of Telecommuting Law of 2023, Law 120(I)/2023, which prohibits monitoring employees through a camera or another application of a similarly intrusive character in order to check performance. Decide what will be logged, tell staff, and keep it proportionate to the risk being managed.
If you are at this point
A usage policy is a short instruction, and it is cheaper before the first incident than after. Send us what your staff already use or call +357 22 680 330.
Where this connects to the Artificial Intelligence Act
The workplace policy and the regulatory analysis are separate exercises that share an input. Both start from a list of the systems in use and what each one is used to decide. Build the inventory once and use it for both.
The regulatory timetable is worth having in mind while the policy is being written. The Act is Regulation (EU) 2024/1689. It entered into force on 1 August 2024, the prohibited practices and the AI literacy obligations have applied since 2 February 2025, the general purpose AI and governance rules since 2 August 2025, and the Regulation applies generally from 2 August 2026. The obligations for high risk systems were then deferred by Regulation (EU) 2026/1744 to 2 December 2027 for the Annex III use cases, and to 2 August 2028 for high risk systems embedded in regulated products. Point 4 of Annex III is the one that matters here: it covers systems used for recruitment or selection, including targeted job advertising, the filtering of applications and the evaluation of candidates, and systems used to decide on terms of work, promotion or termination, to allocate tasks by reference to individual behaviour or personal traits, or to monitor and evaluate performance and behaviour. An employer using a system to screen applicants or to allocate work is looking at December 2027, and at documentation that has to be built before then rather than found afterwards.
What to send us
Your current policy or handbook if you have one, the list of tools in use and the accounts they run on, the supplier terms, and a note of any process affecting staff or applicants that a system touches. If an incident has already occurred, send the sequence of events before anyone is disciplined.
Employment and technology matters sit within our corporate and commercial practice. For the regulatory analysis of the same systems, see The EU Artificial Intelligence Act. For remote workers, the monitoring restrictions are set out in Telecommuting in Cyprus.
This article is for general information only and does not constitute legal advice. Laws and their application can change, and individual circumstances differ. For advice on your own matter, contact Klitos Platis at klitos@kleanthousplatis.com or telephone +357 22 680 330.

Klitos Platis
Advocate, Partner
Kleanthous & Platis LLC, Nicosia · Revised 4 August 2026
Need advice on your own matter?
Send us the documents and a short description at office@kleanthousplatis.com and we will reply within one business day.
Or call +357 22 680 330, or use the enquiry form.