Be careful with using AI without permission, it can lead to dismissal

Foto del autor

By TP


An employee copies a contract with customer data into ChatGPT to summarize it in minutes. Another uses these tools to prepare reports with private data about their company. A third party writes letters with their personal account to go faster. And no one notifies the company. The use of shadow artificial intelligence (AI), also known as shadow AI, has crept into the daily lives of many organizations as a shortcut used by employees to be productive and please the boss. However, this practice touches the field of labor law, in which employers consider whether these behaviors are punishable or, in the most serious cases, can lead to dismissal. The secret use of chatbots does not seem like a passing fad. The use of AI in the work environment is already a reality. Nearly seven out of ten workers use these tools in their daily routine, according to a study carried out by the consulting firm VML The Cocktail and the Salesforce platform. And, in many cases, they do so without permission: at least 61% of employees acknowledge using this type of technology without the knowledge or consent of their company. Does this type of behavior deserve a sanction? The short answer is: it depends. The punishment for using AI surreptitiously varies depending on each company’s internal policy. It also depends on whether the employee’s habit is specific or repeated, the position he or she holds, or the consequences that this habit may have for the company. “Using ChatGPT to write an internal email is not the same as uploading confidential client information without guarantees of security and data protection,” exemplifies Román Gil Alburquerque, partner at Sagardoy Abogados. In any case, these kinds of sanctions usually range “from a written reprimand to suspension of employment and salary,” says the expert. The scenario becomes more delicate when confidential information is touched. The Workers’ Statute contemplates disciplinary dismissal – without the right to compensation – if the employee uses AI surreptitiously. “For example, entering confidential information or sensitive internal or client documents,” says Raúl Rojas, labor partner at Ecija. The employee could also be accused of “a possible continued and voluntary decrease in performance if the use of AI causes serious errors or failure to meet objectives,” adds the expert. Another conduct that could lead to dismissal is taking credit for a job created entirely by artificial intelligence. Now, suspicion alone is not enough to sanction. Companies need to prove this bad practice and, to do so, they must control their infrastructure. “They can monitor the use of their own systems or audit which external platforms were visited, what data was transferred and from which networks,” says Gil Alburquerque. But this does not mean that companies have carte blanche to monitor the worker. If the evidence is obtained “by violating fundamental rights—for example, by accessing a personal cell phone without guarantees or without having previously informed the internal policies—, it may be null and void and cause the dismissal to be declared unfair,” Rojas emphasizes.

Blind

The problem is that many companies do not have control over a technology that their own workers already use daily. “They have not yet defined what tools their employees can use, for what purposes, with what type of information and under what conditions,” says Marcos Judel, partner at Audens. And, when they do try to regulate it, the expert adds, they sometimes make another mistake: “Thinking that the solution is simply to prohibit it in a general way.” But nipping AI use in the bud rarely works. “As a general rule, it causes tension and is usually unrealistic, because employees will use it on their own if it helps them work better,” warns Judel. And that is when dilemmas appear for companies. “It can generate problems of confidentiality, data protection, intellectual and industrial property or contractual compliance with clients or suppliers,” he summarizes. In the most sensitive environments, furthermore, the impact can be even greater. «In regulated sectors – such as the financial, health or legal sectors – it can involve other types of breaches such as banking secrecy, lawyer-client secrecy or patient medical history,» APEP·IA points out. To avoid stepping on legal landmines, the institution maintains that companies must have clear internal policies and train employees well. In addition, entities must make reliable and authorized corporate tools available to avoid taking unnecessary risks. And there is a compelling reason because, as Judel recalls, it is not the worker who is responsible, but the organization. “Outward responsibility will normally be assumed by the company, since it is the one that has duties of confidentiality and security and assumes the contractual rules,” although this does not prevent the company from later acting against the employee. Companies are at a crossroads. On the one hand, prevent the uncontrolled use of artificial intelligence from translating into labor conflicts with the workforce, information leaks or reputational damage. On the other hand, not being left behind for not having incorporated a technology that, in light or in shadow, is already part of the work routine. “The problem is not the use of AI itself, but the loss of opportunity to improve the business due to use without governance, without evaluation and without control,” concludes APEP·IA.

Personal devices

Doubts about controlling the use of AI increase when surveillance escapes the corporate environment and moves to the worker’s personal device. “The employer can set rules and condition the use of corporate networks or applications, but access to the contents of the worker’s personal device would clash head-on with the fundamental right to privacy,” says Raúl Rojas, partner at Ecija. “The company cannot access the worker’s personal device without their consent or without a judicial resolution,” says Román Gil, partner at Sagardoy Abogados.

0