AI, Workplace Technology and Cyber Security: Why This Is Now an HR Issue

03 Aug 2026

Published in: Member News

AI, workplace technology and cyber security are now HR issues as well as IT concerns. Employers need clear rules on devices, personal data, monitoring and AI use, supported by training and fair processes. HR and IT must work together to protect information, trust, security and accountability.

Laptops, iPads, phones and AI tools are now part of ordinary working life. They help people work faster, stay connected, access information, respond to clients and keep things moving when they are away from the office.

In many businesses, technology has become so normal that people barely stop to think about it. An employee checks emails on their phone. A manager downloads a document to an iPad before a meeting. Someone uses an AI tool to tidy up a customer response or summarise notes. A laptop goes home overnight so work can continue the next morning.

Most of this is practical. Much of it is useful. But it also creates risk.

The mistake many employers make is treating this as purely an IT issue. Of course, IT has a vital role to play. Systems need to be secure, devices need to be protected and access needs to be controlled. But the day to day use of technology is also about behaviour, expectations, confidentiality, trust, training and accountability.

That makes it an HR issue too.

Why Workplace Technology Belongs on the HR Agenda

Technology now sits right in the middle of the employment relationship. It affects how people communicate, how they perform, how they are managed, how information is stored and how work is carried out.

When an employee uses a laptop, phone, tablet or AI tool for work, they may be handling client details, employee records, contracts, payroll information, internal emails, sickness absence information, disciplinary documents or commercially sensitive business data.

If that information is mishandled, the consequences can be serious. There may be data protection concerns, confidentiality breaches, cyber security incidents, disciplinary issues and damage to client or employee trust.

The problem is that many risks do not come from sophisticated cyber attacks. They come from everyday habits.

A password is shared because it is quicker. A document is sent to a personal email address so someone can work from home. A phone with work emails on it is left unlocked. A former employee still has access to a shared folder. A confidential document is copied into an AI tool without anyone thinking about where that information may go.

These are not unusual situations. They are the kind of things that happen when people are busy, under pressure or unclear about the rules.

That is why HR needs to be involved. Policies, contracts, training, induction, manager guidance and disciplinary processes all help shape how technology is used in practice.

AI at Work: Helpful, But Not Without Risk

AI has changed the conversation because it has made powerful tools available to almost everyone.

Employees can now use AI to draft emails, write reports, summarise meeting notes, create content, generate ideas, analyse feedback and speed up routine tasks. Used properly, this can be helpful. It can save time, improve consistency and support employees who are dealing with heavy workloads.

But AI also creates risks that employers cannot afford to ignore.

One of the biggest concerns is confidentiality. If an employee copies personal data, client information, medical details, grievance notes, disciplinary records, payroll information or commercial documents into an AI tool, the business may lose control of that information.

There is also the issue of accuracy. AI generated content can sound confident even when it is wrong. That matters if employees are relying on it to produce advice, letters, HR documents, customer responses or management communications.

Then there is fairness. If AI is used in recruitment, performance management, absence management or any process that affects people’s employment, the employer needs to be especially careful. Human judgement cannot simply be replaced by a tool without understanding how decisions are being influenced.

The practical question for employers is not whether AI is good or bad. It is whether employees know how they are allowed to use it.

If nobody has explained what information must not be entered, which tools are approved, when outputs must be checked and who is responsible for the final decision, then the business is relying on individual judgement. Some employees may be cautious. Others may not realise there is a risk at all.

Personal Devices, Remote Working and Blurred Boundaries

The use of personal devices is another area where convenience can quickly overtake control.

Many employees now check work emails on their own phones, access documents from home, use messaging apps to discuss work or log in to systems from personal tablets or laptops. For small businesses in particular, this can feel like a practical solution. It allows people to respond quickly and work flexibly without the employer needing to provide every piece of equipment.

But it also raises important questions.

If work information is sitting on a personal phone, how is it protected? If the employee leaves, how is access removed? If a device is lost, who needs to be told? If family members also use the device, could they see work information? If documents are saved locally, can the employer recover or delete them?

There is also the employee’s privacy to consider. If an employer allows work access on a personal device, employees should understand what the business can and cannot see, whether any monitoring takes place, and how work data will be managed.

This is where clear guidance matters. Without it, both sides can make assumptions. The employer may assume work data is protected. The employee may assume personal devices are outside the employer’s control. Neither assumption is safe without proper communication. 

Monitoring Employees Through Technology

Technology has also made workplace monitoring much easier.

Employers may be able to see logins, emails, website use, locations, system activity, call records or productivity data. In some situations, monitoring may be reasonable. A business may need to protect confidential information, investigate misconduct, manage performance or meet regulatory obligations.

But just because technology makes monitoring possible does not mean it should be used without thought.

From an HR perspective, the key issues are transparency and proportionality. Employees should know what monitoring takes place, why it is happening, how the information may be used and who has access to it.

Hidden monitoring can quickly damage trust. Excessive monitoring can affect morale and create a culture where employees feel watched rather than managed. It may also raise data protection concerns if the employer cannot justify what it is collecting or how it is using the information.

Good employers do not use technology as a substitute for management. They use it carefully, clearly and only where there is a proper reason. 

When Cyber Security Becomes a Conduct Issue

There will be times when misuse of technology becomes a conduct or disciplinary matter.

An employee may share login details, ignore password rules, download unauthorised software, send confidential information to a personal account, use unapproved AI tools or leave devices unsecured. Depending on the circumstances, these issues may need to be addressed formally.

But employers should be careful before jumping straight to disciplinary action.

The first question should always be whether expectations were clear. Was there a policy? Was the employee trained? Had the rule been communicated? Were managers applying the same standard? Had similar behaviour been tolerated before?

If the business has never explained the rules, it may still need to deal with the incident, but it should also recognise the weakness in its own systems.

A fair process depends on clarity. Employees need to know what is expected before they can reasonably be held accountable for failing to meet that standard. 

What Employers Should Have in Place

The answer is not to overwhelm employees with long technical policies that nobody reads. The aim should be practical, understandable guidance that reflects how people actually work.

An AI, technology and cyber security policy should explain how company devices can be used, whether personal devices are permitted, how passwords and access should be managed, what to do if a device is lost or stolen, and how confidential information should be protected.

It should also explain the organisation’s position on AI. Employees need to know whether AI tools are allowed, which tools are approved, what information must never be entered, when human checking is required, and whether AI can be used in work involving employees, clients or decision making.

This should be supported through induction and regular training. Cyber security and AI use should not be mentioned once in a handbook and then forgotten. The risks change quickly, and so do working habits.

Managers also need guidance. They are often the people who allow informal shortcuts to creep in. A manager who permits shared passwords, personal WhatsApp groups, unapproved software or casual use of AI with sensitive information may be creating risk without realising it. 

Why HR and IT Need to Work Together

Cyber security is strongest when HR and IT work together.

IT can put the technical controls in place. HR can make sure the people side is clear, fair and consistently managed.

That partnership matters at every stage of employment. During recruitment, employers need to think about how applicant data is handled. During onboarding, new employees need to understand the rules around devices and systems. During employment, managers need to know how to deal with concerns. When someone leaves, access needs to be removed quickly and company information needs to be protected.

A weak leaver process, for example, is not just an IT problem. It is also an HR process problem. If someone leaves the business but keeps access to emails, files, systems or shared folders, the organisation has exposed itself unnecessarily.

The same applies to remote working, performance management, monitoring, disciplinary processes and AI use. Technology may sit behind the process, but people are the ones using it. 

Final Thoughts

AI and workplace technology are not going away. Nor should they. Used well, they can save time, improve communication, support flexible working and help businesses operate more effectively.

But employers need to be realistic about the risks.

A business does not need to ban every tool or make work harder than necessary. It does need clear boundaries, sensible training and consistent follow through.

Employees should understand what they can use, what they must avoid and what to do if something goes wrong. Managers should understand what they can approve and when they need advice. The business should know where its information is going, who has access to it and how it is protected.

Technology can make work easier. AI can make work faster. But without proper HR involvement, both can create avoidable problems.

That is why AI, workplace devices and cyber security should now be part of every employer’s HR conversation, not left sitting quietly in the IT corner.

Submitted by Emma from EC Human Resources Ltd
Share on Linked In

Comments

Post A Comment

You must be logged in to post a comment. Please click here to login.