What an AI policy is for
An AI policy creates clarity about which tools are permitted, which data may be entered, and who in the HR team is responsible for what. Unlike a works council agreement, it is written without negotiating with the works council (Betriebsrat, the elected employee representation in German companies), which makes it faster but also weaker: it cannot replace a co-determination right where one exists.
Its real value lies elsewhere. It ends shadow AI. In most HR teams today someone is using a language model with a private account, no data processing agreement, and real names in the prompt. The policy says what applies instead, and it does so in three weeks rather than four months. For subsidiaries of international groups there is a second reason: a group-wide AI policy from headquarters almost never covers the German specifics, and a local addendum for HR is the fastest way to close that gap.
When a policy is enough, and when it is not
The three criteria and the legal basis: Co-determination and AI under German law. The route to the agreement: The Works Council AI Agreement.
What belongs in an AI policy
The same structure as a works agreement, only issued unilaterally instead of negotiated. Eight points, none of them optional:
- ScopeHR team, line managers, every employee who processes personnel data.
- Permitted toolsA closed list with a data processing agreement in place: Copilot, ChatGPT Enterprise, Claude for Work, depending on the company.
- Prohibited tools and use casesPrivate accounts, free versions, automated rejection, emotion recognition.
- Which data may go inAnonymised yes, real names only in tools with a data processing agreement, health data never.
- Human final decisionEvery personnel decision is made by a human. The tool prepares.
- ResponsibilityWho maintains the list, who reviews new tools, who decides when questions come up.
- Training and communicationWho is trained before using a tool, and how the policy is made known.
- Reference to the EU AI ActFor high-risk uses such as candidate selection: documentation and register.
Three steps to the policy
Which tools are used today, officially and unofficially. Ask honestly, do not assume.
Fill in the eight points, align with the data protection officer, name the prohibited cases clearly.
A short briefing to everyone affected, acknowledgement of receipt, inclusion in onboarding.
Review new tools, update the list, revise after a year at the latest.
Where the limits lie
A policy is an instruction from the employer. It can govern what employees may do, but it cannot override a co-determination right of the works council. Where a works council exists and co-determination applies, a policy without an agreement is open to challenge, and the works council can stop the usage through an injunction. The second limit is data protection. The policy can permit a tool, but it does not replace the data processing agreement with the vendor. The third limit is the EU AI Act. For high-risk uses, documentation and registration duties apply regardless of what the policy says. Details under GDPR and AI in HR and The EU AI Act for HR.
From policy to works council agreement
Whoever has built the policy properly has already completed the first step of the works agreement: the use-case inventory. The list of permitted tools and cases is the basis for the first meeting with the works council, and the eight points become the eight points of the agreement. What changes is the form. "The employer sets the rules" becomes "both sides agree", with monitoring rights for the works council, a test phase and a review. The route takes two to four months and is described under The Works Council AI Agreement.
An AI policy for HR teams as a template
A ready structure with the eight core points that you adapt to your tools and processes, including wording for prohibited cases and the reference to the EU AI Act. Not legal advice, but a starting point that saves a week.
Frequently asked questions
Can a policy later become a works council agreement?
Yes. It is a good starting point for the use-case inventory that opens the negotiation. The eight core points are the same. What changes is that a document issued by the employer alone becomes a negotiated one.
Does the policy have to be communicated to employees?
Yes. Rules that have not been made known cannot be enforced in practice. A short briefing with an acknowledgement of receipt works well, and for new joiners the policy becomes part of onboarding.
What if employees use private AI accounts?
That is exactly what the policy governs: which tools are permitted and which are not. Free consumer versions without a data processing agreement belong on the list of tools that are off limits for HR data.
Is our existing IT policy enough?
Rarely. A general IT policy governs access and devices, not which personnel data may go into which language model. The AI policy supplements it, it does not replace it.
Does the policy apply to line managers outside HR?
It should. Managers who draft appraisals or reference letters with AI are processing personnel data. The scope is one of the eight points, and it should reach beyond the HR team.
