Staff are already using these tools, with or without permission. The exposure for the employer is confidential information leaving the business, unverified output relied on as fact, and decisions about people taken with no meaningful human review. This is what to put in place, and in what order.
The decision an employer faces is not whether to allow generative AI. Staff are already using it, on their own accounts if not on the company's, and an employer with no position has taken one by default: unrestricted use, no record of what has been entered, and no way of knowing what has left the business. The exposure is confidential information disclosed to a third party, unverified output relied on as fact, and decisions about people taken by a system nobody has audited. All three are manageable, and none of them is managed by a paragraph in the staff handbook saying that employees should be careful.
The three risks, in order of how often they materialise
Information leaving the business. Anything an employee types into a public tool has been disclosed to whoever operates it, on that operator's terms. Where the material is a client's confidential information, a counterparty's draft, personal data of staff or customers, or the business's own unpublished work, the disclosure may breach a contract, a duty of confidence or data protection obligations regardless of what the tool subsequently does with it. This is the risk that arrives first and the one that cannot be undone.
Output that is wrong. These systems produce text that predicts what an answer looks like. Confident, fluent and false is their characteristic failure, and it is a failure that survives casual reading. An employee who forwards an unverified output to a client has made a representation on behalf of the business.
Bias. Where output reflects patterns in the material a system was trained on, it can reproduce discriminatory assumptions. This matters most where the output touches people: recruitment, promotion, performance assessment, allocation of work.
A usage policy is a short instruction, and it is cheaper before the first incident than after.
What the policy has to contain
A usable policy is short, specific and enforceable. Ours cover the following, and we would not sign off on one that omits any of them.
An approved tool list. Named products, with named account arrangements. Personal accounts should be prohibited for work purposes, because the employer has no control over, and no record of, what passes through them.
A rule on what may be entered. State the categories that may never be put into a tool: client confidential information, personal data, unpublished financial information, anything received under an obligation of confidence, and credentials. Say it in categories staff recognise from their own work, not in abstractions.
Verification before use. Nothing generated leaves the business, goes to a client, or is relied on in a decision until a named person has checked it against a source. Where the output is a legal, financial or technical proposition, the source has to be the primary material.
Human oversight of decisions about people. No recruitment, disciplinary, performance or dismissal decision should rest on a system's output. A human decision maker must have the underlying material, the authority to depart from the recommendation, and a record of the reasons.
Disclosure. When AI generated material is provided to a client or a counterparty, or used in a public communication, decide in advance whether it will be identified as such. Contracts with clients increasingly require it.
Intellectual property. State who owns what staff produce with these tools, and warn that output may reproduce third party material. Content generated for publication should be checked before it is published, not after a complaint.
Training and a record. The policy has to be issued, acknowledged and trained. An unacknowledged policy is of limited use in defending a claim, and of no use at all in enforcing one.
The claims that follow misuse
Where the policy is absent or ignored, the exposure typically takes one of four forms. Discrimination claims, where a decision affecting an employee or applicant is influenced by output reflecting systemic bias. Unfair dismissal or detrimental treatment claims, where a system contributed to a decision without adequate human oversight and the employer cannot show a reasoned human process. Intellectual property claims, where an employee generated content that infringes a third party's rights. And breach of contract or confidence claims from clients whose information was disclosed to a tool the client never approved.
Note where the liability lands. In each of these cases the employee acted, and the business answers for it. The employer's protection is not the disclaimer in the tool's terms of service, to which the employer is not a party in any useful sense. It is a documented policy, evidence that it was issued and understood, and a record that the human decision was genuinely human.
Disciplinary use and monitoring
Two cautions. First, an employer cannot discipline an employee for breaching a rule that was never communicated, so the policy must be issued before it is enforced. Second, monitoring employees' use of these tools is itself processing of personal data, and where the employee works remotely it engages section 8 of the Regulation of the Framework for the Organisation of Telecommuting Law of 2023, Law 120(I)/2023, which prohibits monitoring employees through a camera or another application of a similarly intrusive character in order to check performance. Decide what will be logged, tell staff, and keep it proportionate to the risk being managed.
If you are at this point
A usage policy is a short instruction, and it is cheaper before the first incident than after. Send us what your staff already use or write to office@kleanthousplatis.com.
Where this connects to the Artificial Intelligence Act
The workplace policy and the regulatory analysis are separate exercises that share an input. Both start from a list of the systems in use and what each one is used to decide. Build the inventory once and use it for both.
The regulatory timetable is worth having in mind while the policy is being written. The Act is Regulation (EU) 2024/1689. It entered into force on 1 August 2024, the prohibited practices and the AI literacy obligations have applied since 2 February 2025, the general purpose AI and governance rules since 2 August 2025, and the Regulation applies generally from 2 August 2026. The obligations for high risk systems were then deferred by Regulation (EU) 2026/1744 to 2 December 2027 for the Annex III use cases, and to 2 August 2028 for high risk systems embedded in regulated products. Point 4 of Annex III is the one that matters here: it covers systems used for recruitment or selection, including targeted job advertising, the filtering of applications and the evaluation of candidates, and systems used to decide on terms of work, promotion or termination, to allocate tasks by reference to individual behaviour or personal traits, or to monitor and evaluate performance and behaviour. An employer using a system to screen applicants or to allocate work is looking at December 2027, and at documentation that has to be built before then rather than found afterwards.
Making an enquiry
Briefly describe your matter and mention any deadline. You do not need to gather documents before getting in touch.
Information we may need later
Once we confirm we can act, we will explain what to provide. The following information is for the subsequent review, not your first message.
Your current policy or handbook if you have one, the list of tools in use and the accounts they run on, the supplier terms, and a note of any process affecting staff or applicants that a system touches. If an incident has already occurred, send the sequence of events before anyone is disciplined.
Employment and technology matters sit within our corporate and commercial practice. For the regulatory analysis of the same systems, see The EU Artificial Intelligence Act. For remote workers, the monitoring restrictions are set out in Telecommuting in Cyprus.
Questions we are asked
Can I monitor staff use of these tools?
With care, and not by every means. Monitoring is itself processing of personal data, and where the employee works remotely it engages section 8 of the Regulation of the Framework for the Organisation of Telecommuting Law of 2023, Law 120(I)/2023, which prohibits monitoring employees through a camera or another application of a similarly intrusive character in order to check performance. Decide what will be logged, tell staff, and keep it proportionate to the risk being managed.
Can I discipline someone who breached the policy?
Only if the policy was communicated first. An employer cannot discipline an employee for breaching a rule that was never communicated, so issuing it, and having evidence that it was acknowledged, comes before enforcing it. Where an incident has already happened, the sequence of events is reviewed before anyone is disciplined.
When do the Artificial Intelligence Act obligations start?
Regulation (EU) 2024/1689 entered into force on 1 August 2024. The prohibited practices and the AI literacy obligations have applied since 2 February 2025, the general purpose AI and governance rules since 2 August 2025, and the Regulation applies generally from 2 August 2026. Regulation (EU) 2026/1744 then deferred the high risk obligations to 2 December 2027 for the Annex III use cases and to 2 August 2028 for high risk systems embedded in regulated products.
Should we allow staff to use generative AI at all?
That is not the decision in front of an employer. Staff are already using these tools, on their own accounts if not the company's, and an employer with no position has taken one by default: unrestricted use, no record of what has been entered, and no way of knowing what has left the business.
What is the exposure, in order of how often it materialises?
Information leaving the business, which arrives first and cannot be undone: anything typed into a public tool has been disclosed to whoever operates it, on that operator's terms, and where the material is a client's confidential information, a counterparty's draft, personal data or the business's own unpublished work, the disclosure may breach a contract, a duty of confidence or data protection obligations. Then output that is wrong, because confident, fluent and false is these systems' characteristic failure and it survives casual reading. Then bias, which matters most where the output touches people: recruitment, promotion, performance assessment and allocation of work.
Is a line in the staff handbook enough?
No. None of the three risks is managed by a paragraph saying that employees should be careful. A usable policy is short, specific and enforceable, and it is cheaper before the first incident than after.
What has to be in the policy?
An approved tool list of named products with named account arrangements, with personal accounts prohibited for work purposes, and the rest of the items the article sets out. A policy that omits any of them is not one we would sign off.
Related Reading
This article is for general information only and does not constitute legal advice. Laws and their application can change, and individual circumstances differ. For advice on your own matter, contact Klitos Platis at klitos@kleanthousplatis.com or telephone +357 22 680 330.

Klitos Platis
Advocate, Partner
Kleanthous & Platis LLC, Nicosia · Revised 4 August 2026
Need advice on your own matter?
Briefly describe your situation, the people involved and any deadline.
We reply within one business day. We will ask for documents once we confirm we can act.
Receive legal updates by email
When Cyprus law changes, hear it from us
One short email when something changes that matters: new legislation, a decision worth knowing, a deadline. Written by the partners, no marketing, unsubscribe with one click.
You are on the list. The next update on Cyprus law will reach your inbox.
That did not go through. Please write to office@kleanthousplatis.com and we will add you.
Your address is used for these updates and nothing else. Privacy notice.