Meru Data's Podcast

Navigating AI and Privacy in Employment

Priya Keshav

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 57:55

As businesses rapidly integrate AI into everyday operations, legal risk assessments are often struggling to keep pace. This creates growing challenges at the intersection of employment law, privacy, data protection, and emerging AI regulations.

In this webinar, Priya Keshav, Founder & CEO of Meru Data, along with Deepa Menon and Hannah Wilkins, Partners at Eversheds Sutherland, shared practical insights on navigating the evolving legal, privacy, and employment-related challenges associated with workplace AI.

The session explored the key risks businesses should consider before introducing AI tools into the workplace and highlighted how businesses can better understand and manage risks throughout the AI lifecycle, from adoption to the ongoing use.

Topics covered:

  • Legal and regulatory considerations for workplace AI across jurisdictions
  • Risks associated with AI tools such as chatbots, virtual assistants, and transcription platforms
  • Employee monitoring, BYOD risks, and biometric data implications
  • Managing contracts, privilege, confidentiality, and trade secret risks
  • Workforce impacts and governance considerations in AI adoption

Priya Keshav: Good afternoon, everyone. We'll give a few more minutes for everybody to join before we Proceed.

 

Priya Keshav: We'll give another minute or two for, everybody to join, and then get started.

 

Deepa Menon: Should we get started?

 

Priya Keshav: Yeah.

 

Priya Keshav: Good afternoon, everyone. My name is Priya Keshav, and I'm one of the founders and CEO of Meru Data.

 

Priya Keshav: Welcome to today's webinar, Navigating AI and Privacy in Employment.

 

Priya Keshav: As AI becomes increasingly embedded in workplace, tools and employment decisions, businesses should navigate fast-changing mix of privacy, data protection, and employment and AI-specific regulatory requirements.

 

Priya Keshav: For many companies, this is no longer a theoretical compliance issue. It is an urgent governance challenge that affects how employees are hired, monitored, managed, and protected.

 

Priya Keshav: In today's session, we'll discuss the key risks businesses should consider before introducing AI tools into Workplace, including how to identify, assess, and manage risk throughout the AI life cycle, from adoption to ongoing use.

 

Priya Keshav: As I have previously mentioned, my name is Priya Keshav, and I'm one of the founders and CEOs of Meru Data.

 

Priya Keshav: At Meru Data, we simplify and sustain privacy programs for customers worldwide. I help operationalize privacy and AI requirements and build privacy by design into, technologies.

 

Priya Keshav: Previously, I used to be managing director of KPMG's Forensic technology practice in the Southwest US. I've spoken and written about trends in privacy and information governance regularly.

 

Priya Keshav: Joining me on this discussion are Deepa Menon, partners, Eversheds Sutherland

 

Priya Keshav: They bring deep experience advising organizations on privacy, data protection, employment, and technology-related issues across various jurisdictions.

 

Priya Keshav: Deepa Menon advises domestic and international companies with AI deployment.

 

Priya Keshav: And, she's a partner at, Eversheds Sutherland.

 

Priya Keshav: She helps companies,

 

Priya Keshav: with numerous private and public companies through AI deployment, privacy practices, incident response, and data retention. Her extensive experience includes helping companies deal with deployment of internal AI technology, including employee monitoring, validation, performance management, and talent acquisition.

 

Priya Keshav: Further, Deepa assists companies with establishing governance structures to manage AI deployment and contracting with third-party AI vendors. She has been invited by multiple platforms, including SHRM and various ACC chapters, to lead trainings on AI adoption.

 

Priya Keshav: Hannah advises global corporates, including leading technology companies and financial institutions, on cross-border employment law, workforce governance, and in particular on large-scale multi-jurisdiction change programs and employment dimensions of AI deployment enterprise AI deployment.

 

Priya Keshav: She has extensive experience advising on workforce implications of AI-enabled tools, including employee monitoring technologies, algorithmic management systems, and AI-driven performance analytics.

 

Priya Keshav: Hannah regularly counsels clients on employment law rising from AI in the workplace, including consultation obligations, transparency requirements, discrimination and bias concerns, and management of employee relations where new technologies affect how work is observed and assessed.

 

Priya Keshav: Welcome to the webinar, Deepa and Hana.

 

Deepa Menon: Thank you.

 

Hannah Wilkins: Nice to begin.

 

Priya Keshav: To start us off, could you share what you're seeing as some of the biggest legal and privacy risks companies should be thinking about as they introduce AI into workplace?

 

Deepa Menon: Absolutely, and, you'll see that we're sharing a PowerPoint in case you cannot see it, let us know. But,

 

Deepa Menon: And I'll kind of start, and then I'm based in DC, and I deal largely with the United States, and then Hannah sits in our UK office and deals with the rest of the world.

 

Deepa Menon: So, but we do see a bunch, in terms of your question of what we're seeing.

 

Deepa Menon: that's the best part about doing employment law and AI slash privacy law, is that it touches everything.

 

Deepa Menon: I mean, there's very few things that at the end of the day, when you're deploying AI within the workforce.

 

Deepa Menon: you're touching everything from employment law, to IP, to data trade secret protections, to privacy laws, to AI laws. I mean, the entire gamut, safety and health laws. So and that's what makes this tricky, and that's really what makes it more complex than just.

 

Deepa Menon: oh, it's another process, let's call HR and have them hit the green light. That's, that's what makes it an issue. And it's also, in the US, it's an area, and pretty much around the world, is that you have the legal, but you also have the reputational impact, and those tend to get amplified when it's employees.

 

Deepa Menon: on the other side, because legally, the protections I mean, courts generally tend to be more employee-leaning when they're looking at damage caused by new I mean, damage when I say damage, I mean monetary damage, or any other kind of work laws, or any kind of privacy, interference, anything of that sort. When a court looks at this and says, oh wait, there is an employee and an employer, there just tends to be

 

Deepa Menon: more employee-leaning, kind of judgments that come out, because the employee generally has not much of a handle on what kind of system is being rolled out, what kind of technology is being rolled out. And then there's the reputational impact, which, again, is global, and we live in a time where reputational impact becomes

 

Deepa Menon: Almost as important as, and sometimes more important, than the legal consequence.

 

Deepa Menon: Hannah? That's it.

 

Hannah Wilkins: Yeah, no, I completely agree with all of those points, and I think I think we are seeing a real evolution currently in relation to how people are, I suppose, thinking about, AI implementation, but also thinking about the, kind of, the risk profile in relation to AI implementation, and as you said, Deepa Rick, kind of, it spans so many different,

 

Hannah Wilkins: areas within each business when you're looking at implementing AI, but also so many different areas of legal risk, which are often held within by different stakeholders. And something that I,

 

Hannah Wilkins: talk to my clients about quite regularly is, when we're talking about implementing AI, we are, of course, talking about AI that HR teams might use.

 

Hannah Wilkins: You know, some of the tools that we're going to kind of come on and talk about, you know, candidate screening tools, for example, so some of those tools which might be used by the AI the HR function. But of course.

 

Hannah Wilkins: AI impacts on all employees, normally. At some point, AI that you're operating within your businesses will be interacting or intersecting with employees. And so, certainly for kind of an outside-of-US perspective, that means you need to be considering, kind of, employment laws in each of the different jurisdictions that you have employees when you're looking at implementing

 

Hannah Wilkins: And that's AI in the broadest sense, not just your AI tools that you might be utilizing within the HR function.

 

Deepa Menon: P.

 

Deepa Menon: And with that, you know, we're just going to quickly go through today's one-hour presentation. We're obviously not going to cover every single thing, but we're hoping that you will leave from here with an idea of some of the key risks and some of the nuances that you should be aware of as AI is getting deployed in the workplace.

 

Deepa Menon: And again.

 

Deepa Menon: obviously, as you know, a lot of this conversation has come up because of Gen AI, right? Your clause, your chat GPTs, and that's really

 

Deepa Menon: automated systems that think for themselves has just that's what's increased the risk more than just AI. AI has been around for machine learning has been around for a long time, as you know. But it's the Gen AI introduction that's kind of changed the nature of the conversation, because now we're looking at digital employees and agents that are kind of doing what people would have done earlier.

 

Deepa Menon: And then

 

Deepa Menon: Obviously, there is a tech stack to this, there's the AI data centre infrastructure, and then you have, kind of, you know, you build up on these. For the most part, where HR tools come in is either at the application stage or at the API phase. Like, those are the two stages where most employers will come in, as far as AI adoption goes, because you have the data centre, you have the

 

Deepa Menon: GPD model, you have whatever foundational model, and then you get a vendor, and you say, hey, can you give us this? Or you build something in-house. We've seen it go, right? At this point, we see it go both ways. We have tech companies that a lot of tech companies like to develop their own

 

Deepa Menon: software, and so we see that, or even the API programming, they like to do it in-house. But for the most part, that's really where you see HR and AI kind of come in, at those two points.

 

Deepa Menon: Again.

 

Deepa Menon: AI stops answering and starts acting, right? That's where you have the risk, and that's the key, issue that comes up, is there is an autonomous tool that goes out, is reviewing resumes, is monitoring employees, to Hannah's point, is making decisions, is investigating.

 

Deepa Menon: there are multiple risks associated with that kind of if the human oversight isn't there, that obviously ups the ante, and you'll see that that's where a lot of jurisdictions have come in and said, is there human oversight, right? At the end of the day, is there disclosure? Is there human oversight?

 

Deepa Menon: And, just to kind of give you an idea of how this has grown in February of 2025, this is the kind of legal text. I'm just talking about on the legal side, right, for those of us who are in-house counsel or lawyers, this is what legal tech looked like in February 2025. As of March 2026, this is what it looked like in terms of providers.

 

Deepa Menon: So that's, as you can see, the AI offerings for folks to use in-house has increased by multifield, and it's the same thing with HR-based AI tech.

 

Deepa Menon: And like we said, it is not never just one issue. Every HR-based AI use case cuts across, and Hannah and I, we I mean, we spend most of our time now working on HR and AI, and it's, again, because, you know, whether you're looking all the way from AI regulation to employment, IP,

 

Deepa Menon: customer-supplier contractual arrangements, right? There's commercially, when if you're being onboarded as a vendor, there may be, there may be provisions in your commercial contract that restricts or

 

Deepa Menon: specifies how you're going to use AI for your work, and therefore also dictates the kind of AI that's deployed.

 

Deepa Menon: Internally. Your litigation, dispute resolution, sector-specific regulations. If you are in the financial sector.

 

Deepa Menon: may the force be with you, because the kind of regulations we're seeing in the financial sector, in the health sector, huge regulations, especially when it comes to AI.

 

Deepa Menon: Data privacy, product liability, consumer protection. So we're seeing a bunch of different areas being implicated.

 

Deepa Menon: So I'll kind of start with the U.S. There's clearly a race to U.S. dominance, right? The current administration has taken the position, and to be to be very candid, it is U.S. has to be in front of this race.

 

Deepa Menon: And complete deregulation at the federal level is what we're seeing. There is also a lot of pressure on states to deregulate and not well, at least not to over-regulate AI and AI innovation.

 

Deepa Menon: the patchwork of U.S. laws, because obviously, as you know, we don't believe in making many things easy, so we will not have just one law, like the EUAI Act, or that's not what we will have. We will have multiple systems that come together, and have multiple laws that come together, and so

 

Deepa Menon: It gets trickier, because now you have a patchwork of laws to consider.

 

Deepa Menon: At the state level, and this is true when we see, you know, this is, again, very true whenever we see federal deregulation, is we see states stepping in and saying, and often along party lines, stepping in and saying, well, now we're going to regulate. So we're seeing a bunch of different states respond to what is considered federal silence.

 

Deepa Menon: And again, there and we're not alone, so Hannah, if you want to just kind of just jump through the different countries outside.

 

Hannah Wilkins: Yeah, sure. So,

 

Hannah Wilkins: there is obviously a patchwork, as, Deepa has mentioned, both in the US, but also externally. We are we have, obviously, the EU AI Act.

 

Hannah Wilkins: Which we'll come on and talk about in a second, in a bit more detail. But the but we are seeing all sorts of AI regulations, kind of employee-related, coming out in various different jurisdictions. You know, for example, I came across one just the other day that's come that's coming out in Australia in relation to protection of employees, and specifically their, kind of, psychological health.

 

Hannah Wilkins: in relation to the use of AI in the workplace.

 

Hannah Wilkins: In the UK, we don't have any specific regulation, but we what we do have is some non-statutory guidance in relation to specifically AI, in, recruitment.

 

Hannah Wilkins: within the UK. But our UK government has taken a similar approach to the US at a federal level in relation to AI specifically, and is kind of not regulating.

 

Hannah Wilkins: But that's not to say that there aren't specific employment laws in each of the different jurisdictions around the world that are relevant, that you need to think about when you are implementing and operating both HR-related AI, but then also AI more generally across the workplace.

 

Hannah Wilkins: And that's what, this slide is really kind of meant to flag. So

 

Hannah Wilkins: The way I kind of think of AI regulation from an employment law perspective across a kind of a global basis is almost it's kind of like the icing on the cake.

 

Hannah Wilkins: Because actually, what you need to consider when you're looking at AI implementation is the underlying employment laws and privacy laws that apply

 

Hannah Wilkins: Anyway, they've applied for some time, and they obviously are different, depending on the different jurisdiction that you are in the world, and that so it's a patchwork. And the kind of,

 

Hannah Wilkins: points that we are looking at, or kind of flow through from existing employment regulation, are potentially obligations around employee consent when you're implementing AI, or notice, if it's coming from a data protection privacy type obligation.

 

Hannah Wilkins: certainly certain regulations in certain parts of the world that I've talked about. There's the kind of general privacy frameworks in each of the different jurisdictions, around, kind of, collection of employee data, use of employee data, storage of employee data, transfer of employee data. Most of that comes from the existing privacy frameworks that we have in place, either under GDP

 

Hannah Wilkins: GDPR, or the other different GDPR-type regulations in the different parts of the different parts of the world.

 

Hannah Wilkins: And what I think is really interesting is actually

 

Hannah Wilkins: whilst, certainly from the employment perspective, employment law perspective, the employment laws that are relevant here have been in place for a long time. And yet we are now starting to see them kind of

 

Hannah Wilkins: operated or utilized more effectively, particularly by employee representative groups, because AI is just and gen AI is just so prevalent now around us, so people are just much more aware of their rights.

 

Hannah Wilkins: Both individual employees representatives.

 

Hannah Wilkins: In your businesses, or certainly in the businesses of customers.

 

Hannah Wilkins: That, you might be selling to, tech companies might be selling to. And this is the key piece that we're seeing, and actually this is, from my perspective, one of the most fundamental points in how you implement AI, how you operate AI, and whether you can operate the AI that you want to operate, basically. Because

 

Hannah Wilkins: There is a kind of a framework in certain jurisdictions

 

Hannah Wilkins: around whether you can implement technology. And that's not that's not AI-specific, but you, in certain jurisdictions, particularly Europe, but also LATAM, some of  some in some places in the Middle East and also in Asia, before you implement technology.

 

Hannah Wilkins: including AI technology, there is a requirement to consult, inform, and sometimes agree, depending on the type of technology you're implementing, with employees or employee representatives. So, if you have, kind of, works councils within your business, or if you have health and safety representatives in your business.

 

Hannah Wilkins: or employee forums in certain jurisdictions. They will

 

Hannah Wilkins: they have a right to have a say in relation to the technology that's been being implemented. And as I mentioned, that's been a right for some considerable time, but

 

Hannah Wilkins: everyone is becoming much more aware of it now, because of the type of AI that's being implemented, the fact that AI is all around us, and because, certainly, employee representatives, so works councils, trade unions, are have an eye on what the kind of the future might look like in terms of, the job market, kind of post

 

Hannah Wilkins: some of the AI that we're seeing implemented.

 

Hannah Wilkins: And so, that's the kind of the key piece, from my perspective, to always consider when you're looking at AI implementation, is what are the obligations that you need to engage with, before that technology is implemented. And some of those obligations can be incredibly far-reaching, depending on the type of technology you're implementing. But the likely, even in a kind of a baseline information and consultation

 

Hannah Wilkins: process with representatives in Europe, you're likely going to have to look at the vendor contract, for example, for the technology that you're looking at. You will likely have to look at the extent of capability of the technology you're implementing, even if some of that isn't currently turned on.

 

Hannah Wilkins: You will need to look at, certainly, the elements of where employee data is being collected, where it's going to be transferred to, where it's going to be stored, etc. So, it's kind of absolutely critical that those kind of key pieces are looked at.

 

Hannah Wilkins: And I've just put some examples on the slide of some of the likely durations of those kind of information and consultation processes when you're looking at implementing technology. And so, I think, as you can see from these.

 

Hannah Wilkins: it's important to kind of be planning ahead, for some of these, processes before you look at rolling out certain, technology, certainly, and certainly AI technology.

 

Hannah Wilkins: And I think one of the key pieces that we're seeing increasingly now is that when AI technology is implemented.

 

Hannah Wilkins: and Gen AI particularly, there are elements of employee monitoring, within the AI technologies that are being implemented. And that can be, that can be a whole range of employee monitoring.

 

Hannah Wilkins: And actually, in certain jurisdictions, you don't actually have to be monitoring if the tool has the capacity to monitor in some way, or, even in Germany.

 

Hannah Wilkins: If employees think it might be, monitoring them, then you will have a certain additional obligations in relation to the employees or their employee representatives in relation to that.

 

Hannah Wilkins: And those obligations flow from both the employment laws in each of the jurisdictions, but also the privacy framework, because, of course, when you're monitoring employees, there's various different implications that come into play. And on this slide, we've just looked at some of the

 

Hannah Wilkins: Some of the, kind of, sanctions that come into play if you don't

 

Hannah Wilkins: comply with the obligations that you have, either in relation to employees individually, when you're wanting to monitor them, or in relation to the obligations you have for certain, employee representatives, if you don't want to go through the process to get agreement with them when you're implementing AI.

 

Hannah Wilkins: So the kind of the kind of highest obligations there on the left, then you have kind of lower obligations, so you have to consult with representatives or the employees.

 

Hannah Wilkins: But you can normally get through the process, and we've included some examples on the slide of the kind of countries where you might have more difficulty in implementing certain types of, AI.

 

Hannah Wilkins: And then on the bottom of the slide there, I've just included some examples, because there are now increasingly, fines being levied, normally by, the data protection privacy, regulators in each of the jurisdictions.

 

Hannah Wilkins: Around, breaches of,

 

Hannah Wilkins: AI kind of monitoring, or monitoring through AI tools, but often they come from, employee monitoring. And so there's a couple of examples on the slide of, some of the fines that have been levied, in relation to certain, in certain jurisdictions around monitoring.

 

Deepa Menon: Thanks, Hannah. And then, in the US, as you rightly pointed out, we have less of, really, when it comes to implementations, that's the easy part in the US.

 

Deepa Menon: Our general framework really is, in the US is, I can take your firstborn with consent, that's the general and there's implied consent in the US, which, again, I think that if I came over to the UK and said implied consent, you'd ask me, are you crazy? So, again, in the US, we do tend to have an easier time implementing. The issue, though, in the US is once you implement

 

Deepa Menon: it's the litigation that could follow the implementation that drives a lot of the concern here in the U.S, is what the litigation potential could be with each rollout.

 

Deepa Menon: Again

 

Deepa Menon: And a lot of this comes from the idea of data privacy, and it does find its roots in both data privacy and in employment law, in addition to the other laws, yes, but these two kind of take,

 

Deepa Menon: The key, the, key center stage.

 

Deepa Menon: Again, multiple state laws on different restrictions, and of course you have the wiretapping laws that come in. And I think of every, and Hannah, correct me if you think otherwise.

 

Deepa Menon: But at least 60-70% of the time, the questions we're getting in terms of HR-based AI tools relate to the idea of.

 

Deepa Menon: Can we review emails? Can we look at what, efficiency is like? Can we monitor employees? And I'm not talking about the application stage, but when it comes to in-house deployment, the question is, how much can we monitor, right? Can we see if the employee's spending more time, working on

 

Deepa Menon: our work rather than browsing. Are they emailing things that are, are they emailing stuff to themselves? Are they sending emails to… are they moving, company information to their personal accounts? So, the idea really comes down to how much can we monitor? How much can we get into the lives of what these employees are doing?

 

Deepa Menon: In the U.S, we've always had more of a broad stroke there. The idea has been, if it's company-issued, or company-owned, equipment, there is a lot of some states, like New York, say you still need to have a notice in place.

 

Deepa Menon: But for the most part, you know, there's a lot of latitude on what an employer can do to monitor.

 

Deepa Menon: On the other hand, where we tend to run into issues is with the bring your own devices, where you have how much can you monitor on somebody's personal device.

 

Deepa Menon: And with AI, the idea is, before where you would have to have more of a manual process and sifting through things. Now, with the advent of AI, especially Gen AI, it's possible to just go through everyone's emails, make a summary, and flag to management, wait, this is what the employee's been discussing, and these are our emails.

 

Deepa Menon: And there's really a push to go in that direction from a bunch of employers. We see those questions come up.

 

Deepa Menon: But that's also where the risks are, where you have medical information, for example, or where that data is being used to make an adverse employment decision, and then you have now discrimination concerns that come up because

 

Deepa Menon: somebody's been monitoring efficiency, but efficiency may not be the same thing for someone with a disability versus someone without. So there's, like, a bunch of different concerns that come up, and at the helm of it is also privacy, right? Are you really just… how much of my data are you using, and what purpose?

 

Deepa Menon: And that's really, with New York City Law 144 stands as one of the biggest, examples of how much

 

Deepa Menon: can be regulated, because and this is for those of you who have for those of you who are deploying AI to make decisions in New York City, and have New York City employees slash applicants, again, may the force be with you, because New York City law

 

Deepa Menon: it blows pretty much every law, including, I think, the Act, out of the water, because it essentially says you need to do audits and put the results out. If there's adverse impact, you need to put the results out on a public-facing website. Now, that's kind of like telling your plaintiff's lawyers, hey, don't look anywhere else, just come sue me instead. Because you're giving them the numbers on a platter.

 

Deepa Menon: There's a lot of transparency required under New York City Law 144.

 

Deepa Menon: CCPA, again, there we do have the ADMT rules.

 

Deepa Menon: Colorado is here with automated decision making. It's nowhere near what we thought it would be, because essentially we thought it was going to be far more rigorous. It is not. The for all these laws, the focus has been transparency disclosure. How transparent are you about the use of AI?

 

Deepa Menon: And that's been that kind of notice has been the big piece.

 

Deepa Menon: One thing that's coming up, and we're seeing more, is with respect to RIFs, because when you have maximization of efficiency, that's code for we're trying to cut back on human resources, right? And there are states, that are now moving toward that kind of

 

Deepa Menon: Are you using AI to drive rifts? And if so, you need increased transparency, particularly in the context of the WARN disclosure.

 

Deepa Menon: So that's, something to watch out for. Once again, like Hannah said, there is the multi-country conundrum. What flies in one country may not fly in the other. So for those of you

 

Deepa Menon: And I think this is one place where I like to say this. If you are trying to comply with every single legal requirement in every single country that you operate in, it's not you're not going to do it. There's

 

Deepa Menon: you can only do the best you can, and I try to say this off the bat, because I feel like we get so stuck in that kind of complete compliance.

 

Deepa Menon: that often employers lose sight of some of the more key pieces that drive AI deployment, such as governance structures, or the policies that need to go into this, or the other kind of IP-based issues, for example, that are underlying these.

 

Deepa Menon: So, and again, with that kind of different multi-country, you know, legal system comes the in-house role of balancing that innovation, and with those multiple laws, kind of, there's a lot of pressure on in-house lawyers.

 

Deepa Menon: Now, I think that I just want to stop here for a second, and when we say HR here, we mean everybody who's touching HR, right? Both HR, any, the IT team that's supporting HR, the legal team that is making employment decisions.

 

Deepa Menon: In the past, the idea really was, you know, tech kind of provides you with a great solution, and the HR team is now responsible for implementing.

 

Deepa Menon: And I think now it's changed to HR is now the architect. You have to help build the system out, because there are just so many key pieces that go into this that you're never going to do it without those key stakeholders in the room. Or you could do it, but then you just have to go back and fix it, which is far more onerous.

 

Deepa Menon: The idea that and Hannah, I think we've seen this, that the rule has, once again, changed from reviewer to architect, or from responding to actually managing. And what are would you like to say a few words on what you're seeing, in the UK and Europe?

 

Hannah Wilkins: Yeah, absolutely, and I think that's absolutely critical. It kind of goes back to one of the points I was making earlier in in Europe, if you have a Europe-based workforce and you want to implement AI technology, then you will have to get it if you're a

 

Hannah Wilkins: company of any reasonable size, you will have to get it through your works councils. And as is mentioned earlier, they will ask for modifications if they don't like it. And so, having that kind of input at the outset when you're actually designing the technology, is kind of critical, because, as Deepa says, there's no point in designing an AI solution that you want to implement across a workforce that cannot be implemented in certain jurisdictions.

 

Hannah Wilkins: Unless you're happy to accept that it won't that it will be a regional tool only. So I think I think that's absolutely critical.

 

Deepa Menon: Thank you.

 

Deepa Menon: And, for what it's worth, I was seconded to a global media, social media tech company as AGC for about a year and a half, where I was doing both Privacy Framework, and I was also product counsel. So, I… I think that we're well aware of

 

Deepa Menon: What it goes into a product design, and

 

Deepa Menon: Having to fix it after the fact is

 

Deepa Menon: the kind of resource spend that we see there, when you could have just had all the stakeholders in the room from the get-go, it's, I think it's so key when it comes to managing the budget and managing the resources with any product deployment.

 

Deepa Menon: With that, where are we seeing AI deployed in the workforce, in the workplace?

 

Deepa Menon: Talent acquisition recruitment. As you're aware, that's kind of the first offering. Performance management, people analytics, workforce scheduling and deployment, safety and compliance, learning and development, you know, personalized training tools.

 

Deepa Menon: HR operations and self-service. These include bots, for example, to handle benefits queries. Employee experience and engagement when it comes to surveys, kind of finding out what the employee pulse is.

 

Deepa Menon: productivity and knowledge work, which, again, is the fastest growing next to the acquisitions and talent acquisitions and performance management. And this includes your GitHub co-pilot, this includes your Enterprise Cloud, Enterprise ChatGPT, all of these.

 

Deepa Menon: Now, and there I will pause to say this, this if a company doesn't have an enterprise version of AI,

 

Deepa Menon: rest assured that the employees are using AI. They're just we don't tell you they're using AI, but they're definitely using AI, and it's just I think more employers are coming to the understanding that it's better to offer an enterprise version than take the risk, because

 

 

Deepa Menon: There was a study in which 3 out of 5… well, 4 out of 5 employees were using AI, and 3 out of 5 said, well, we're not going to tell the employer, because this is outside the enterprise. We don't have an enterprise version, so we don't want to tell them that we're using it.

 

Deepa Menon: There's compensation and pay equity is another place we're seeing AI use, and organizational design, again, restructurings, understanding bottlenecks, etc.

 

Deepa Menon: And with that, we'll jump into the key risks. The first risk, bias and discrimination. That remains the key risk with any AI rollout. And, Hannah, do you want to speak about this?

 

Hannah Wilkins: Yeah, absolutely. And actually, this is one of the areas where I think probably in the US, you're kind of almost leading the way in relation to discrimination specifically linked to AI. But yeah, I think we can be rest assured that absolutely in all of the jurisdictions around the world where

 

Hannah Wilkins: you have employees, or your companies have employees, there will be some element of discrimination protection, to differing degrees. Obviously, in the UK, we have a high level of,

 

Hannah Wilkins: Equity and equality protection. And

 

Hannah Wilkins: absolutely, all AI tools need to be operated in accordance with those. Then, obviously, in addition to that, we have the kind of EU AI regulations that also now put certain obligations on employers in addition to the discrimination-type protection that already exists in each of the different jurisdictions.

 

Deepa Menon: In the US, we really are looking to see what the Mobley case brings.

 

Deepa Menon: In case you're not, aware of the Mobley case, the idea, the complaint is that, the AI-based it's a workday tool. The complaint was the plaintiff alleges that the AI-based applicant screening tools were biased on the basis of race, age, and disability. The collective action has been approved.

 

Deepa Menon: And the basis for that is Mobley had actually applied to 100 jobs with companies that use Workday's AI-based hiring tools, and he claims that he was rejected each time.

 

Deepa Menon: So, where do we stand with the Mobley case right now? It's still ongoing, we're still kind of at the class action, the certification stage. The one thing that has happened with the Mobley case is that the judge said, produce a list of all the employers who've used a Workday AI tool.

 

Deepa Menon: That can be dangerous, right? Because Workday came back and said, well, we customize our AI data tools for each employer, so it's not like all the employers are using the same tool. The judge said, doesn't matter, give me a list of every single employer. And that's what really opens the risk, right? Because employers said.

 

Deepa Menon: Wait, does that mean that if I ever used an AI tool, even if it wasn't this AI tool, you want I'm going to be on this list that is now going to the judge, and potentially that opens the path for more, plaintiff's claims against those specific employers.

 

Deepa Menon: And so there's,

 

Deepa Menon: all eyes on Mobley, for now, to see how this, proceeds, and how  and I think this is going to set the this is kind of going to this is going to set the path.

 

Deepa Menon: for what how the U.S. tends to handle bias, discrimination, and how, you know, it's pretty much the trailblazer in the legal world for, you know, for this particular issue.

 

Deepa Menon: Again, the one other thing I wanted to point out is the tort claims that we're seeing, because a few years ago in Georgia, which doesn't have a privacy law, if you're aware, the state of Georgia, there was this employee who went in and said, you know, my data was being misused, and the employer said, there's no data privacy law. And the court said, well, we have a tort claim for unreasonable interference with privacy.

 

Deepa Menon: So when an employer is using an employee's data in a way that the employee could not have reasonably foreseen, meaning you told the employee you're going to collect it for employment purposes, and then you used it for a completely different purpose, there is that potential tort claim.

 

Deepa Menon: Which is just a reminder to a lot of us that even if there's no state-based privacy law, because California is the only privacy law, per se, that covers, employees, and then you have some of the AI-based laws that will cover

 

Deepa Menon: Explicitly, right? But it's important to remember that you have these potential tort claims that could come up.

 

Deepa Menon: Employee monitoring, the state laws vary. We have a two-party consent and one-party consent state, which essentially means one-party consent state means only one of the parties, either the person recording or the person being recorded, needs to consent.

 

Deepa Menon: Which may not make a lot of sense to Hannah and to maybe the rest of the world, but then you also have the two-party consent states, which says both parties have to consent. This comes up a lot for us in note-taking, transcription tools, the recording tools, meeting assistance, all of these pieces.

 

Deepa Menon: And With that, we there are higher risks, there's, you know, there's not all risks are created equal.

 

Deepa Menon: when you have something that is going into, say, biometric analysis, where you're looking at, break rooms, private rooms, off-monitoring, off-hours monitoring, or bring your own devices, all of these are high risk when it comes to AI deployment. Hannah, I didn't know if you wanted to add to those?

 

Hannah Wilkins: Yeah, well, and or just plain not possible in some jurisdictions. They that that element of certainly the kind of

 

Hannah Wilkins: out of hours, or kind of monitoring through your laptop, but monitoring during non-working hours, or the potential of capturing data of third parties, family members, etc. It just might not be possible in certain jurisdictions around the world. Either for privacy-type reasons, i.e. reasons coming from the privacy laws, or because you'll need to get it through

 

Hannah Wilkins: regulators, or because you'll need to get it through works councils and they won't agree to it. So yeah, that does need to be approached with caution, as I mentioned on one of the earlier slides in relation to monitoring, and the extent of the monitoring is absolutely critical to consider.

 

Deepa Menon: One thing in the U.S. that is also interesting to me is, you know, there may not be explicit monitoring, but if you create the impression that employees are being monitored, that in itself could lead to claims under the National Labor Relations Act.

 

Deepa Menon: Because if an employee feels my concerted activity is being monitored, that could in itself create an issue.

 

Hannah Wilkins: Yeah, absolutely, and we see that really, as I touched on earlier, at the kind of implementation phase. If employees or their representatives feel like there might be monitoring, or there is a perception of monitoring, that might kick you into a higher level of obligation in relation to those representatives. And yeah, as I said, we're talking about agreement. You need their agreement, so often that will mean that you have to

 

Hannah Wilkins: Kind of de-scope the tool, or reduce.

 

Hannah Wilkins: Or put certain, kind of, protections in place in relation to the levels of monitoring that you're doing. Opt-outs, for example.

 

Deepa Menon: And, you know, again, biometrics obviously ups the ante a little, and it comes down to consent.

 

Deepa Menon: And but then consent, again, is not created equal across jurisdictions. Is it meaningful consent? And there's some jurisdictions, like in the UK, employee consent in itself is a problematic area, and how much and what are you getting consent for, right? What is the purpose limited?

 

Deepa Menon: So again, biometrics is still in the US, biometrics continues to lead the way, and pretty much around the world, biometrics kind of leads the way in terms of high risk.

 

Deepa Menon: AI resumes, video interview analysis tools, automated performance monitoring, AI-driven compensation benchmarks, predictive attrition models, AI and accommodation, leave decision support. All of these, again, continue to be high-risk areas where things can go. And it's interesting to me because

 

Deepa Menon: often a lot of these issues can be remedied with the basics, which is policies, trainings, kind of comes down to the basics. And, I think one of the biggest risk points I see with employers adopting innovation is that

 

Deepa Menon: there's such a run to innovate, and I'm like, collect the basics, let's talk the basics, which is, do your folks know what to do with this data, or how to implement, and how to deploy this? So it's also interesting. I'm sure nobody on this call, is in that boat, but it's interesting to me how many different employers I see where they're just

 

Deepa Menon: Into the innovation and not thinking about the actual basics of it.

 

Deepa Menon: You'll see here that we have some different examples. We're not going to go into each one of these, but the idea really here is that when you there's just different risks that could come. For example, the second one, Scenario B, where the manager's using ChatGPT to draft performance reviews.

 

Deepa Menon: pasting in employee personal data, medical accommodation notes, and performance ranking. You have HIPAA slash state privacy laws that could be implicated. You have acceptable use by policy violations that could be implicated. In another case where a company is AI video monitoring the whole time, you have National Labor Relations Act, and then you have wiretapping statute, so it's just

 

Deepa Menon: Anything you touch, you just touch we just wanted to put it out there to show you how many different kinds of laws can be implicated with seemingly simple circumstances.

 

Deepa Menon: And there's, of course, the idea of shadow AI, and you'll bring your own device.

 

Deepa Menon: Which is, when an employee and the one thing I want to point out here is April 2023, Samsung engineers used ChatGPT to help fix problems with source code and mistakenly entered top-secret data. This became a big deal. So, the idea of having employee documentation that is very clear on what kind of data you can put into an AI tool, and basically educating

 

Deepa Menon: employees on the this is not

 

Deepa Menon: I mean, it may look like your best friend, but it really isn't, because it's open it's everybody's best friend, and so you're kind of releasing information in to the, into kind of the third-party world, unless it is an enterprise version, and unless there are promises made to you by the vendor that employee data is not going to be used, for example, to train the models.

 

Deepa Menon: So, just again, we just have to be careful on that front. It's easier when you have bring your own devices for that world to get blurred, and for the company not to have complete control over how some of this data is being used. So, just brings down, again, once again, brings us down to the basics.

 

Deepa Menon: Also wanted to point out about privilege. So if you are counsel, or you're working with council.

 

Deepa Menon: There is still a lot of commentary around this, but the idea is if you put your data, confidential information, into an AI tool, does that waive privilege? And there is a real argument that it does.

 

Deepa Menon: Because it's not particularly, at least in the US especially, there is the idea that, well, you waived it by putting it into this tool that's open to all. Hannah, what are you seeing in the UK and EU?

 

Hannah Wilkins: Yeah, absolutely. The position, obviously, is slightly different in, across the world, because there are some countries that just don't have privilege, because they don't have obligations of disclosure in the same way as we do in the US or the UK. But even in those jurisdictions, it's a relevant point, because, of course.

 

Hannah Wilkins: If there is certain data that you thought was, that you thought was privileged, if it's shared even in an enterprise-wide version, but the individuals that have access to that data, wouldn't normally have access, or would normally, be within the, kind of, the privileged circle, as it were, then absolutely, it will it will waive privilege.

 

Hannah Wilkins: Or in those jurisdictions where they don't have a concept of disclosure, the more widely the information is disseminated, the more likely it is that the other side might be able to ask for specific pieces of information, which is how those systems work, where there isn't a concept of disclosure. So, yeah, absolutely.

 

Deepa Menon: Perhaps, that kind of brings us back to the idea of also vendors, right? Vendors are being seen as agents, so when, you know, if and this is if you look at California's FIFA, the Federal Employment Housing Act, which is kind of the basis for a lot of the anti-discrimination provisions in California.

 

Deepa Menon: There's there have been changes that

 

Deepa Menon: algorithmic data, for example, has to be stored, just like personnel records, so you have to store those. Question is, who stores them? Because

 

Deepa Menon: You have a vendor who's coming, and there's a fundamental difference between a vendor who's coming in and who's just giving you the software and saying, you know, run with it, this is yours.

 

Deepa Menon: And with a vendor who says, I'm going to run this for you. This is your staffing agency, which might say, I'm going to go ahead and recruit on your behalf. So I'm going to have do all these AI tools, I have all these AI tools, I'm going to deploy them, I'm going to go through the resumes, and I'll pass on to you, after the first two stages, the list of folks who you want to consider, right? So they're actually deploying the AI tool on your behalf.

 

Deepa Menon: Or, the vendor is saying, here's a tool, go, you know, go to town.

 

Deepa Menon: In either case, though, especially in that first case where they're running the tool for you, California and most states will take the position they're acting as your agent. And so the employer also has responsibility to make sure that the data is retained in the way that the state requires you to.

 

Deepa Menon: So, in California, for example, your vendor, before, you could just pass it on to the vendor and say, vendor, you're responsible for retaining this data. Fija just came in and said, nope, now the employer is also going to be responsible. On the other hand, Fija also tells the vendor, when you do these things, you are acting as the employer. So now both parties are equally responsible.

 

Deepa Menon: Again, but those contractual terms, reviewing the commercial contractual terms and ensuring that they match up to what the HR… what HR expects, that is key. And so when it comes to liability.

 

Deepa Menon: We've gone through these. A lot of this is just a rehash peace line. We want to leave some time for questions, like 5 minutes for questions, but the idea really is know your tech, right? Ask all the questions you need to ask on knowing your tech.

 

Deepa Menon: What is the impact? Who is using this? How is it going to be used? Who's storing the data? Often issues come up because nobody understands the tech fully.

 

Deepa Menon: And meaningful disclosures, and like I said, coming back down to the basics. Policies, how are you what does the governance structure look like? How is it,

 

Deepa Menon: Is there risk training? Are there audits in place? How are you assessing those risks?

 

Deepa Menon: So just, again, by no means is this intended to be your be-all and end-all of all HR-based AI nuances, but we're hoping that we could we gave you, kind of, a roadmap to go with. Any questions?

 

Priya Keshav: While we are waiting for the attendees to ask questions, I have a couple of them. So, one question I have, we talked a lot about the monitoring tools. So, you have the employee monitoring tools that HR deploys, maybe for a specific purpose.

 

Priya Keshav: But, you also have these ancillary tools, like Teams, for example, you know, and you see a lot of

 

Priya Keshav: what I would say useful reports that look like monitoring that come out of some of these tools.

 

Priya Keshav: Where you can and they're turned on, but typically by IT, where you see things like, you know, you've been online for so many hours, or you've attended so many meetings, and these are the groups you're more active with, versus others, which

 

Priya Keshav: you know, translates in some way to a level of monitoring, and, you know, you don't know who else has access to these reports, so what are your thoughts around some of those tools?

 

Hannah Wilkins: Well, so, from an international perspective, that's all monitoring. The bar in terms of what is monitoring is low, so that would be considered monitoring for the purposes of, your obligations in relation to your employees or your works councils, certainly in… across Europe.

 

Hannah Wilkins: And then equally, if you're looking at it from a kind of a privacy perspective, again, that would need to feature in your, kind of, notices to employees in the, kind of, GDPR-type jurisdictions.

 

Hannah Wilkins: In terms of what the tool can do, what you're going to use the data, where's the data going. So even if they're not, kind of, overt monitoring tools, they are what we would consider to be monitoring.

 

Deepa Menon: Same thing in the US, Priya, because the idea would really be, unless you had monitored them, you wouldn't have the report. So, while you may not really call it monitoring, did the employees know that you were being they were 

 

Deepa Menon: that their activity was being monitored. And often it's just a case of putting it in a policy, in the US at least, where you just say.

 

 

Deepa Menon: You know, all employer-based equipment system use will be monitored.

 

Deepa Menon: And you should not have any expectation of privacy, right? Being able to put that in the it comes down to that disclosure. And also, to your point, Priya, again, it comes down to who has access to this? How is it being used?

 

Deepa Menon: But being very clear about internally now, you don't have to put it out on a banner and put it out for all employees and say, you know, I solemnly swear that this is not going to be used for anything else.

 

 

Deepa Menon: But internally, there needs to be an understanding, because

 

Deepa Menon: especially with smaller organizations, the risk is that the data may not you might not have very siloed divisions, and it what has happened with the AI introduction is

 

Deepa Menon: The siloing has become important now, because you have to be clear on which division is going to have access to the data, and how it's going to use this data. Because if you're collecting the data for, I don't know, the idea is

 

Deepa Menon: I want to tell you how to improve your personal performance, then the hiring manager cannot come in and take that data and say, oh, but, like, we noticed that this is what I mean, if that's what the employee consented to by using the tool.

 

Deepa Menon: Then, now the hiring manager can't come in and say, by the way, we've been tracking your hours, and we know that you haven't been using your hours wisely. Because now, that's just a whole different use of the tool.

 

Priya Keshav: The other example that I often see as well, you know, we talk about biometrics, WISE analytics, I mean, again, obvious use cases, there is high risk, but I also see with Gen AI, you know, you can kind of look at

 

Priya Keshav: emotional equivalence of like, I've seen people analyze, you know.

 

Priya Keshav: how this meeting has been, you know, in terms of based on conversations, as to whether they've been supportive, whether they are… I mean, like, all kinds of, you know, feedback that a co-pilot or another Gen AI tool could probably provide, you know, in terms of the emotional component of

 

Priya Keshav: various people that have participated in team meetings, right? So, again, these are use cases that may not be official, but is possible, to be used by a manager or a team leader, you know, and how do you kind of look at those, use cases?

 

Hannah Wilkins: Yeah, absolutely, and I think, certainly, from a, well, from a European perspective, not UK, but from a European perspective, anyone covered by the EU AI Act, obviously, that would be prohibited use within the, under the EU AI Act, because any inferring of emotion within the workplace is prohibited.

 

Hannah Wilkins: But even if it's not being used, even if that's not the stated purpose.

 

Hannah Wilkins: Again, those kind of monitoring, even if you're not in the protect you're not in the prohibited category, then you're going to be in the high-risk category, and so that will need to be have been thought through in advance, so you will need to have done some form of assessment at the outset, a bit like a kind of a privacy assessment under the various privacy laws around the world, in terms of how you're going to use utilize that AI.

 

Hannah Wilkins: And I suppose one other point that it's just worth flagging is, in lots of countries and around the world, if you haven't implemented the technology correctly, and or if you're using data that the technology has collected for a purpose that you've not stated at the outset, you cannot use that

 

Hannah Wilkins: to, informal action, a kind of a labour or workforce

 

Hannah Wilkins: action. So, for example, you can't use it to terminate, you can't use it to discipline, you can't use it to performance manage. If you haven't been up front at the outset, you can't then use it later on down the line for a different purpose in lots of different jurisdictions.

 

Deepa Menon: Also, in the U.S, you know, when you use sentiment analysis or facial analysis, the concern is you have discrimination issues that come up, and come up very quickly, and that's really where we see the most litigation. When it comes to biometrics and facial analysis. The idea is

 

Deepa Menon: I mean, you could see any number of claims come out of that, right?

 

Priya Keshav: Any other closing thoughts before we wrap up? I don't see any questions from the audience, so,

 

Priya Keshav: Want to give you a minute or two for any closing thoughts.

 

Deepa Menon: My takeaway, at least in the US, would be have your legal folks involved from the design phase, or the adoption phase. Absolutely imperative that they're involved, and

 

Deepa Menon: Again, that's I think my favourite phrase is, it's the basics, the basics, the basics. Like, you need to go down to the basics, understand your tech, understand your policies, your trainings, your people.

 

Deepa Menon: If you can hit the basics, most of your issue will

 

Deepa Menon: It'll be it'll be an easier ride-through.

 

Deepa Menon: Yeah. And this is also… sorry, and this is not the place to be the trailblazer. I think this is one place where you don't want to be the first to adopt a technology.

 

Hannah Wilkins: Yeah, and I think we've seen that from some of the finds that we've seen, certainly outside of the US, some of the trailblazers, some of the finds that they've seen. I would echo all of those points deeper, and I think also trying to understand what technology is being implemented within your business. So often there's technology implemented through existing tools, so AI starts running through existing technology tools that, you know, we in the AI

 

Hannah Wilkins: HR or the employment legal space are not even aware of, and so understanding that is really important.

 

Priya Keshav: Thank you so much for, joining Deepa and Hannah for and giving us, some great insights around, use of AI in employment.

 

Priya Keshav: And, thank you for everyone for joining this webinar. The recording will be made available for, after the call as well, and, thanks again. And you can reach out to Deepa and Hannah on LinkedIn if you have any questions, you know, beyond this, webinar as well. Thanks again.