Where AI is already being used
In practice, workplace AI systems increasingly support:- CV screening and candidate ranking
- Automated recruitment assessments
- Employee productivity monitoring
- Performance scoring and analytics
- Internal investigations
- Workforce planning and allocation of tasks
- Risk and compliance monitoring
AI does not remove employer responsibility
One of the most common misconceptions is that responsibility sits with the software provider. It does not. Even where decisions are assisted by AI, employers remain responsible for ensuring compliance with employment law, GDPR obligations, anti-discrimination rules, and applicable regulatory requirements. If an AI-supported recruitment process systematically disadvantages certain groups of candidates, or if employee monitoring becomes excessive, liability will generally remain with the employer.The GDPR challenge
Most workplace AI systems process significant volumes of personal data. This may include:- employee identification data;
- performance metrics;
- communications data;
- behavioural information;
- location data;
- productivity indicators;
- recruitment information.
The AI Act changes the landscape
The EU AI Act introduces a new layer of compliance obligations. Particular attention should be paid to AI systems used for:- recruitment and candidate selection;
- promotion decisions;
- employee evaluation;
- allocation of work;
- monitoring employee behaviour;
- employment termination decisions.
Employee monitoring requires particular caution
Many organisations are exploring AI-powered monitoring tools that can analyse employee activity, communications, productivity patterns, and behavioural indicators. These technologies can create significant privacy and workplace relations concerns. Before implementing such tools, employers should assess:- whether monitoring is genuinely necessary;
- whether less intrusive measures could achieve the same objective;
- whether employees have been properly informed;
- whether monitoring remains proportionate to the intended purpose;
- whether sufficient safeguards and oversight mechanisms exist.
Governance is becoming the real compliance challenge
In our experience, the greatest legal risk rarely comes from the AI system itself. Instead, difficulties arise when organisations cannot demonstrate:- who approved the system;
- who oversees its operation;
- how decisions are reviewed;
- how bias and errors are managed;
- how employees can challenge outcomes;
- how compliance is documented.
Practical steps for employers
Before deploying AI in the workplace, organisations should consider:- conducting a legal and regulatory assessment;
- reviewing GDPR compliance requirements;
- determining whether a DPIA is required;
- assessing AI Act implications;
- establishing governance and accountability frameworks;
- documenting human oversight procedures;
- updating employee notices and internal policies;
- ensuring a sufficient level of AI literacy among staff operating or using AI systems.
How ECOVIS ProventusLaw can assist
ECOVIS ProventusLaw advises employers, fintech companies, and regulated organisations on the legal and regulatory aspects of AI deployment in the workplace. Our team assists with:- AI governance frameworks for HR and workforce management systems;
- GDPR compliance for employee data processing and monitoring tools;
- Legal assessment of AI-assisted recruitment and decision-making processes;
- Data Protection Impact Assessments (DPIAs) for high-risk AI use cases;
- Workplace monitoring policies, including legal review of surveillance and productivity tools;
- Alignment with the EU AI Act, employment law requirements, and internal governance standards;
- Regulatory risk assessment for AI systems used in regulated financial services environments.
About the Author:
Loreta Andziulytė is a Partner and Attorney-at-Law at ECOVIS ProventusLaw, heading the firm’s Data Protection, Employment, and Corporate Commercial teams. With over 20 years of experience, she advises employers, fintech companies, and regulated financial institutions on employment law, data protection, AI governance, and regulatory compliance.
Her practice focuses on complex cross-border employment matters, workplace governance, employee monitoring, internal investigations, and the legal implications of emerging technologies in HR processes, including AI-assisted decision-making and workforce analytics. Loreta has significant experience advising on GDPR compliance, the EU AI Act, DORA-related governance requirements, and regulatory frameworks affecting digital and regulated workplaces across the EU.
She is ranked in FinTech Legal by Chambers and Partners (2020, 2023–2026) and recognised by The Legal 500 in FinTech, Employment, TMT, and Dispute Resolution (2019–2025). Loreta is a Certified Data Protection Expert (CIPP/E).
LT
RU
CN
DE