AI is fast becoming embedded in day-to-day people management. Employers are experimenting with algorithmic tools to shortlist candidates, score interviews, allocate shifts, forecast demand, monitor productivity, flag performance issues, support redundancy exercises and even trigger investigations and dismissal processes. Whilst in recent years, the adoption and integration of AI has been concentrated in large tech businesses, management applications of AI are beginning to proliferate into different sectors.
AI technologies promise speed, consistency and decisiveness. They also introduce new and significant legal and employee relations risks, particularly if implemented without robust governance, transparency and meaningful human oversight. UK employers should give careful thought to the way that relevant legal frameworks are engaged by AI-assisted management.
In this article, we first summarise some of the key legal risks that may be engaged by the management use of AI tools, before looking at some practical recommendations as to how employers can engage with AI responsibly, safely and fairly.
The legal frameworks
AI systems neither reduce nor replace the responsibility of employers for the actions they take in relation to their employees. They can, however, create new potential liabilities – some of which the employer may be entirely unaware of.
Unfair dismissal
Employers must have a statutory potentially fair reason and follow a fair process before dismissing employees with 2+ years continuous service, even for those on fixed-term contracts. From 1 January 2027, that threshold will drop to 6+ months (find out more here). The Government has estimated that this change will give an additional 6.3 million employees (or 22% of all employees over 16) unfair dismissal protections. Over-reliance on the outputs of automated tools to inform dismissal decisions can seriously complicate both identifying a fair reason and the fairness of a process.
Many AI systems operate as a “black box”, producing an outcome without recording the logical process that produced it. Where AI-led recommendations for dismissals are uncritically followed, an employer may struggle to establish that the true reason for the dismissal was a statutory potentially fair reason. The ultimate decision-maker in any dismissal should always be a human that carefully and critically assesses the evidence before them. Employees may also challenge reliance on opaque scoring or flawed data forming part of an AI system’s inputs or outputs. This has been an issue in large-scale redundancy exercises where employees have been selected to be put at risk using AI tools. Where AI outputs form part of the evidential picture of a dismissal, tribunals will be likely to scrutinise this carefully.
Even if a potentially fair reason for dismissal is identified, the employer must follow a fair process. This will usually include the decision-maker considering all the relevant circumstances and consulting with the employee. Tribunals have been critical of employers relying on flawed investigatory data and have underscored that a fair process requires active, not passive, assessment of evidence before dismissal. Over‑reliance on an AI recommendation without critical assessment risks creating procedural unfairness.
Discrimination, harassment, victimisation, reasonable adjustments
AI can embed discriminatory biases through training data or proxies, including in ways the employer (usually purchasing the AI tool from a third party developer) is not themselves aware of. This can create significant exposure under the Equality Act 2010 in a number of ways and throughout the employment lifecycle, from recruitment through to in-role management and up to dismissal. These include:
- Direct discrimination – This risk is likely to be limited in most cases, but some AI tools can be directly discriminatory. For example, one AI tool was alleged to have deprioritised candidates for interview where their CVs included references to playing in women’s sports teams.
- Indirect discrimination – Indirect discrimination risk exists where neutral criteria disproportionately disadvantage a protected group and cannot be justified as a proportionate means of achieving a legitimate aim. For example, historical success profiles in some industries may encode gendered or racialised patterns, skewing outcomes even when protected characteristics are not formally used to train the systems. Algorithmic systems have been shown to inappropriately use features like postcodes (which can correlate with ethnicities) and gaps in work history (which can correlate with disability or sex, through to periods of maternity leave).
- Reasonable adjustments – Employers must proactively make reasonable adjustments for disabled workers. This includes where automated systems applied to all colleagues substantially disadvantage them specifically. Examples could include rigid productivity thresholds or keystroke monitoring that does not account for assistive technology.
- Harassment – Use of certain monitoring or automated feedback technologies could, if deployed without appropriate transparency and safeguards, create a hostile or intimidating environment which could constitute harassment.
- Victimisation – If AI tools either actively or passively treat less favourably those who have done protected acts, which might include raising grievances or whistleblowing, then victimisation claims could follow.
Opacity and explainability gaps (including in respect of “black box” decisions or recommendations) hinder an employee’s ability to understand and challenge decisions or recommendations. Importantly, though, they also hamper the employer’s ability to justify decisions.
Data protection claims
Most AI management tools involve looking at personal data and many may engage with special category data by inference (e.g. health information or ethnicity, including via proxies). Employers using these tools should have: (i) a clearly identified lawful basis for doing so; (ii) appropriate transparency notices that explain the logic involved and envisaged consequences; and (iii) Data Protection Impact Assessments (DPIAs) for high‑risk processing (including large‑scale monitoring of employee work activity).
If third parties that provide AI tools act as data processors, the contracts with them should include appropriate protections and assurances in relation to model performance and security. If such third parties act as controllers, joint controllership analyses may be needed. Inaccurate or incomplete data inputs for these tools can produce erroneous and unfair outcomes. Similarly, productivity tools may misclassify legitimate activity or ignore context. Employees might ultimately try to bring claims against an employer for misusing AI tools, for example in unlawful processing of their data or in relation to solely automated decision-making. Regulatory fines and investigations in relation to data protection breaches are also a possibility.
Confidentiality and implied term of mutual trust and confidence
Common law obligations require all employers not to act in a manner calculated or likely to destroy or seriously damage trust and confidence. The deployment of intrusive monitoring (particularly without appropriate transparency), or disciplinary action or dismissal based on undisclosed automated metrics, can undermine trust with employees and may support claims of a breach of trust and confidence. This could in turn support constructive unfair dismissal claims, or even claims that the employer has attempted to unilaterally amend employment terms without employee consent. More broadly, inappropriate use of these tools can negatively affect workforce morale and engagement and erode trust in the employer. This sort of workplace environment often correlates with an increase in grievances, union activity and voluntary attrition.
Consultation and collective issues
Where a workplace has a recognised union, introducing or materially changing monitoring practices may require information and consultation under existing collective agreements. Similarly, any changes to employment terms or policies connected with management AI use should follow proper variation processes. Where no union is present, employers would be prudent to engage actively and transparently with their workforce through employee forums or all-staff events about the proposed uses of AI tools. Reputational harm may follow if AI use is perceived as unfair, intrusive or discriminatory. Depending on the employer’s industry, this could also attract media, union, regulatory, investor or donor scrutiny.
Practical tips for employers considering adopting AI management tools
- Establish appropriate governance. At the outset, assign responsibility to an AI oversight group, ideally including HR, legal, data protection, IT and employee representatives. This group could maintain an AI systems register, clearly documenting purposes, data flows, security measures, third party vendors (and the associated due diligence), and any identified and mitigated risks.
- Set clear policy. Implement a clear policy on AI and algorithmic tools. This should cover at least: procurement, approval, permitted uses, transparency to staff, and escalation routes. Any monitoring practices should be aligned with the privacy notice and acceptable use policies.
- Keep humans in the loop. Prohibit solely automated decisions and train decision makers (particularly with reference to hiring/firing decisions) to interrogate AI outputs, consider context and mitigation, and record reasons where departing from or following recommendations.
- Assess and document risks. Conduct DPIAs for high risk uses, including employee monitoring. Keep a clear record of legitimate aims, necessity and proportionality, and how impacts on protected groups are mitigated. Keep records of due diligence on third party providers, particularly around their own security measures.
- Test tools for bias and accuracy. Before deployment and periodically afterwards, validate datasets and outputs for disparate impact, particularly on those with protected characteristics, and error rates. Features, thresholds or processes can then be adjusted as appropriate, if disproportionate effects are identified. Where this type of testing and validation is undertaken by a third-party supplier, ensure that the contractual arrangements require appropriate testing and validation and include suitable warranties, indemnities and other appropriate contractual protections.
- Train managers. Provide practical training on interpreting AI outputs, avoiding automation bias, spotting data quality issues, and handling challenges. Re-emphasise the employer’s duties towards their employees, particularly around discrimination, unfair dismissal principles, and data protection.
- Be transparent. Communicate clearly with the workforce about what tools are used, why, what data is processed, and the consequences. Explain how to raise concerns about this, request human review, or correct data. Engage with workforce representatives on material changes.
- Align other policies. Update the grievance, disciplinary and performance procedures to address AI informed evidence, disclosure of underlying data where appropriate, and routes for appeals. Ensure reasonable adjustments are considered in any AI informed process.
- Manage third party providers carefully. Allocate data controller/processor roles correctly and ensure compliance with the relevant obligations. Ensure contracts include audit rights, performance and bias reporting, incident notification, data localisation, and exit support. If possible, avoid “black box” and prefer those that record a clear logical rationale for their recommendations.
- Monitor and iterate. Track outcomes, complaints and appeals to identify patterns arising from the use of AI tools. Use these findings to refine configuration, policies and training (if applicable). Discontinue the use of tools that cannot be operated in compliance with legal and regulatory standards and where continued use is a significant source of liability.
Conclusion
AI can support efficient and fair people decisions if implemented well. Employers who combine strong governance, transparent communication and continuous validation will be best placed to realise the benefits of AI tools in management.
If you have any questions on anything outlined above, get in touch with Peter Kerr-Davis or Paul Jennings.
The material in this article is provided for guidance and general information only and is not intended to constitute legal or other professional advice upon which you should rely. In particular, the information should not be used as a substitute for a full and proper consultation with a suitably qualified professional. Please do contact the Bates Wells team if you require further advice or information about management training which we offer.