A ban moves the use into private accounts where nobody can see it. The approach that works has three parts: a company-provided account, a rule that states explicitly what is allowed, and a documented briefing. Only after that does the question of monitoring make sense, because you can only monitor what happens inside your own systems.
At a glance
- A quarter of German companies already know of AI use without employer approval, either as everyday practice or in individual cases.
- More than half of employees present AI-generated work as their own, and a ban reinforces exactly that.
- The employer's right to issue instructions carries the rule, data protection accountability makes it necessary, and trade secret protection makes it valuable.
- Co-determination applies once the account sits inside the company and usage data accumulates, not for private accounts in a browser.
- HR owns this rule, not IT: it is about work behaviour, qualification and trust, not about software.
The number that surprises HR leaders most is rarely the number of people using AI. It is the number of people who say nothing about it. In the largest global survey on the subject, 57 percent of employees say they hide their AI use and present AI-generated work as their own.
For an HR team this is not a technology question. It is the same situation as private devices fifteen years ago: a practice arrives faster than any rule, and the longer the rule is missing, the more facts the practice creates. The difference is that this time employee data, applications and draft references can travel into external systems without leaving a trace anywhere.
This article sorts out the situation: what is actually happening, why a ban makes things worse, what German law already requires without a rule of your own, where the works council has a say, and what a rule looks like that holds up in daily work. It describes the general framework and does not replace legal advice: the assessment of your case belongs with your data protection officer, your works council and your employment law counsel.
What is happening, even if nobody reports it
Unapproved AI use is no longer a fringe phenomenon in German companies, it is known in roughly a quarter of them. According to the survey by the industry association Bitkom among 604 companies with 20 or more employees, it is widespread in 8 percent of companies, up from 4 percent the year before. Another 17 percent see individual cases, up from 13 percent. A further 17 percent suspect such use but cannot prove it.
This self-assessment by companies is the cautious version. Ask employees directly and the numbers are considerably higher. In the study by KPMG and the University of Melbourne among more than 48,000 people in 47 countries, 57 percent say they hide their AI use. The Work Trend Index by Microsoft and LinkedIn puts the share of AI users who bring their own tools to work at 78 percent.
A look at methodology helps here. The Bitkom survey is representative of companies with 20 or more employees and was conducted by telephone in calendar weeks 27 to 32 of 2025, so it captures what management notices. The global study surveyed employees themselves between November 2024 and January 2025. Both are solid, they simply measure different things: one measures what a company sees, the other what people do.
The gap between the two numbers is the real message. Companies see a fraction of what happens, and they do so systematically. If you have not permitted a practice, it does not get reported to you, and if it does not get reported, you assume it is smaller than it is. That is not negligence on the part of the workforce, it is the predictable response to a situation without a rule.
For HR there is a second observation hidden in the numbers. Use does not spread by department or age, it spreads by workload. Whoever produces a lot of text reaches for the tool first: job ads, meeting notes, interview guides, draft references. Which puts the centre of gravity exactly where a company keeps its most sensitive data.
Company self-reporting and employee self-reporting describe the same practice from two different distances.
Why a ban only makes the use invisible
A ban without an alternative produces exactly the risk it is meant to prevent, because it pushes the use out of company systems and into private accounts. There you have no logs, no deletion periods, no contract with the provider and no way to reconstruct which data left the building. The risk does not disappear, it simply becomes unobservable.
The cost of that invisibility has been quantified. The Cost of a Data Breach Report by IBM and the Ponemon Institute puts the additional cost for organisations with a high level of shadow AI at 670,000 US dollars per breach, against a global average breach cost of 4.44 million US dollars. 63 percent of the organisations studied had no AI governance policy at all. Issuing a ban while refusing access puts you in that same group.
There is also a quality problem that many underestimate. In the same global study, 66 percent say they rely on AI output without checking whether it is accurate, and 56 percent report making mistakes at work as a result. Those mistakes survive better in the dark than in the open, because nobody can ask how a text came about without forcing a confession. What this looks like for one concrete HR document is covered in the article on AI-generated employment references.
And there is a consequence that shows up late and then costs money. Under German trade secret law, information only counts as a trade secret if it is subject to reasonable steps to keep it secret. If drafts, calculations or client data are routinely typed into arbitrary services and the company offers neither a rule nor an alternative, arguing that reasonable steps were in place becomes difficult.
The last point is cultural. A workforce that uses a tool in secret does not talk about the results either. The company then loses the part that would actually be valuable: the experience of where the tool carries weight and where it misleads. That knowledge is the raw material of every later rollout, and a ban burns it.
What a pure ban sets in motion
- Use migrates to private accountsNo logs, no deletion periods, no contract with the provider.
- Data leaks go unreportedAdmitting the use means admitting a breach of the rules, so nobody reports.
- Errors stay in the textWithout approval there is no legitimate reason to have a result double-checked.
- Trade secret protection weakensReasonable steps to keep information secret are hard to claim with neither rule nor tool in place.
- Experience builds up outside the companyThe learning curve runs privately and the organisation never benefits from it.
What applies while nothing is regulated
Even without a policy of your own the situation is not unregulated, it is merely undefined. Under the German Trade Regulation Act, the employer may specify the content, place and time of work at its reasonable discretion, as far as these conditions are not already set by the employment contract, a works agreement, a collective agreement or statute. Which tools are used falls within that scope. The right to issue instructions carries the rule, but it does not replace it.
On the data protection side the standard is clearer than many realise. Personal data must be processed in a way that ensures appropriate security, and the controller must be able to demonstrate compliance with these principles. On top of that comes an obligation that reads as if it were written for this case: controllers must take steps to ensure that any person acting under their authority who has access to personal data processes it only on instructions. Without an instruction there is no such demonstration. The wider frame is set out on the page about GDPR and AI in HR.
The third strand is trade secret protection, and it points the same way. Information is only a trade secret if it is subject to reasonable steps to keep it secret, taken by its lawful holder. A written rule on which content may go into which tools is such a step. A verbal recommendation in a team meeting is not.
There is also an obligation under the EU AI Act that applies regardless of risk class and is often overlooked: providers and deployers of AI systems must take measures to ensure a sufficient level of AI literacy among their staff. For HR that means the rule comes with a briefing, and that the briefing should be documented.
Taken together this creates an uncomfortable asymmetry. Regulating nothing is not a neutral position, it is the weaker one: the same obligations apply, but there is no record, and in a serious case you can neither show what was permitted nor prove that you communicated it. The rule protects the company first and the data second.
Where the works council has a say, and where it does not
Co-determination does not hang on the tool, it hangs on whether data about employee behaviour or performance accumulates inside the company. The Betriebsrat, the elected works council, co-determines the introduction and use of technical devices designed to monitor the behaviour or performance of employees. Under settled case law, objective suitability for monitoring is enough, an intention to monitor on the employer's part is not required.
The Hamburg Labour Court described the opposite pole in 2024. In the case decided there, a company had allowed the use of ChatGPT through accounts employees created themselves and published guidelines on its intranet. The court denied a co-determination right because the application did not run on company systems and the employer had no access to the data created there. The browser as a technical device was already covered by an existing works agreement.
For practice this produces a rule that looks paradoxical at first: the more cleanly you bring the use into your own environment, the clearer co-determination becomes. Company accounts with user profiles, logs and reporting options are precisely what co-determination covers. That is not an argument against company accounts, it is an argument for involving the works council from the start rather than asking for approval at the end. How such an agreement is structured is set out on the page about the works council AI agreement.
German law gives the works council additional weight in this field. If the works council has to assess the introduction or use of artificial intelligence in order to perform its duties, calling in an expert is deemed necessary. That wording removes the usual argument about whether external expertise is required at all. Planning for it saves weeks in the process.
Supervisory authorities see involvement as part of the procedure too. The German data protection authorities, in their joint guidance on artificial intelligence, list involving the data protection officer and the employee representation as an explicit step. That is a fair indication of what a later inspection will look like: the question will be who was involved, and when.
Co-determination grows with proximity to your own systems, not with the capability of the tool.
Permit, provide, limit
The effective route reverses the usual order: access first, then the rule, then any monitoring. The German data protection authorities are explicit about the first step. For professional use of AI applications, employers should provide devices and accounts, and employees should not have to work with private accounts and devices on their own, because that way profiles about individual employees can be created.
This is exactly the gap the Bitkom figures show. 26 percent of companies provide their own AI solutions and another 17 percent plan to. The majority does neither and still expects that nobody reaches for a private account. That is not a realistic expectation of people under deadline pressure.
Depending on where you start, there are different routes to access, and they differ mainly in effort. Many companies have already licensed the capability without knowing it, because it sits inside a product suite they own. Where that is not the case, a managed account with the provider, with a contract and training use switched off, is often the fastest step. A self-hosted environment is the most demanding option and pays off mainly where personal data will be processed. IT makes that call, but the requirement comes from HR.
The step most companies skip is an honest starting line. Introducing a new rule while announcing consequences for past use produces better hiding, not reports. A clearly named transition period, in which existing use can be declared without disciplinary consequence, is the only way to get a picture of what is actually running. That is not leniency, it is the price of a baseline.
And it needs a clear owner. This rule belongs to HR, not IT. IT supplies the environment, but the questions that decide whether the rule survives daily work are HR questions: which work may be made easier without responsibility disappearing, who still decides about people, and how employees can tell that they are not doing anything wrong. Why rollouts fail when those questions stay open is covered in the article on why AI projects in HR fail.
- Provide accessA company account, through function accounts or managed user accounts, provided by the organisation. Without this step every rule stays an intention.
- Draw limits by data classDo not list tools, list content. Personal data, health information, performance assessments and application documents stay out until there is a separately reviewed route for them.
- Explain the starting lineA named transition period in which existing use can be declared without employment consequences. After that the rule applies to everyone equally.
- Document the briefingA short session, written confirmation, repeated when things change. This also satisfies the AI literacy obligation.
What belongs in the rule
A usable AI rule answers five questions and fits on two pages: what is allowed, what is forbidden, which data must never go in, who decides in case of doubt, and what happens when something goes wrong. Anything beyond that goes unread, and what goes unread has no effect. The Bitkom survey shows how early most companies still are: 23 percent have rules in place, 31 percent are planning them.
The most important sentence is the one about what is allowed. A policy containing only prohibitions reads like a vote of no confidence and produces shadow use all over again. So name the use cases the tool is meant for: drafting, shortening, structuring notes, producing alternative wordings. A fuller version for HR is described on the page about an AI policy for HR teams.
The second important sentence is about responsibility. Whoever adopts a result is accountable for it, regardless of how it was produced. That sounds obvious, but it relieves a lot of pressure in daily work because it ends the question of whether using AI is acceptable in itself. It is, if the result was checked. The assessment then hangs on the work and not on the tool.
The third point is qualification, and it is not optional. Only 47 percent of employees worldwide have received AI training, and only 40 percent have access to a policy. The German data protection authorities explicitly recommend raising awareness through training, guidelines and conversations, and the EU AI Act makes a sufficient level of AI literacy an obligation of the deployer. Half an hour with real examples from your own company does more than a compliance module.
Finally, the point that decides how long the rule survives: a route for new cases. Questions will come up that the rule does not cover, and if there is no path for them, everyone decides for themselves. A named contact, a short route and a deadline for the answer are enough. Without that, any policy ages within a quarter.
What carries an AI rule for HR
- Permitted use cases, named explicitlyDrafts, summaries, alternative wordings. What is not named is not automatically forbidden, it needs clarification.
- Blocked data classes instead of blocked toolsPersonal data, health information, performance and behaviour data, application documents.
- Responsibility for the resultWhoever adopts a text stands behind it. Checking is part of the work, not an extra.
- Decisions about people stay with peoplePreparing, summarising and suggesting yes. Selection, assessment and separation are decided by humans.
- A documented briefingShort, with examples from your own company, recorded. This also satisfies the AI literacy obligation.
- A route for new casesNamed contact, short deadline, and the answer feeds back into the rule.
When data has already left the building
If it turns out that employee data has ended up in an external service, a clock starts, regardless of whether the use was permitted. In the case of a personal data breach, the controller notifies the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. The clock starts when the company becomes aware, not when management does.
That leads to an uncomfortable conclusion about how reports should be handled. If employees only report a mistake once they are sure there will be no consequences, you lose the very hours in which the deadline runs. The route to a report has to be short, named and free of fear. In practice an address, a person and an explicit sentence that a prompt report is valued more highly than a quiet repair attempt will do.
Where the risk is high, notification of the individuals concerned is added. If the breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller communicates it to the data subject without undue delay. In an HR context that threshold is reached quickly, because the data types are sensitive: health information, application details, pay data, notes from conflict cases.
Independently of any notification there is a documentation duty. The controller documents breaches, including the facts, their effects and the remedial action taken, and that documentation must enable the supervisory authority to verify compliance. This applies to cases that turn out not to be notifiable as well. Without a written assessment you are left with your memory.
In the first hours four things matter: establish which data is affected, stop access to the service or have the input deleted where that is possible, make the assessment together with your data protection officer, and record the case in writing. Questions of responsibility and consequences come afterwards, not during. An incident that improves the rule is expensive enough.
Measuring use without monitoring people
Once company access exists, a new temptation appears: you can now see who uses how much. This is where it is decided whether the rule holds or gets undermined within a year. Personal analysis of use is not lawful merely because the data happens to accumulate. It needs its own purpose, a legal basis and involvement of the works council, because a system that records usage data per person is objectively suitable for monitoring behaviour and performance.
The useful distinction is between steering knowledge and knowledge about individuals. For steering, totals are enough: how many accounts are active, where use is growing, which use cases are being named, where questions pile up. Those figures answer every question a rollout actually has, and none of them requires a name.
For the question of quality no log helps anyway, only a conversation. The most revealing session in a rollout is the one where teams describe where the tool misled them. Run those sessions without any intention to assess, and you get answers no usage report provides, plus the examples that the next briefing is built from.
If a personal analysis really does become necessary, for instance where there is a suspicion of a serious breach, it belongs in an orderly procedure with a clear trigger, defined responsibility and involvement of the relevant bodies. What the works agreement says about this decides the matter in a dispute, not what is technically possible. Writing that passage in advance is uncomfortable and saves weeks later.
The underlying standard is purpose limitation: data may only be collected for specified, explicit and legitimate purposes. A log created to operate the system is therefore not a basis for assessing performance. Saying that limit out loud is the most effective contribution to trust an HR team can make in this rollout, and it costs nothing.
The first thirty days
Getting started does not require a strategy, it requires a baseline and a decision. Waiting until a full concept is ready means more months of unobserved use. One month is enough to move from suspicion to knowledge and to bring the works council to the table before facts are created.
Week one is about numbers rather than opinions. An anonymous short survey in the teams, five questions, no names: is AI being used, for what, through which account, what is missing, what causes uncertainty. The result is regularly clearer than expected, and it is the basis for every later conversation because it removes the argument about whether this is happening at all.
In week two the works council joins, with the baseline as the starting point rather than with a finished draft. That is not a courtesy, it is the faster procedure: an agreement developed jointly does not need a conciliation committee. Plan for the fact that calling in an expert is deemed necessary when the works council assesses artificial intelligence, instead of resisting it.
In week three the rule is written, and it stays short. Two pages, the five questions above, a list of permitted use cases drawn from week one. In parallel, IT settles access: extend an existing product, set up a managed account or build a dedicated environment. The effort differs considerably, but all three beat the status quo without access.
Week four is briefing and launch. Half an hour per team, real examples, the limits stated explicitly, the transition period explained. After that the rule applies. The rest is maintenance: a fixed contact point for questions, a review date after three months, and the willingness to let the list of permitted use cases grow rather than defending it.
One month to a first workable rule. The fine tuning comes after that, not before.
Sources
- Bitkom press release of 21 October 2025: employees increasingly use shadow AI (in German)
- KPMG and University of Melbourne: Trust, attitudes and use of artificial intelligence, global study 2025
- Microsoft and LinkedIn: Work Trend Index 2024
- IBM and Ponemon Institute: Cost of a Data Breach Report 2025
- Section 2 Trade Secrets Act (GeschGehG): reasonable steps to keep information secret
- Section 106 Trade Regulation Act (GewO): the employer's right to issue instructions
- Article 5 GDPR: principles relating to processing and accountability
- Article 32 GDPR: security of processing, processing only on instructions
- EU AI Act, Article 4: AI literacy
- Section 87(1) no. 6 Works Constitution Act (BetrVG): co-determination on monitoring devices
- Federal Labour Court, decision of 16 July 2024, 1 ABR 16/23: objective suitability for monitoring
- Hamburg Labour Court, decision of 16 January 2024, 24 BVGa 1/24: ChatGPT via private accounts (summary at LTO, in German)
- Section 80(3) Works Constitution Act (BetrVG): expert support for assessing artificial intelligence
- German Data Protection Conference: guidance on artificial intelligence and data protection, 6 May 2024 (in German)
- Article 33 GDPR: notification of a personal data breach to the supervisory authority
- Article 34 GDPR: communication of a personal data breach to the data subject
Frequently asked questions
Can we simply ban private AI use?
The employer's right to issue instructions generally covers rules about the tools of work, unless the employment contract, a works agreement, a collective agreement or statute says otherwise. The practical question is different: a ban without a provided alternative moves the use into private accounts where there are no logs, no deletion periods and no contract. A ban only becomes effective together with company access.
Does the works council have to be involved?
Once access sits inside the company and usage data accumulates, co-determination applies to technical devices that are objectively suitable for monitoring behaviour or performance. For purely private accounts without employer access, a German labour court decided otherwise in 2024. Independently of that, when the works council assesses artificial intelligence, calling in an expert is deemed necessary.
Which data must never go into an external AI tool?
As a rule of thumb for HR: no names and no combination of details that points to a person, no health data, no performance or behaviour assessments, no application documents and no draft references containing real data. Drawing limits by data class lasts longer than lists of individual tools, because tools change faster than data types do.
What about employees who have been using it in secret?
An explicitly named transition period is the only route to an honest baseline. Introducing a new rule while punishing past use produces better camouflage, not reports. Once the transition period ends, the rule applies to everyone equally, and breaches can then be treated as breaches.
Do we need training, or is a written rule enough?
The EU AI Act requires deployers to take measures ensuring a sufficient level of AI literacy among staff, regardless of risk class, and the German data protection authorities recommend training, guidelines and conversations. In practice a short briefing with real examples from your own company, documented and repeated when things change, is enough. What matters is the record, not the length.
Talk it through
A free first conversation to sort out your starting position: what is already running in the company, what co-determination requires and which rule fits your organisation.
Talk it through